Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge — Threadlinqs Intelligence
As of 2026-08-22, Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge is a medium-severity ransomware threat attributed to Qilin, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-2110 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: Qilin · FINANCIAL
Cyble's August 2026 landscape report maps five recurring endpoint blind spots ransomware operators exploit for access and persistence: abused remote-access tooling (VPN/RDP/RMM), credential harvesting
Cyble published "Ransomware Attack Vectors and Endpoint Blind Spots" on 2026-08-21, synthesizing its 2025-2026 ransomware telemetry into five recurring blind spots that operators exploit to gain and keep access. The report sits against a landscape in which Cyble Research and Intelligence Labs (CRIL) tracked 6,604 ransomware attacks in 2025 (up 52% from 4,346 in 2024), catalogued 57 new ransomware groups and 27 new extortion groups, and identified more than 350 new ransomware strains, the majority built on the MedusaLocker, Chaos, and Makop codebases. Emerging groups adopted double extortion immediately to maximize leverage.
Blind spot 1 (remote-access abuse): Qilin affiliates abuse WinSCP, AnyDesk, and ScreenConnect for lateral movement, then pivot across SMB, RDP, WinRM, and PsExec, typically exfiltrating within 3-5 days of initial access before detonating a Rust-based encryptor. In October 2025, Qilin was observed combining a Linux-based ransomware payload deployed on Windows hosts (via WinSCP/Splashtop) with a BYOVD exploit in a hybrid attack chain, and in 2025 the group added a DDoS capability as a third extortion lever alongside encryption and leak-site pressure.
Blind spot 2 (credential harvesting on compromised endpoints): CRIL tracks a staged credential-theft toolkit combining Mimikatz with NirSoft utilities (WebBrowserPassView, BypassCredGuard, SharpDecryptPwd) and a WDigest registry modification that forces Windows to cache plaintext credentials, feeding downstream LSASS dumping. This is frequently paired with BYOVD (Bring Your Own Vulnerable Driver) to blind EDR/AV before the credential toolkit or encryptor runs; documented 2025-2026 BYOVD cases include a December 2025 Talos-tracked DeadLock ransomware loader abusing a vulnerable Baidu Antivirus driver to kill EDR processes and disable Windows Defender, and a February 2026 Reynolds ransomware sample that embedded a vulnerable NsecSoft driver (CVE-2025-68947) directly in its payload.
Blind spot 3 (vendor/supply-chain island hopping): nation-state actor Silk Typhoon breached MSPs and cloud/remote-management providers via VPN zero-days, password spraying, and misconfigured privileged access, then pivoted into downstream customer environments using inherited admin credentials and compromised service principals. China-aligned PlushDaemon trojanized a South Korean VPN vendor's installer with the SlowStepper backdoor, turning a trusted remote-access tool into an espionage vector. On the ransomware side, newly emerged groups RALord/Nova, Warlock, Sinobi, The Gentlemen, and BlackNevas specifically targeted software supply chains, concentrating on the IT & ITES, Technology, and Transportation & Logistics sectors, while Cl0p's exploitation of Oracle E-Business Suite vulnerabilities produced downstream supply-chain impact across more than 118 entities globally. Software supply-chain attacks overall rose 93% year-over-year to 297 in 2025, with ransomware groups responsible for more than half.
Blind spot 4 (OT/ICS bridged to corporate IT): 119 ransomware groups targeted industrial organizations in 2025, a 49% increase from 80 in 2024, and 3,300 industrial organizations were hit versus 1,693 in 2024, with manufacturing the most-targeted vertical. Only 30% of OT networks retain monitoring capable of detecting an intrusion before operational impact, 81% of assessed environments have poor IT/OT segmentation, and the all-time average OT ransomware dwell time is 42 days -- IT/OT convergence lets ransomware that lands on the corporate network reach the plant floor largely unseen.
Blind spot 5 (targeted business-email phishing): phishing and malicious email account for roughly 37% of ransomware initial access. Highly targeted, often AI-generated phishing now achieves click rates up to 54% versus 12% for conventional lures, and the fastest 2025 intrusions reached data exfiltration in as little as 72 minutes from initial access.
Cyble's own Jan-Apr 2025 Ransomware Threat Landscape re
Target sectors: manufacturing, technology, information-technology, transportation-and-logistics, government administration, energy-and-utilities, critical-infrastructure
Target regions: Global
Timeline
- Cyble's Jan-Apr 2025 measurement window opens; global ransomware incidents begin an 86% quarter-over-quarter surge.
- Cl0p compromises more than 330 victims in February-March 2025 by exploiting Oracle E-Business Suite vulnerabilities, described as the most intense ransomware surge publicly recorded to that point, with downstream supply-chain impact across 118+ entities.
- Close of Cyble's Jan-Apr 2025 window: global ransomware incidents up 86%, with Cl0p accounting for 28% of that period's activity; emerging groups Devman, Sinobi, Warlock, and Gunra concentrate on Government & LEA and Energy & Utilities targets.
- Cisco Talos documents Qilin's attack methods across multiple cases, detailing credential-harvesting and remote-tool abuse patterns.
- Qilin is observed combining a Linux-based ransomware payload deployed on Windows hosts (via WinSCP/Splashtop) with a BYOVD exploit in a hybrid attack chain.
- Talos tracks a DeadLock ransomware BYOVD loader abusing a vulnerable Baidu Antivirus driver to terminate EDR processes and disable Windows Defender.
- CRIL tallies 6,604 ransomware attacks for 2025 (up 52% from 4,346 in 2024), 57 new ransomware groups, 27 new extortion groups, and 350+ new ransomware strains built largely on MedusaLocker, Chaos, and Makop.
- Reynolds ransomware embeds a vulnerable NsecSoft driver (CVE-2025-68947) directly within its payload, eliminating a separate EDR-killing deployment step.
- Cyble publishes 'Ransomware Attack Vectors and Endpoint Blind Spots', identifying the five recurring blind spots synthesized in this record.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1133, T1566, T1195.002, T1199, T1078, T1685, T1112, T1003.001, T1555.003, T1570