France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge
France Threat Landscape (TL-2026-1652), also tracked as France Dark Web, Ransomware & Hacktivism Report, is a high-severity ransomware and hacktivist operation, first published 2026-07-23. It is attributed to Qilin (Russia) with medium confidence, affects N/A French local government / municipal administrative systems, maps to 33 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-1652
- Threat ID
- TL-2026-1652
- Also known as
- France Dark Web, Ransomware & Hacktivism Report, #BrokenByte
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE_HACKTIVISM
- First published
- 2026-07-23
- Last reviewed
- 2026-07-23
- Attribution
- Qilin
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government administration, local government, municipal administration, financial services, technology, telecoms, transport, energy, aviation, automotive, manufacturing, cultural institutions
- Target regions
- france, Europe
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in France Threat Landscape
Malware and tooling: AgendaCrypt, LockBit, MedusaLocker, Bobik, DDoSia, DDoSia multi-tiered C2, Mimikatz, PSEXEC
CloudSEK reports a 4x surge in France-related dark web activity over 24 months (~17,800 items, dark-web volume rising from under 300/month mid-2024 to over 1,400/month January 2026), driven primarily by infostealer credential logs and resale rather than targeted intrusion. Ransomware groups Qilin (8 advisories, Commune d'Eyguières re-listed repeatedly), MedusaLocker (Mairie Thiverval-Grignon, 162 emails exfiltrated), and LockBit (recurring, opportunistic cross-sector) are active against French local government and small organizations, while pro-Russian hacktivist group NoName057(16) runs a sustained DDoS and access-claim campaign (742 France-tagged items in 6 months) against French government ministries, transport, energy, and defense-adjacent manufacturers tied to France's support for Ukraine.
How France Threat Landscape works
CloudSEK's Global Threat Intelligence (GTI) platform documents a 4x increase in France-tagged dark web activity over the trailing 24 months, from under 300 items/month in mid-2024 to over 1,400 items/month in January 2026, settling above 1,000/month through spring 2026, for a cumulative total of approximately 17,800 items (data leaks, credential dumps, ransomware advisories, and hacktivist claims). The leading data types are account credentials (4,447), credential collections (4,360), combined datasets (4,011), and breached records (3,565), overwhelmingly the product of commodity infostealer malware harvesting logs at scale and reselling them through underground forums rather than sophisticated targeted intrusion. Top targeted sectors by volume are government (1,652), financial services (1,594), technology (1,491), telecommunications (1,480), and email (1,427).
Ransomware activity against France over the trailing six months totals 213 victim advisories, concentrated on local government and small organizations (0-10 employees). Qilin — a Rust-based (rebuilt from an earlier Go variant) RaaS operation offering affiliates up to 85% revenue share, operating a Tor-hosted double-extortion leak site, and ranked among the top-five ransomware groups globally by 2025 victim count — posted the Commune d'Eyguières across eight separate advisory listings within 24 hours (June 20-21, 2026), a re-listing pattern used to maximize negotiation pressure. Qilin's initial access relies on VPN credential theft (via infostealer logs, credential stuffing, and exploitation of unpatched VPN appliances) and spear-phishing against high-privilege staff; it has been observed harvesting Chrome browser credentials domain-wide via GPO-distributed scripts and, since October 2025, abusing Windows Subsystem for Linux (WSL) to execute ransomware payloads and evade Windows-native EDR. Lateral movement leverages RDP, PsExec, WMI, and Mimikatz.
MedusaLocker — a distinct RaaS lineage from the unrelated 'Medusa' ransomware (subject of CISA/FBI/MS-ISAC advisory AA25-071A) — claimed Mairie Thiverval-Grignon, extracting and threatening to publish 162 internal municipal email addresses under dual-attribution posting. MedusaLocker's documented TTPs (per joint CISA/FBI/Treasury/FinCEN advisory) center on brute-forcing and exploiting exposed RDP (External Remote Services, Valid Accounts) for initial access, followed by PowerShell/batch-script execution and network-wide file encryption targeting shared drives.
LockBit maintains a recurring, opportunistic, cross-sector presence against French targets; the group's most recent iteration, LockBit 5.0, ships Windows (AES-256-CTR/RSA-2048), Linux (AES-256-CBC/Curve25519), and VMware ESXi-specific payloads, uses randomized 9-character encrypted file extensions, employs BYOVD techniques (RTCore64.sys, dbutil_2_3.sys) to disable EDR/AV, and terminates backup and security-tool processes (Veeam, SQL, Oracle, Exchange, VSS, Sophos, CrowdStrike, SentinelOne, Carbon Black, Cylance) prior to encryption. LockBit has a documented history against French high-value targets including the French Ministry of Justice, and French law enforcement has participated in coordinated international arrests of LockBit-affiliated developers.
Separately, pro-Russian hacktivist collective NoName057(16) (active since March 2022, operating the crowdsourced 'DDoSia' volunteer-DDoS platform, successor to the earlier 'Bobik' botnet) generated 742 France-tagged dark-web items over six months, explicitly motivated by France's support for Ukraine. Campaigns under the '#BrokenByte' banner targeted drone manufacturers Xsun France and iDrone with application-layer DDoS; the group also claimed unauthorized CCTV access against the Musée National de l'Automobile (Mulhouse) and a Renault/Dacia dealership (video surveillance and client PII access claims), and ran coordinated DDoS against French government ministries (Economy, Justice, Finance, Interior), the Civil Aviation Authority, and the National Reception Office. In January 2026 the group additionally claimed attacks on La Poste/La Banque Postale, the Rennes Metro, the Angers Tramway, French airports, the national road-safety agency, and multiple EDF (national energy utility) portals — a coordinated multi-sector critical-infrastructure campaign. NoName057(16)'s DDoSia client is a Go-based tool distributed via Telegram (t.me/DDosiabot), where volunteers register for a unique 'User Hash' and receive cryptocurrency rewards for participation; the client authenticates to a multi-tiered C2 infrastructure (Tier-1 servers refresh roughly every nine days, proxying to access-controlled Tier-2 servers) using AES-GCM-encrypted JSON payloads over HTTP POST /client/login and GET /client/get_targets, with randomized User-Agent strings and Base32-encoded padding to evade filtering. Attack activity clusters in two daily waves (05:00-07:00 UTC and around 11:00 UTC on weekdays), consistent with a standard Russian working schedule. Across a prior 12-month window (July 2024-July 2025), France accounted for 6.09% of the group's global targeting, concentrated in government/public sector (41.09%), transportation/logistics (12.44%), and technology/media/communications (10.19%). International law enforcement action (Eurojust-coordinated) has produced two arrests (including one preliminary arrest in France) and 24 house searches across Europe, without disrupting operational tempo.
The surge is compounded by regulatory findings underscoring systemic weaknesses in French data protection: CNIL fined Free Mobile/Free EUR 42M in January 2026 for inadequate security controls after 24.6 million subscriber contracts were exposed, and fined France Travail EUR 5M the same month after 43 million job-seeker records were exposed due to weak authentication and excessive access permissions — both incidents feeding the same infostealer/credential-resale ecosystem CloudSEK tracks.
MITRE ATT&CK techniques used in TL-2026-1652
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force; T1555 Credentials from Password Stores
Collection
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Privilege Escalation
T1055 Process Injection; T1068 Exploitation for Privilege Escalation; T1484 Domain or Tenant Policy Modification
Execution
T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Discovery
T1083 File and Directory Discovery
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1498 Network Denial of Service; T1499 Endpoint Denial of Service
Resource Development
defense-impairment
Affected products and versions in France Threat Landscape
- N/A — French local government / municipal administrative systems
Vulnerable versions: Unpatched/exposed RDP and VPN appliances
Fixed in: N/A - no CVE disclosed - N/A — Public-facing government, transport, and utility web portals (DDoS exposure)
Vulnerable versions: Unmitigated web infrastructure without DDoS/WAF protection
Fixed in: N/A
Remediation for France Threat Landscape
Patches
- No CVEs disclosed in source reporting; apply vendor patches for any exposed VPN/RDP-facing appliances per standard vulnerability management
Immediate actions
- Disable or strictly VPN-gate exposed RDP; enforce MFA on all remote access and VPN appliances
- Patch and monitor VPN appliances for known exploited vulnerabilities; rotate credentials exposed in infostealer logs
- Deploy anti-DDoS/WAF and rate-limiting for public-facing government and utility web portals ahead of predictable weekday attack windows (05:00-07:00 UTC, ~11:00 UTC)
- Block known DDoSia C2 infrastructure and Telegram-based coordination channels at the network egress layer
- Restrict and monitor WSL (Windows Subsystem for Linux) usage on endpoints; alert on WSL-hosted binary execution
- Harden Group Policy Object (GPO) distribution channels against unauthorized script deployment (Chrome credential-harvesting vector)
Workarounds
- Disable RDP where not operationally required; require jump-host + MFA for any remaining RDP access
- Rate-limit and geofence public web portals against high-volume application-layer request floods
Longer-term hardening
- Deploy EDR with behavioral detection tuned for LOTL techniques (PsExec, WMI, Mimikatz) and BYOVD driver-loading
- Implement immutable, offline/air-gapped backups resilient to VSS deletion and backup-service termination
- Network segmentation to limit lateral movement from RDP/VPN entry points into municipal and government administrative systems
- User awareness training on credential-harvesting infostealers and spear-phishing targeting high-privilege staff
- Continuous dark-web/credential-leak monitoring to detect stolen credentials before resale/exploitation
Weaknesses (CWE) in France Threat Landscape
CWE-287, CWE-798, CWE-400
Timeline of France Threat Landscape
- NoName057(16) pro-Russian hacktivist collective emerges, launching DDoS operations against Ukraine-supporting states
- CloudSEK's 24-month tracking window begins; France-tagged dark web activity under 300 items/month
- CISA/FBI/MS-ISAC publish joint advisory AA25-071A on the (unrelated) Medusa ransomware variant, documenting over 300 victims
- Qilin observed abusing Windows Subsystem for Linux (WSL) to execute ransomware payloads and evade Windows-native EDR detection
- NoName057(16) claims coordinated DDoS campaign against La Poste/La Banque Postale, Rennes Metro, Angers Tramway, French airports, national road-safety agency, and multiple EDF energy portals
- Barracuda reports Qilin ransomware surging into 2026, ranked among top-five global ransomware operations by victim count
- CNIL fines France Travail EUR 5M after exposure of 43 million job-seeker records due to weak authentication and excessive access permissions
- CNIL fines Free Mobile/Free EUR 42M for inadequate security after exposure of 24.6 million subscriber contracts
- Qilin claims cyberattack against French IT distributor Exclusive Networks, threatening data release absent negotiation
- Classic-Days.fr breached by actor 'Saturne'; 11GB database including plaintext passwords, activation keys, and source code exposed, tracing to SQL injection vulnerabilities dating to 2024
- MedusaLocker claims Mairie Thiverval-Grignon, exfiltrating and threatening to publish 162 internal municipal email addresses under dual attribution
- France-tagged dark web activity volume settles above 1,000 items/month through spring into summer 2026, confirming sustained 4x baseline increase
- Qilin re-lists Commune d'Eyguières across eight separate advisory postings within 24 hours (June 20-21, 2026)
- Qilin's Commune d'Eyguières advisory re-listing campaign concludes after eighth posting
- CloudSEK queries CNIL public sanction records and publishes the France Dark Web, Ransomware & Hacktivism Report synthesizing the 24-month trend
Sources cited for France Threat Landscape
- France Dark Web, Ransomware & Hacktivism Report
- Qilin Ransomware Attack Targets French IT Distributor Exclusive Networks
- Qilin Ransomware: Group Profile, TTPs, IOCs & Defense (2026)
- Qilin ransomware surges into 2026
- Dark Web Profile: Qilin (Agenda) Ransomware
- Ransomware.live: Qilin group tracker
- Inside DDoSia: NoName057(16)'s Pro-Russian DDoS Campaign Infrastructure
- Pro-Russian hackers claim attack on French postal service operator
- NoName057/NoName05716: DDoS Threat Intel & Defense Guide
- La France est elle vraiment ciblée par NoName057(16) ?
- Noname057(16) - Wikipedia
- The La Poste attack in France was a coordinated campaign that targeted critical infrastructure
- Hacktivist group responsible for cyberattacks on critical infrastructure in Europe taken down
- #StopRansomware: Medusa Ransomware
- Medusa Ransomware: IOCs, MITRE TTPs & Detection
Threats related to France Threat Landscape
- Human-Operated Ransomware via GPO Abuse — Domain-Wide Encryption Through Group Policy Weaponization
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver (CVE-2025-7771)
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands
- LockBit 5.0 Cross-Platform Ransomware Analysis
- Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led)
- BYOVD EDR Killer Tooling — Ransomware Groups Weaponizing Signed Kernel Drivers to Blind Endpoint Detection
Detection coverage for TL-2026-1652
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1652 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.