# Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting, BYOVD as Standard Prep, Double/Triple Extortion Economics, IAB Vertical Integration, Critical Infrastructure Escalation

> Strategic landscape analysis of ransomware ecosystem evolution from 2025 through early 2026: RaaS model destabilization from law enforcement disruption and affiliate trust collapse, record-low payment rates (~20% Q4 2025), data-exfiltration-only extortion losing efficacy, Conti leak spawning 6+ derivative families, ESXi hypervisor targeting as force multiplier, BYOVD as standard pre-encryption preparation, insider recruitment as novel initial access, and the emergence of targeted social engineering replacing opportunistic intrusion

- **Published:** 2026-02-06T12:00:00Z
- **Last reviewed:** 2026-02-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0115
- **ID:** TL-2026-0115
- **Severity:** CRITICAL
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The ransomware threat landscape in 2025-2026 is undergoing its most significant structural transformation since the emergence of double-extortion in 2019-2020. This analysis synthesizes intelligence from Coveware quarterly reports (Q3 2025, Q4 2025), Verizon DBIR 2025, Arctic Wolf incident response data, and Threadlinqs Intelligence database entries covering 10+ ransomware-linked threats to provide a comprehensive strategic overview of the evolving ransomware ecosystem.

**1. RaaS MODEL DESTABILIZATION — THE TRUST COLLAPSE**

The Ransomware-as-a-Service model that powered Conti, Hive, LockBit, and BlackCat/ALPHV has fundamentally destabilized. Three simultaneous forces drove this collapse:

(a) Law enforcement disruption: 2024 was a banner year for LE actions against ransomware groups. Operation Cronos dismantled LockBit's infrastructure in February 2024, seized servers, published affiliate identities, and released decryptors. While LockBit attempted revival, its reputation among affiliates was permanently damaged by the exposure of internal data showing LockBit retained victim data even after payment.

(b) Affiliate trust fracture: In Q1 2024, both LockBit and BlackCat/ALPHV were caught cheating their own affiliates — withholding payments, stealing credentials, and operating deceptively (per Coveware). BlackCat executed a brazen exit scam in March 2024 after receiving the $22M Change Healthcare ransom, posting a fake FBI seizure notice while absconding with funds. This dual collapse splintered the affiliate market and destroyed trust in the RaaS franchise model.

(c) Payment rate decline: Ransom payment rates have plummeted to historic lows — approximately 20% in Q4 2025 (Coveware), down from 30-40% in 2022-2023. Data-exfiltration-only payment rates dropped to 19% in Q3 2025 and approximately 25% in Q4 2025. CL0P's five successive mass exploitation campaigns (Accellion 2021 → GoAnywhere 2023 → MOVEit 2023 → Cleo 2024 → Oracle EBS 2025) demonstrate the economic degradation: payment rates fell from ~25% (Accellion) to ~2.5% (MOVEit) to 0% (Cleo) as organizations learned that paying for data suppression offers no durable benefit.

The RaaS framework that brought Conti, Hive, and LockBit to prominence is unlikely to succeed in its prior form. Coveware assesses that increasingly dire economics are forcing ransomware actors to be less opportunistic and more creative — pivoting to social engineering, insider recruitment, and targeted attacks against 'white whale' enterprises.

**2. CONTI LEAK WEAPONIZATION CASCADE**

The August 2022 Conti source code leak (Conti 2 builder) spawned at least 6 derivative ransomware families, fundamentally democratizing ransomware capability:

- Nitrogen/Azote (TL-2026-0105): Derivative with fatal ESXi crypto bug — Curve25519 memory corruption makes decryption permanently impossible even with cooperation. Malvertising via Google/Bing ads for IT tools.
- Royal → BlackSuit: Conti successor led by former Conti member 'Zeon'. Royal rebranded to BlackSuit in mid-2024 after attribution pressure.
- BlackByte: Conti offshoot using AES-256 + RSA-4096, known for attacking critical infrastructure.
- Meow: Data-exfiltration-focused Conti derivative, sells stolen data on clearnet marketplace.
- Monti: Close Conti code reuse, targets Linux/ESXi with Conti v2 builder output.
- LukaLocker: Conti-derived ransomware associated with infrastructure targeting.

The Conti leak transformed ransomware from a specialist capability to a commodity. Any moderately skilled operator can now build functional ransomware from leaked source code, lowering the barrier to entry and fragmenting the market into dozens of small operations.

**3. ESXi HYPERVISOR TARGETING — THE FORCE MULTIPLIER**

VMware ESXi has become the highest-value ransomware target because a single hypervisor hosts dozens of virtual machines. Encrypting one ESXi host can cripple an entire organization's infrastructure simultaneously. Key developments:

- ESXi-specific variants: Nearly every major ransomware family now includes a Linux/ESXi variant (Akira, LockBit, Royal/BlackSuit, Nitrogen, Qilin, Play, RansomHub).
- ESXi attack pattern: SSH brute-force or credential reuse → disable ESXi firewall → kill VM processes (esxcli vm process kill) → encrypt VMFS datastores (.vmdk, .vmx, .vmem, .vswp, .nvram).
- Nitrogen accidental wiper (TL-2026-0105): Nitrogen's ESXi variant has a fatal Curve25519 implementation bug — a QWORD write at rsp+0x1c overwrites 4 bytes of the public key at rsp+0x20, corrupting the Diffie-Hellman exchange. The resulting symmetric key is derived from a corrupted public key for which no corresponding private key exists. Decryption is mathematically impossible. Even paying the ransom cannot recover data. This transforms 'ransomware' into an 'accidental wiper.'
- Detection vacuum: Many organizations lack syslog forwarding from ESXi hosts to SIEM, making ESXi encryption invisible until VMs stop responding. ESXi is the single most dangerous detection gap in enterprise ransomware defense.

**4. BYOVD AS STANDARD RANSOMWARE PREPARATION**

Bring Your Own Vulnerable Driver (BYOVD) has evolved from a niche technique to standard pre-encryption preparation. Ransomware operators load signed but vulnerable kernel drivers to kill EDR/AV from Ring 0 before deploying the encryptor:

- truesight.sys (TL-2026-0105 Nitrogen): RogueKiller Antirootkit driver used to kill 59 security tools from kernel mode. Listed on LOLDrivers.io.
- AuKill: Kills Sophos, SentinelOne, and other EDR products using Process Explorer driver (procexp.sys).
- Poortry/Stonestop (TL-2026-0091): Sophisticated loader+driver combination used by multiple groups including Scattered Spider. Driver signed with stolen certificates.
- EDRKillShifter: Custom EDR-killing framework that rotates between multiple vulnerable drivers.
- BackConnect AnyDesk BYOVD: Uses legitimate remote access tools to sideload vulnerable drivers.
- The BYOVD taxonomy (TL-2026-0091) documents 11 cross-references across the Threadlinqs database, demonstrating how pervasive this technique has become.

BYOVD effectiveness stems from a fundamental architectural weakness: Windows kernel-mode drivers run with the same privileges as security tools. A valid signed driver that contains a vulnerability can be used to terminate any process, including EDR agents. Until Windows enforces HVCI/WDAC driver allowlists universally, BYOVD will remain a reliable EDR bypass.

**5. EMERGING INITIAL ACCESS EVOLUTION**

(a) Insider recruitment: The BBC documented Medusa ransomware offering a company employee 15% of the ransom payment for network access (Coveware Q3 2025). This represents a fundamental shift — traditional RaaS used opportunistic vectors (access brokers, stolen credentials, known vulns). Shrinking profits are driving actors to targeted, higher-cost methods including insider bribes.

(b) Targeted social engineering: Helpdesk social engineering, pioneered by Scattered Spider, has been widely adopted across numerous encryption and data extortion gangs in 2025. Silent Ransom (Luna Moth) uses callback phishing targeting insurance and law firms. The merge of remote access compromise and social engineering means adversaries obtain access by convincing someone to provision it, not by exploiting a technical flaw.

(c) Malvertising as targeted self-selection: Nitrogen's Google/Bing ad campaigns for IT tools (WinSCP, KeePass, PuTTY, AnyDesk) create self-selecting targeting — victims are IT administrators with elevated privileges who actively search for the tools they use daily.

(d) PAM/trusted tool exploitation: CVE-2026-1731 BeyondTrust (TL-2026-0110) demonstrates that privileged access management tools are prime targets. Compromising PAM = instant domain control because PAM stores/manages credentials for the entire organization.

**6. MARKET STRUCTURE — Q4 2025**

Coveware Q4 2025 data shows the market is bifurcating:
- Top variants: #1 Akira (14%), #2 Qilin (13%), #3 Lone Wolf (12%), #4 CL0P (7%), #5 Silent Ransom (6%), #6 Shiny Hunters (4%).
- The top two (Akira, Qilin) both use encryption as primary impact driver. Slots 3-6 are data-exfiltration-only operations.
- Average ransom payment Q4 2025: $591,988 (+57% from Q3). Median: $325,000 (+132% from Q3). The divergence reflects isolated high-impact settlements, not broad willingness to pay.
- Encryption-driven payments remain higher than data-exfiltration-only payments, suggesting a return to encryption as the primary extortion lever.
- Coveware predicts actors may return to encryption roots as data-exfiltration-only economics collapse.

**7. LAW ENFORCEMENT & REGULATORY EVOLUTION**

Operation Cronos (LockBit, Feb 2024), BlackCat exit-scam exposure, and ongoing LE doxxing of threat actors have raised the personal risk for ransomware operators. CISA KEV mandates, SEC cyber incident reporting rules (Dec 2023), and expanded breach notification requirements are creating regulatory pressure that makes paying ransoms increasingly untenable from a governance perspective.

**8. PREDICTIONS — 2026-2027**

- Return to encryption: As data-exfiltration-only economics collapse (CL0P model degraded from 25% to 0% payment rates), actors will refocus on encryption as the primary lever.
- White whale targeting: Shrinking margins will drive concentration on large enterprises where single payments justify higher intrusion costs.
- Insider threat expansion: The Medusa insider recruitment model will be replicated as social engineering and bribes become viable alternatives to technical exploitation.
- ESXi becomes primary target: ESXi encryption will be the default deployment target because of force multiplication (1 host = dozens of VMs).
- BYOVD standardization: Every serious ransomware operation will include BYOVD as pre-encryption preparation.
- AI-assisted operations: Ransomware groups will increasingly use AI for vulnerability discovery (already happening — Hacktron AI discovered CVE-2026-1731), negotiation automation, and social engineering content generation.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1566.002 Spearphishing Link
- T1189 Drive-by Compromise
- T1078 Valid Accounts
- T1199 Trusted Relationship
- T1059.001 PowerShell
- T1136.002 Domain Account
- T1219 Remote Access Tools
- T1068 Exploitation for Privilege Escalation
- T1685 Disable or Modify Tools
- T1553.002 Code Signing
- T1003.001 LSASS Memory
- T1555 Credentials from Password Stores
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1560 Archive Collected Data
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1489 Service Stop
- T1485 Data Destruction
- T1588.001 Malware
- T1569.002 Service Execution
- T1547.001 Registry Run Keys / Startup Folder
- T1588.002 Tool
- T1688 Safe Mode Boot
- T1567.002 Exfiltration to Cloud Storage
- T1657 Financial Theft
- T1555.003 Credentials from Web Browsers
- T1547.006 Kernel Modules and Extensions

## Sources

- [Coveware Q4 2025 — Mass Data Exfiltration Campaigns Lose Their Edge](https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025)
- [Coveware Q3 2025 — Insider Threats Loom](https://www.coveware.com/blog/2025/10/24/insider-threats-loom-while-ransom-payment-rates-plummet)
- [Coveware — Nitrogen ESXi Bug](https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug)
- [Coveware Q2 2025 — Social Engineering Surge](https://www.coveware.com/blog/2025/7/21/targeted-social-engineering-is-en-vogue-as-ransom-payment-sizes-increase)
- [Coveware Q1 2025 — RaaS Organizational Evolution](https://www.coveware.com/blog/2025/4/29/the-organizational-structure-of-ransomware-threat-actor-groups-is-evolving-before-our-eyes)
- [Coveware Q4 2024 — Law Enforcement Success](https://www.coveware.com/blog/2025/1/31/q4-report)
- [Coveware Q1 2024 — RaaS Trust Collapse](https://www.coveware.com/blog/2024/4/17/raas-devs-hurt-their-credibility-by-cheating-affiliates-in-q1-2024)
- [Verizon 2025 DBIR](https://www.verizon.com/business/resources/reports/dbir/)
- [BBC — Medusa Insider Recruitment](https://www.bbc.com/news/articles/c3w5n903447o)
- [Threadlinqs Intelligence Database — Cross-Referenced Threats](https://intel.threadlinqs.com/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0115
