Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands — Threadlinqs Intelligence
As of 2026-07-26, Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands is a medium-severity ransomware threat attributed to Nitrogen (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-1710 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: Nitrogen · Russia · FINANCIAL
Proofpoint's 2026 AI-Era Ransomware Report (953 security professionals, 12 countries) finds 54% of ransomware-affected organizations globally paid an initial ransom, and 37% of those payers were
Proofpoint's 2026 AI-Era Ransomware Report surveyed 953 cybersecurity professionals across 12 countries (US, UK, France, Germany, Italy, Spain, UAE, Australia, Japan, Singapore, India, Brazil) and 20 industry sectors between March and April 2026. The headline finding is that ransomware has evolved from a single encryption event into a sustained, multi-stage extortion campaign: 65% of affected organizations said AI had measurably improved the attacks that precede ransomware deployment (more convincing phishing, BEC, credential harvesting, and malicious-link lures), and 66% of victims had sensitive data stolen before or alongside encryption. Globally, 54% of affected organizations paid a ransom, yet 37% of those payers were hit with a second extortion demand — meaning payment increasingly buys temporary relief rather than closure. Regional variation was stark: 58% of UK organizations paid (of whom 22% faced repeat extortion), 93% of US organizations paid, and only 19% of Japanese organizations paid, a spread Proofpoint attributes to differing regulatory environments, recovery capability, insurance incentive structures, and cultural norms around disclosure and negotiation. Two percent of all payers never recovered their encrypted files regardless of payment.
The report and its press coverage (DataBreaches.net, The Register) ground the repeat-extortion trend in two concrete, named-actor case studies. LockBit, the prolific Russia-linked ransomware-as-a-service (RaaS) operation administered by Dmitry Yuryevich Khoroshev (alias 'LockBitSupp'), claimed over 2,000 victims and more than $120M in ransom payments before international law enforcement's Operation Cronos seized 34 servers across eight countries on 19 February 2024, recovered roughly 1,000 decryption keys, froze 200+ cryptocurrency accounts, and arrested affiliates in Poland and Ukraine. Critically, investigators discovered that LockBit had not deleted victims' exfiltrated data as promised after ransom payment — the exact repeat-extortion risk Proofpoint's survey quantifies. Khoroshev was subsequently indicted on 26 counts in US federal court and sanctioned by the US, UK, and Australia, with a $10M US State Department reward for his arrest.
The second case study, Nitrogen, is a ransomware operation that emerged in 2023 as an initial-access loader for the BlackCat/ALPHV RaaS operation before evolving into an independent double-extortion ransomware group by late 2024, using code derived from the leaked Conti 2 builder and tradecraft overlapping with former BlackCat affiliates. Nitrogen's primary initial-access technique is malvertising: fraudulent, highly-ranked Google ads distribute trojanized installers of legitimate admin tools (WinSCP, AnyDesk, Advanced IP Scanner, PuTTY), delivered inside archives (e.g., 'Version.zip') containing a masqueraded, DLL-side-loaded Python interpreter. A documented September 2024 intrusion (analyzed in depth by The DFIR Report) shows the full kill chain: drive-by malvertising compromise, Sliver and Cobalt Strike beacon deployment via Py-Fuscate-obfuscated Python loaders, LSASS credential dumping (first local-admin, then domain-admin credentials within hours), BloodHound/PowerView/Impacket-driven AD discovery and lateral movement over RDP and SMB admin shares, Restic-based exfiltration to a Bulgaria-hosted REST server, and — roughly 156 hours after initial access — deployment of BlackCat/ALPHV ransomware via PsExec, preceded by Safe Mode boot reconfiguration, Volume Shadow Copy deletion, and mass Windows event-log clearing. In February 2026, researchers at Coveware disclosed that Nitrogen's own ESXi ransomware variant contains a memory-offset coding error that corrupts the RSA/Curve25519 public key during encryption, meaning even Nitrogen's own decryptor cannot recover encrypted ESXi hosts — converting a financially-motivated attack into irreversible destruction regardless of whether the ransom is paid. In May 2026, Nitrogen listed electronics
Weaknesses (CWE)
CWE-125, CWE-502, CWE-284, CWE-22, CWE-787
Target sectors: government administration, finance, health, manufacturing, technology, construction, electronics, aerospace, critical-infrastructure, education, retail, professional-services
Target regions: North America, united states of america, united kingdom, Europe, japan, Asia-Pacific, australia, Middle East, UAE, india, brazil, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, CVE-2023-4966, CVE-2023-4967, CVE-2023-0669, CVE-2023-27350, CVE-2018-13379, CVE-2020-0796, T1189, T1190, T1204.002, T1059.001, T1059.003, T1059.006, T1569.002, T1047, T1098, T1053.005