France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge — Threadlinqs Intelligence
As of 2026-07-23, France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge is a high-severity ransomware hacktivism threat attributed to Qilin (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1652 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE_HACKTIVISM
Attribution: Qilin · Russia · FINANCIAL
CloudSEK reports a 4x surge in France-related dark web activity over 24 months (~17,800 items, dark-web volume rising from under 300/month mid-2024 to over 1,400/month January 2026), driven primarily
CloudSEK's Global Threat Intelligence (GTI) platform documents a 4x increase in France-tagged dark web activity over the trailing 24 months, from under 300 items/month in mid-2024 to over 1,400 items/month in January 2026, settling above 1,000/month through spring 2026, for a cumulative total of approximately 17,800 items (data leaks, credential dumps, ransomware advisories, and hacktivist claims). The leading data types are account credentials (4,447), credential collections (4,360), combined datasets (4,011), and breached records (3,565), overwhelmingly the product of commodity infostealer malware harvesting logs at scale and reselling them through underground forums rather than sophisticated targeted intrusion. Top targeted sectors by volume are government (1,652), financial services (1,594), technology (1,491), telecommunications (1,480), and email (1,427).
Ransomware activity against France over the trailing six months totals 213 victim advisories, concentrated on local government and small organizations (0-10 employees). Qilin — a Rust-based (rebuilt from an earlier Go variant) RaaS operation offering affiliates up to 85% revenue share, operating a Tor-hosted double-extortion leak site, and ranked among the top-five ransomware groups globally by 2025 victim count — posted the Commune d'Eyguières across eight separate advisory listings within 24 hours (June 20-21, 2026), a re-listing pattern used to maximize negotiation pressure. Qilin's initial access relies on VPN credential theft (via infostealer logs, credential stuffing, and exploitation of unpatched VPN appliances) and spear-phishing against high-privilege staff; it has been observed harvesting Chrome browser credentials domain-wide via GPO-distributed scripts and, since October 2025, abusing Windows Subsystem for Linux (WSL) to execute ransomware payloads and evade Windows-native EDR. Lateral movement leverages RDP, PsExec, WMI, and Mimikatz.
MedusaLocker — a distinct RaaS lineage from the unrelated 'Medusa' ransomware (subject of CISA/FBI/MS-ISAC advisory AA25-071A) — claimed Mairie Thiverval-Grignon, extracting and threatening to publish 162 internal municipal email addresses under dual-attribution posting. MedusaLocker's documented TTPs (per joint CISA/FBI/Treasury/FinCEN advisory) center on brute-forcing and exploiting exposed RDP (External Remote Services, Valid Accounts) for initial access, followed by PowerShell/batch-script execution and network-wide file encryption targeting shared drives.
LockBit maintains a recurring, opportunistic, cross-sector presence against French targets; the group's most recent iteration, LockBit 5.0, ships Windows (AES-256-CTR/RSA-2048), Linux (AES-256-CBC/Curve25519), and VMware ESXi-specific payloads, uses randomized 9-character encrypted file extensions, employs BYOVD techniques (RTCore64.sys, dbutil_2_3.sys) to disable EDR/AV, and terminates backup and security-tool processes (Veeam, SQL, Oracle, Exchange, VSS, Sophos, CrowdStrike, SentinelOne, Carbon Black, Cylance) prior to encryption. LockBit has a documented history against French high-value targets including the French Ministry of Justice, and French law enforcement has participated in coordinated international arrests of LockBit-affiliated developers.
Separately, pro-Russian hacktivist collective NoName057(16) (active since March 2022, operating the crowdsourced 'DDoSia' volunteer-DDoS platform, successor to the earlier 'Bobik' botnet) generated 742 France-tagged dark-web items over six months, explicitly motivated by France's support for Ukraine. Campaigns under the '#BrokenByte' banner targeted drone manufacturers Xsun France and iDrone with application-layer DDoS; the group also claimed unauthorized CCTV access against the Musée National de l'Automobile (Mulhouse) and a Renault/Dacia dealership (video surveillance and client PII access claims), and ran coordinated DDoS against French government ministries (Economy, Justice, Finance, Interior), the Civil Aviation
Weaknesses (CWE)
CWE-287, CWE-798, CWE-400
Target sectors: government administration, local government, municipal administration, financial services, technology, telecoms, transport, energy, aviation, automotive, manufacturing, cultural institutions
Target regions: france, Europe
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE_HACKTIVISM, HIGH, threat intelligence, cybersecurity, T1078, T1566, T1566, T1133, T1190, T1059, T1059, T1072, T1547, T1053