Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge

Ransomware Attack Vectors (TL-2026-2110) is a medium-severity ransomware operation, first published 2026-08-22. It is attributed to Qilin with medium confidence, affects Multiple Enterprise remote-access infrastructure (VPN, RDP, maps to 13 MITRE ATT&CK techniques (T1003.001, T1021.001, T1078), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2110

Threat ID
TL-2026-2110
Severity
MEDIUM
Status
ACTIVE
Category
RANSOMWARE
First published
2026-08-22
Last reviewed
2026-08-22
Attribution
Qilin
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, technology, information-technology, transportation-and-logistics, government administration, energy-and-utilities, critical-infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in Ransomware Attack Vectors

Malware and tooling: AgendaCrypt, AnyDesk, Chaos, Clop, DEVMAN, Makop, MedusaLocker, MimiKatz, AnyDesk, Mimikatz, NirSoft utilities (WebBrowserPassView, BypassCredGuard, SharpDecryptPwd), ScreenConnect

Cyble's August 2026 landscape report maps five recurring endpoint blind spots ransomware operators exploit for access and persistence: abused remote-access tooling (VPN/RDP/RMM), credential harvesting on compromised endpoints, vendor/supply-chain island hopping, unpatched OT/ICS bridged to corporate IT, and highly targeted business-email phishing. It documents Qilin affiliates abusing WinSCP, AnyDesk, and ScreenConnect for lateral movement plus BYOVD to disable EDR, and CRIL-tracked operators using Mimikatz and NirSoft utilities for credential theft.

How Ransomware Attack Vectors works

Cyble published "Ransomware Attack Vectors and Endpoint Blind Spots" on 2026-08-21, synthesizing its 2025-2026 ransomware telemetry into five recurring blind spots that operators exploit to gain and keep access. The report sits against a landscape in which Cyble Research and Intelligence Labs (CRIL) tracked 6,604 ransomware attacks in 2025 (up 52% from 4,346 in 2024), catalogued 57 new ransomware groups and 27 new extortion groups, and identified more than 350 new ransomware strains, the majority built on the MedusaLocker, Chaos, and Makop codebases. Emerging groups adopted double extortion immediately to maximize leverage.

Blind spot 1 (remote-access abuse): Qilin affiliates abuse WinSCP, AnyDesk, and ScreenConnect for lateral movement, then pivot across SMB, RDP, WinRM, and PsExec, typically exfiltrating within 3-5 days of initial access before detonating a Rust-based encryptor. In October 2025, Qilin was observed combining a Linux-based ransomware payload deployed on Windows hosts (via WinSCP/Splashtop) with a BYOVD exploit in a hybrid attack chain, and in 2025 the group added a DDoS capability as a third extortion lever alongside encryption and leak-site pressure.

Blind spot 2 (credential harvesting on compromised endpoints): CRIL tracks a staged credential-theft toolkit combining Mimikatz with NirSoft utilities (WebBrowserPassView, BypassCredGuard, SharpDecryptPwd) and a WDigest registry modification that forces Windows to cache plaintext credentials, feeding downstream LSASS dumping. This is frequently paired with BYOVD (Bring Your Own Vulnerable Driver) to blind EDR/AV before the credential toolkit or encryptor runs; documented 2025-2026 BYOVD cases include a December 2025 Talos-tracked DeadLock ransomware loader abusing a vulnerable Baidu Antivirus driver to kill EDR processes and disable Windows Defender, and a February 2026 Reynolds ransomware sample that embedded a vulnerable NsecSoft driver (CVE-2025-68947) directly in its payload.

Blind spot 3 (vendor/supply-chain island hopping): nation-state actor Silk Typhoon breached MSPs and cloud/remote-management providers via VPN zero-days, password spraying, and misconfigured privileged access, then pivoted into downstream customer environments using inherited admin credentials and compromised service principals. China-aligned PlushDaemon trojanized a South Korean VPN vendor's installer with the SlowStepper backdoor, turning a trusted remote-access tool into an espionage vector. On the ransomware side, newly emerged groups RALord/Nova, Warlock, Sinobi, The Gentlemen, and BlackNevas specifically targeted software supply chains, concentrating on the IT & ITES, Technology, and Transportation & Logistics sectors, while Cl0p's exploitation of Oracle E-Business Suite vulnerabilities produced downstream supply-chain impact across more than 118 entities globally. Software supply-chain attacks overall rose 93% year-over-year to 297 in 2025, with ransomware groups responsible for more than half.

Blind spot 4 (OT/ICS bridged to corporate IT): 119 ransomware groups targeted industrial organizations in 2025, a 49% increase from 80 in 2024, and 3,300 industrial organizations were hit versus 1,693 in 2024, with manufacturing the most-targeted vertical. Only 30% of OT networks retain monitoring capable of detecting an intrusion before operational impact, 81% of assessed environments have poor IT/OT segmentation, and the all-time average OT ransomware dwell time is 42 days -- IT/OT convergence lets ransomware that lands on the corporate network reach the plant floor largely unseen.

Blind spot 5 (targeted business-email phishing): phishing and malicious email account for roughly 37% of ransomware initial access. Highly targeted, often AI-generated phishing now achieves click rates up to 54% versus 12% for conventional lures, and the fastest 2025 intrusions reached data exfiltration in as little as 72 minutes from initial access.

Cyble's own Jan-Apr 2025 Ransomware Threat Landscape report frames the acute end of this trend: global ransomware incidents rose 86% quarter-over-quarter, Cl0p alone accounted for 28% of that period's activity, and in February-March 2025 Cl0p compromised more than 330 victims via Oracle E-Business Suite exploitation -- described as the most intense ransomware surge publicly recorded to that point. Newly emerged groups such as Devman, Sinobi, Warlock, and Gunra concentrated heightened attacks on Government & LEA and Energy & Utilities critical-infrastructure targets during the same window.

MITRE ATT&CK techniques used in TL-2026-2110

Credential Access

T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers

Lateral Movement

T1021.001 Remote Desktop Protocol; T1570 Lateral Tool Transfer

Persistence

T1078 Valid Accounts

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Initial Access

T1133 External Remote Services; T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship; T1566 Phishing

Command and Control

T1219 Remote Access Tools

Impact

T1657 Financial Theft

Affected products and versions in Ransomware Attack Vectors

  • Multiple — Enterprise remote-access infrastructure (VPN, RDP, RMM/remote-support tools)
    Vulnerable versions: Not version-specific; technique/tooling abuse, not a patchable vulnerability
  • Multiple — OT/ICS environments network-connected to corporate IT and cloud platforms
    Vulnerable versions: Not version-specific; architectural/segmentation exposure

Remediation for Ransomware Attack Vectors

Patches

  • No vendor CVE was disclosed in this report; apply the Microsoft vulnerable/blocked driver list to mitigate the specific BYOVD drivers referenced (e.g. CVE-2025-68947)

Immediate actions

  • Enforce phishing-resistant MFA on all VPN, RDP, and RMM/remote-access endpoints
  • Restrict and allow-list which remote-access/RMM tools (AnyDesk, ScreenConnect, WinSCP, Splashtop) are permitted to run in the environment; alert on unauthorized installs
  • Deploy EDR tamper-protection / kernel driver block-lists (e.g. Microsoft vulnerable driver blocklist) to reduce BYOVD exposure
  • Monitor for Mimikatz, NirSoft utility execution, and WDigest UseLogonCredential registry modifications on endpoints
  • Segment OT/ICS networks from corporate IT and disable unnecessary cross-boundary connectivity

Workarounds

  • Where RMM tools are not business-required, disable or remove them from endpoint images
  • Restrict LSASS access via Credential Guard / Protected Process Light where compatible with the environment

Longer-term hardening

  • Implement vendor/third-party risk assessments and least-privilege access for MSP and supply-chain integrations to reduce island-hopping exposure
  • Deploy OT-aware network monitoring to close the visibility gap below the IT/OT boundary
  • Adopt behavioral/AI-aware email security to counter high-click-rate AI-generated phishing
  • Build and rehearse a ransomware incident-response plan covering double-extortion and DDoS-as-leverage scenarios

Timeline of Ransomware Attack Vectors

  • Cyble's Jan-Apr 2025 measurement window opens; global ransomware incidents begin an 86% quarter-over-quarter surge.
  • Cl0p compromises more than 330 victims in February-March 2025 by exploiting Oracle E-Business Suite vulnerabilities, described as the most intense ransomware surge publicly recorded to that point, with downstream supply-chain impact across 118+ entities.
  • Close of Cyble's Jan-Apr 2025 window: global ransomware incidents up 86%, with Cl0p accounting for 28% of that period's activity; emerging groups Devman, Sinobi, Warlock, and Gunra concentrate on Government & LEA and Energy & Utilities targets.
  • Cisco Talos documents Qilin's attack methods across multiple cases, detailing credential-harvesting and remote-tool abuse patterns.
  • Qilin is observed combining a Linux-based ransomware payload deployed on Windows hosts (via WinSCP/Splashtop) with a BYOVD exploit in a hybrid attack chain.
  • Talos tracks a DeadLock ransomware BYOVD loader abusing a vulnerable Baidu Antivirus driver to terminate EDR processes and disable Windows Defender.
  • CRIL tallies 6,604 ransomware attacks for 2025 (up 52% from 4,346 in 2024), 57 new ransomware groups, 27 new extortion groups, and 350+ new ransomware strains built largely on MedusaLocker, Chaos, and Makop.
  • Reynolds ransomware embeds a vulnerable NsecSoft driver (CVE-2025-68947) directly within its payload, eliminating a separate EDR-killing deployment step.
  • Cyble publishes 'Ransomware Attack Vectors and Endpoint Blind Spots', identifying the five recurring blind spots synthesized in this record.

Sources cited for Ransomware Attack Vectors

More in ransomware

Detection coverage for TL-2026-2110

As of 2026-08-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2110 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats