Threat reportRansomwareTL-2026-0115
Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting, BYOVD as Standard Prep, Double/Triple Extortion Economics, IAB Vertical Integration, Critical Infrastructure Escalation
Ransomware Threat Landscape 2025-2027 (TL-2026-0115) is a critical-severity ransomware operation, first published 2026-02-06. It has no confirmed attribution, maps to 31 MITRE ATT&CK techniques (T1003.001, T1018, T1021.002), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 31MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0115
- Threat ID
- TL-2026-0115
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- Healthcare, Financial Services, Government, Manufacturing, Education, Legal, Insurance, Critical Infrastructure, Technology, Retail
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Ransomware Threat Landscape 2025-2027
Malware and tooling: Akira - S1129, BlackByte, BlackCat - S1068, Clop (ELF), Conti - S0575, LockBit, Qilin, Royal Ransom (ELF)
How Ransomware Threat Landscape 2025-2027 works
Strategic landscape analysis of ransomware ecosystem evolution from 2025 through early 2026: RaaS model destabilization from law enforcement disruption and affiliate trust collapse, record-low payment rates (~20% Q4 2025), data-exfiltration-only extortion losing efficacy, Conti leak spawning 6+ derivative families, ESXi hypervisor targeting as force multiplier, BYOVD as standard pre-encryption preparation, insider recruitment as novel initial access, and the emergence of targeted social engineering replacing opportunistic intrusion
The ransomware threat landscape in 2025-2026 is undergoing its most significant structural transformation since the emergence of double-extortion in 2019-2020. This analysis synthesizes intelligence from Coveware quarterly reports (Q3 2025, Q4 2025), Verizon DBIR 2025, Arctic Wolf incident response data, and Threadlinqs Intelligence database entries covering 10+ ransomware-linked threats to provide a comprehensive strategic overview of the evolving ransomware ecosystem.
**1. RaaS MODEL DESTABILIZATION — THE TRUST COLLAPSE**
The Ransomware-as-a-Service model that powered Conti, Hive, LockBit, and BlackCat/ALPHV has fundamentally destabilized. Three simultaneous forces drove this collapse:
(a) Law enforcement disruption: 2024 was a banner year for LE actions against ransomware groups. Operation Cronos dismantled LockBit's infrastructure in February 2024, seized servers, published affiliate identities, and released decryptors. While LockBit attempted revival, its reputation among affiliates was permanently damaged by the exposure of internal data showing LockBit retained victim data even after payment.
(b) Affiliate trust fracture: In Q1 2024, both LockBit and BlackCat/ALPHV were caught cheating their own affiliates — withholding payments, stealing credentials, and operating deceptively (per Coveware). BlackCat executed a brazen exit scam in March 2024 after receiving the $22M Change Healthcare ransom, posting a fake FBI seizure notice while absconding with funds. This dual collapse splintered the affiliate market and destroyed trust in the RaaS franchise model.
(c) Payment rate decline: Ransom payment rates have plummeted to historic lows — approximately 20% in Q4 2025 (Coveware), down from 30-40% in 2022-2023. Data-exfiltration-only payment rates dropped to 19% in Q3 2025 and approximately 25% in Q4 2025. CL0P's five successive mass exploitation campaigns (Accellion 2021 → GoAnywhere 2023 → MOVEit 2023 → Cleo 2024 → Oracle EBS 2025) demonstrate the economic degradation: payment rates fell from ~25% (Accellion) to ~2.5% (MOVEit) to 0% (Cleo) as organizations learned that paying for data suppression offers no durable benefit.
The RaaS framework that brought Conti, Hive, and LockBit to prominence is unlikely to succeed in its prior form. Coveware assesses that increasingly dire economics are forcing ransomware actors to be less opportunistic and more creative — pivoting to social engineering, insider recruitment, and targeted attacks against 'white whale' enterprises.
**2. CONTI LEAK WEAPONIZATION CASCADE**
The August 2022 Conti source code leak (Conti 2 builder) spawned at least 6 derivative ransomware families, fundamentally democratizing ransomware capability:
- Nitrogen/Azote (TL-2026-0105): Derivative with fatal ESXi crypto bug — Curve25519 memory corruption makes decryption permanently impossible even with cooperation. Malvertising via Google/Bing ads for IT tools. - Royal → BlackSuit: Conti successor led by former Conti member 'Zeon'. Royal rebranded to BlackSuit in mid-2024 after attribution pressure. - BlackByte: Conti offshoot using AES-256 + RSA-4096, known for attacking critical infrastructure. - Meow: Data-exfiltration-focused Conti derivative, sells stolen data on clearnet marketplace. - Monti: Close Conti code reuse, targets Linux/ESXi with Conti v2 builder output. - LukaLocker: Conti-derived ransomware associated with infrastructure targeting.
The Conti leak transformed ransomware from a specialist capability to a commodity. Any moderately skilled operator can now build functional ransomware from leaked source code, lowering the barrier to entry and fragmenting the market into dozens of small operations.
**3. ESXi HYPERVISOR TARGETING — THE FORCE MULTIPLIER**
VMware ESXi has become the highest-value ransomware target because a single hypervisor hosts dozens of virtual machines. Encrypting one ESXi host can cripple an entire organization's infrastructure simultaneously. Key developments:
- ESXi-specific variants: Nearly every major ransomware family now includes a Linux/ESXi variant (Akira, LockBit, Royal/BlackSuit, Nitrogen, Qilin, Play, RansomHub). - ESXi attack pattern: SSH brute-force or credential reuse → disable ESXi firewall → kill VM processes (esxcli vm process kill) → encrypt VMFS datastores (.vmdk, .vmx, .vmem, .vswp, .nvram). - Nitrogen accidental wiper (TL-2026-0105): Nitrogen's ESXi variant has a fatal Curve25519 implementation bug — a QWORD write at rsp+0x1c overwrites 4 bytes of the public key at rsp+0x20, corrupting the Diffie-Hellman exchange. The resulting symmetric key is derived from a corrupted public key for which no corresponding private key exists. Decryption is mathematically impossible. Even paying the ransom cannot recover data. This transforms 'ransomware' into an 'accidental wiper.' - Detection vacuum: Many organizations lack syslog forwarding from ESXi hosts to SIEM, making ESXi encryption invisible until VMs stop responding. ESXi is the single most dangerous detection gap in enterprise ransomware defense.
**4. BYOVD AS STANDARD RANSOMWARE PREPARATION**
Bring Your Own Vulnerable Driver (BYOVD) has evolved from a niche technique to standard pre-encryption preparation. Ransomware operators load signed but vulnerable kernel drivers to kill EDR/AV from Ring 0 before deploying the encryptor:
- truesight.sys (TL-2026-0105 Nitrogen): RogueKiller Antirootkit driver used to kill 59 security tools from kernel mode. Listed on LOLDrivers.io. - AuKill: Kills Sophos, SentinelOne, and other EDR products using Process Explorer driver (procexp.sys). - Poortry/Stonestop (TL-2026-0091): Sophisticated loader+driver combination used by multiple groups including Scattered Spider. Driver signed with stolen certificates. - EDRKillShifter: Custom EDR-killing framework that rotates between multiple vulnerable drivers. - BackConnect AnyDesk BYOVD: Uses legitimate remote access tools to sideload vulnerable drivers. - The BYOVD taxonomy (TL-2026-0091) documents 11 cross-references across the Threadlinqs database, demonstrating how pervasive this technique has become.
BYOVD effectiveness stems from a fundamental architectural weakness: Windows kernel-mode drivers run with the same privileges as security tools. A valid signed driver that contains a vulnerability can be used to terminate any process, including EDR agents. Until Windows enforces HVCI/WDAC driver allowlists universally, BYOVD will remain a reliable EDR bypass.
**5. EMERGING INITIAL ACCESS EVOLUTION**
(a) Insider recruitment: The BBC documented Medusa ransomware offering a company employee 15% of the ransom payment for network access (Coveware Q3 2025). This represents a fundamental shift — traditional RaaS used opportunistic vectors (access brokers, stolen credentials, known vulns). Shrinking profits are driving actors to targeted, higher-cost methods including insider bribes.
(b) Targeted social engineering: Helpdesk social engineering, pioneered by Scattered Spider, has been widely adopted across numerous encryption and data extortion gangs in 2025. Silent Ransom (Luna Moth) uses callback phishing targeting insurance and law firms. The merge of remote access compromise and social engineering means adversaries obtain access by convincing someone to provision it, not by exploiting a technical flaw.
(c) Malvertising as targeted self-selection: Nitrogen's Google/Bing ad campaigns for IT tools (WinSCP, KeePass, PuTTY, AnyDesk) create self-selecting targeting — victims are IT administrators with elevated privileges who actively search for the tools they use daily.
(d) PAM/trusted tool exploitation: CVE-2026-1731 BeyondTrust (TL-2026-0110) demonstrates that privileged access management tools are prime targets. Compromising PAM = instant domain control because PAM stores/manages credentials for the entire organization.
**6. MARKET STRUCTURE — Q4 2025**
Coveware Q4 2025 data shows the market is bifurcating: - Top variants: #1 Akira (14%), #2 Qilin (13%), #3 Lone Wolf (12%), #4 CL0P (7%), #5 Silent Ransom (6%), #6 Shiny Hunters (4%). - The top two (Akira, Qilin) both use encryption as primary impact driver. Slots 3-6 are data-exfiltration-only operations. - Average ransom payment Q4 2025: $591,988 (+57% from Q3). Median: $325,000 (+132% from Q3). The divergence reflects isolated high-impact settlements, not broad willingness to pay. - Encryption-driven payments remain higher than data-exfiltration-only payments, suggesting a return to encryption as the primary extortion lever. - Coveware predicts actors may return to encryption roots as data-exfiltration-only economics collapse.
**7. LAW ENFORCEMENT & REGULATORY EVOLUTION**
Operation Cronos (LockBit, Feb 2024), BlackCat exit-scam exposure, and ongoing LE doxxing of threat actors have raised the personal risk for ransomware operators. CISA KEV mandates, SEC cyber incident reporting rules (Dec 2023), and expanded breach notification requirements are creating regulatory pressure that makes paying ransoms increasingly untenable from a governance perspective.
**8. PREDICTIONS — 2026-2027**
- Return to encryption: As data-exfiltration-only economics collapse (CL0P model degraded from 25% to 0% payment rates), actors will refocus on encryption as the primary lever. - White whale targeting: Shrinking margins will drive concentration on large enterprises where single payments justify higher intrusion costs. - Insider threat expansion: The Medusa insider recruitment model will be replicated as social engineering and bribes become viable alternatives to technical exploitation. - ESXi becomes primary target: ESXi encryption will be the default deployment target because of force multiplication (1 host = dozens of VMs). - BYOVD standardization: Every serious ransomware operation will include BYOVD as pre-encryption preparation. - AI-assisted operations: Ransomware groups will increasingly use AI for vulnerability discovery (already happening — Hacktron AI discovered CVE-2026-1731), negotiation automation, and social engineering content generation.
MITRE ATT&CK techniques used in TL-2026-0115
credential-access
T1003.001 LSASS Memory; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
discovery
lateral-movement
T1021.002 SMB/Windows Admin Shares
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage
execution
T1059.001 PowerShell; T1569.002 Service Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
defense-evasion
persistence
T1136.002 Domain Account; T1547.001 Registry Run Keys / Startup Folder; T1547.006 Kernel Modules and Extensions
initial-access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.002 Spearphishing Link
command-and-control
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
defense-impairment
T1553.002 Code Signing; T1685 Disable or Modify Tools; T1688 Safe Mode Boot
collection
resource-development
Remediation for Ransomware Threat Landscape 2025-2027
Patches
- No single patch — requires continuous vulnerability management across all internet-facing infrastructure
- Priority: BeyondTrust RS/PRA (CVE-2026-1731), VMware ESXi, VPN appliances (Ivanti, Fortinet, Palo Alto), file transfer (MOVEit, Cleo)
Immediate actions
- Patch internet-facing appliances within 24 hours of critical CVE disclosure — the weaponization window has collapsed to near-zero
- Enable ESXi syslog forwarding to SIEM — ESXi encryption is the most dangerous detection blind spot
- Block known BYOVD drivers (truesight.sys, procexp.sys, AuKill drivers) via WDAC/HVCI driver allowlist
- Implement MFA on all remote access (VPN, RDP, cloud SSO, PAM) — credential-based intrusion remains dominant initial access
- Segment backup infrastructure from production — immutable, air-gapped backups are the only reliable ransomware recovery mechanism
Workarounds
- Network segmentation between management infrastructure (PAM, ESXi, AD) and general purpose computing
- Application allowlisting to prevent unauthorized software execution including ransomware payloads
- Disable unnecessary Windows services and protocols (SMBv1, WMI remote, WinRM) to limit lateral movement surface
Longer-term hardening
- Deploy HVCI and WDAC driver allowlists to prevent BYOVD attacks at the kernel level
- Mature insider threat programs — ransomware groups are now recruiting employees for initial access
- Evaluate PAM security architecture — PAM compromise = keys-to-the-kingdom (per TL-2026-0110 BeyondTrust)
- Implement helpdesk social engineering controls — Scattered Spider tactics have been widely adopted across multiple groups
- Build ransomware-specific incident response playbook including credential rotation procedures for PAM compromise scenarios
- Establish pre-negotiated cyber insurance with clear ransom payment policy aligned with organizational governance
- Adopt default non-payment posture for data-exfiltration-only incidents per industry best practice (Coveware, specialized counsel)
Timeline of Ransomware Threat Landscape 2025-2027
- Conti version 2 source code leaked, spawning 6+ derivative ransomware families (Nitrogen, Royal/BlackSuit, BlackByte, Meow, Monti, LukaLocker). Democratized ransomware capability. Source: Multiple
- Operation Cronos dismantles LockBit infrastructure — servers seized, affiliate identities published, decryptors released. LockBit attempts revival but reputation permanently damaged. Source: NCA/FBI/Europol
- BlackCat/ALPHV executes exit scam after receiving $22M Change Healthcare ransom — posts fake FBI seizure notice, absconds with affiliate funds. Destroys RaaS trust model. Source: Coveware
- Silk Typhoon exploits CVE-2024-12356 in BeyondTrust to breach US Treasury (OFAC, OFR, Secretary Office). Nation-state exploitation of PAM infrastructure. Source: US Treasury/CISA
- Coveware Q4 2024 report: 2024 was a banner year for law enforcement actions against ransomware. Ransom payment rates continuing downward trajectory. Source: https://www.coveware.com/blog/2025/1/31/q4-report
- Coveware Q1 2025 report: RaaS organizational structure evolving — model has not recovered from law enforcement disruption. Novice actors and non-Russian state-linked cybercriminals entering ecosystem. Source: https://www.coveware.com/blog/2025/4/29/the-organizational-structure-of-ransomware-threat-actor-groups-is-evolving-before-our-eyes
- Coveware Q2 2025 report: Targeted social engineering 'en vogue' — helpdesk SE widely adopted by multiple ransomware groups beyond Scattered Spider. Ransom payment sizes increase. Source: https://www.coveware.com/blog/2025/7/21/targeted-social-engineering-is-en-vogue-as-ransom-payment-sizes-increase
- BBC reports Medusa ransomware gang offered company employee 15% cut of ransom for network access. First documented case of traditional RaaS group pivoting to insider bribes. Source: https://www.bbc.com/news/articles/c3w5n903447o
- Coveware Q3 2025 report: Payment rates fall to 23% historic low (DXF-only at 19%). Akira and Qilin dominate. Insider threats emerging. Economics forcing ransomware actors from opportunistic to targeted. Source: https://www.coveware.com/blog/2025/10/24/insider-threats-loom-while-ransom-payment-rates-plummet
- Coveware publishes Nitrogen ESXi crypto bug analysis — Curve25519 memory corruption makes decryption mathematically impossible. Transforms ransomware into accidental wiper. Paying ransom will not assist victims. Source: https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug
- Coveware Q4 2025 report: Payment rates drop to ~20% new historic low. Average payment $591,988 (+57%). Mass data exfiltration campaigns losing efficacy — CL0P Oracle EBS campaign generated near-zero payments despite 'ideal' extortion conditions. Enterprises now default to non-payment. Source: https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025
- Arctic Wolf confirms active CVE-2026-1731 exploitation campaigns — SimpleHelp RAT, domain admin creation, PsExec/Impacket lateral movement. PAM compromise = keys-to-the-kingdom. Source: Arctic Wolf
- As of 2026-05-29, this ransomware-landscape analysis remains ACTIVE and escalating: Check Point's Q1 2026 report logged 2,122 DLS victims (attacks +58% YoY) with Qilin/Akira/The Gentlemen/LockBit 5.0 dominating a reconsolidating market. ESXi targeting surged ~700% (CVE-2025-22225 in CISA KEV, 30k+ exposed) and BYOVD standardized (54 EDR killers, 35 drivers), confirming every core thesis; no single CVE or actor to retire.
Sources cited for Ransomware Threat Landscape 2025-2027
- Coveware Q4 2025 — Mass Data Exfiltration Campaigns Lose Their Edge
- Coveware Q3 2025 — Insider Threats Loom
- Coveware — Nitrogen ESXi Bug
- Coveware Q2 2025 — Social Engineering Surge
- Coveware Q1 2025 — RaaS Organizational Evolution
- Coveware Q4 2024 — Law Enforcement Success
- Coveware Q1 2024 — RaaS Trust Collapse
- Verizon 2025 DBIR
- BBC — Medusa Insider Recruitment
- Threadlinqs Intelligence Database — Cross-Referenced Threats
Detection coverage for TL-2026-0115
As of 2026-02-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0115 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.