Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation — Threadlinqs Intelligence
As of 2026-07-19, Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation is a critical-severity ransomware threat attributed to Qilin, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0758 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: RANSOMWARE
Updated: 2026-07-19 · revalidated 1× · latest source
Attribution: Qilin · FINANCIAL
Check Point Research recorded 2,122 ransomware victims on data-leak sites in Q1 2026 (second-highest Q1 on record). Qilin led for a third straight quarter (338 victims), LockBit 5.0 rebuilt its
Q1 2026 was the second-busiest first quarter on record for ransomware data-leak-site (DLS) extortion, with Check Point Research counting 2,122 victims posted across January (732), February (684) and March (706). The top 10 groups accounted for 71.1% of all DLS victims, and the ecosystem remained heavily US-weighted (~49.6% of victims).
Qilin remained the most prolific operation for a third consecutive quarter with 338 victims. The Gentlemen — a Ransomware-as-a-Service (RaaS) operation founded by former Qilin affiliate 'Hastalamuerte' after a dispute over an unpaid $48,000 commission — exploded +315% from 40 victims in Q4 2025 to 166, reaching third place globally and claiming 53% of all Thai victims. LockBit returned with LockBit 5.0 (launched September 2025), rebuilding its affiliate base +106% to 163 victims; the new build added multi-platform support (Windows, Linux, ESXi), required new affiliates to post a ~$500 Bitcoin deposit, and shifted ~21.2% of its targeting to the US. Play (121, +64%), DragonForce (101, +29%), Nightspire (82, +183%) and Akira rounded out the leaders, while Sinobi (-42%), SafePay (-77%) and Devman (-70%) declined — the Devman operator was added to Interpol's wanted list in January 2026.
Two CVEs drove much of the quarter's initial access. The Gentlemen leveraged CVE-2024-55591, a FortiOS/FortiProxy authentication-bypass (CWE-288, CVSS 9.8) allowing remote super-admin via crafted requests to the Node.js websocket module, maintaining an inventory of ~14,700 pre-exploited FortiGate devices plus 969 brute-forced VPN credentials. Post-exploitation, the group replaced commercial Cobalt Strike with a custom G-BOT C2 framework (per-beacon SOCKS5 tunneling), enumerated Active Directory with NetExec and MANSPIDER, and conducted NTLM relay attacks with ntlmrelayx/RelayKing — also tracking CVE-2025-32433 (Erlang/OTP SSH) and CVE-2025-33073 (NTLM relay). Separately, Cl0p (overlapping with FIN11) mass-exploited CVE-2025-61882, an unauthenticated RCE in Oracle E-Business Suite Concurrent Processing / BI Publisher Integration (CWE-287, CVSS 9.8), as a zero-day from as early as August 9, 2025. The exploit chains SSRF, CRLF injection, authentication bypass and XSL template injection (malicious templates written to the XDO_TEMPLATES_B table with TMP/DEF prefixes) to achieve in-memory RCE, deploying the SAGEGIFT → SAGELEAF → SAGEWAVE Java loader chain and the GOLDVEIN.JAVA downloader. A high-volume extortion-email wave began September 29, 2025; Oracle shipped emergency patches October 4 and October 11, 2025, after the exploit leaked via the 'SCATTERED LAPSUS$ HUNTERS' Telegram group on October 3.
Weaknesses (CWE)
CWE-288, CWE-287, CWE-918, CWE-93, CWE-91, CWE-22, CWE-444, CWE-501, CWE-95
Target sectors: business services, healthcare, manufacturing, consumer goods, financial, government, technology
Target regions: North America, Europe, South America, Asia-Pacific, Australia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2024-55591, CVE-2025-61882, CVE-2025-61884, CVE-2025-32433, CVE-2025-33073, T1190, T1133, T1078, T1110, T1187, T1555, T1059, T1106, T1505, T1098