2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi) — Threadlinqs Intelligence
As of 2026-08-23, 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi) is a high-severity ransomware threat attributed to Multiple RaaS operators: Qilin, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-2125 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Multiple RaaS operators: Qilin · FINANCIAL
Bitdefender reports 53 ransomware groups claimed US-based victims in January-February 2026 (roughly 750-800 US organizations hit), with seven groups — Qilin, Akira, Clop, INC Ransom, Play,
Bitdefender's March 24, 2026 threat report documents a sustained ransomware surge against US organizations across January-February 2026, with 53 distinct ransomware groups claiming US-based victims and an estimated 750-800 US organizations compromised in the period. Seven groups — Qilin, Akira, Clop, INC Ransom, Play, DragonForce, and Sinobi — have held Top-10 activity rankings for over four consecutive months, reflecting a maturing ransomware-as-a-service (RaaS) ecosystem rather than a single campaign.
Across this cohort, Bitdefender identifies a shift to 'identity-first compromise': affiliates increasingly prioritize stealing browser session tokens, OAuth keys, and VPN/SSO credentials over active exploitation of vulnerabilities, because valid identity gives equivalent access with far less detection surface. Where exploitation is used, affiliates increasingly lean on automated PoC-to-exploit tooling — Bitdefender specifically calls out the open-source, AI-orchestrated CyberStrikeAI framework, which compressed the historical 2-3 day PoC-to-mass-exploitation window (2024-2025) down to a couple of hours or less. CyberStrikeAI was independently confirmed in a March 2026 campaign that compromised 600+ FortiGate firewalls across 55 countries, with researchers observing 21 unique operator IPs (China/Singapore/Hong Kong-hosted) running the tool between January 20 and February 26, 2026; it was developed by GitHub user Ed1s0nZ, who also authored the Go-based ransomware prototype banana_blackmail.
For defense evasion, the cohort is converging on BYOVD (Bring Your Own Vulnerable Driver) EDR-killer tooling — Bitdefender names EDRSandblast, HRSword, and EDRKillShifter specifically. EDRKillShifter was first deployed by RansomHub in August 2024 and has since been adopted by Play, Medusa, and BianLian, among others; it is a loader that drops and abuses a signed-but-vulnerable legitimate driver to terminate EDR/AV processes from kernel context. Bitdefender predicts BYOVD will appear in 75%+ of ransomware intrusions going forward. For exfiltration, groups are 'living off the cloud': repurposing legitimate cloud administrative functions (Box, AWS) and remote-access/file-transfer tools (Rclone, Proton Drive, FileZilla) to move stolen data out through channels that blend into normal SaaS/cloud traffic rather than deploying custom exfiltration malware.
Each of the seven named groups shows independently sourced, real-world confirmation of these patterns in 2026: Qilin (aka Agenda) affiliates exploited PAN-OS GlobalProtect authentication bypass CVE-2026-0257 (Arctic Wolf, intrusions investigated June 2026) and the critical Check Point Remote Access VPN/IKEv1 authentication bypass CVE-2026-50751 (CVSS 9.3, exploited in the wild from May 7, 2026, at least one incident attributed to a Qilin affiliate), alongside embedded Mimikatz LSASS/token theft, Chrome browser credential theft, PsExec/RDP lateral movement, Cobalt Strike C2, AnyDesk/Ngrok/LogMeIn remote access, Rclone/Proton Drive/FileZilla exfiltration, ransomware staging under C:\PerfLogs\, Windows event-log clearing, Defender real-time-protection disabling, and a distinctive registry persistence pattern (an asterisk followed by six randomized lowercase letters). Sinobi — a closed RaaS believed to be a rebrand/successor of Lynx (itself descended from INC) that grew from 40 claimed victims in September 2025 to 215+ by January 2026 — compromises SonicWall SSL VPN credentials via CVE-2024-53704 and encrypts with Curve-25519/AES-128-CTR. INC Ransom (900 cumulative leak-site victims as of August 17, 2026, 33 in the trailing 30 days) gains access via stolen/purchased credentials, RDP, and exploitation of Citrix NetScaler CVE-2023-3519 and 'Citrix Bleed' CVE-2023-4966, then uses PsExec/RDP for lateral movement, BYOVD for EDR evasion, Cobalt Strike/AnyDesk/ScreenConnect/TeamViewer for remote access, and password-protected-archive-then-Rclone for exfiltration. DragonForce operates a white-label RaaS 'cart
Weaknesses (CWE)
CWE-287, CWE-502, CWE-306
Target sectors: construction, manufacturing, technology, health, legal-services, financial-services
Target regions: united states of america
Timeline
- CISA and the FBI publish the original #StopRansomware Akira advisory (AA24-109A).
- RansomHub is first observed deploying the EDRKillShifter BYOVD loader, later adopted by Play, Medusa, and BianLian.
- CISA, FBI, and ASD's ACSC publish an updated Play (Playcrypt) ransomware advisory (AA23-352A) after 900+ claimed victims since 2022.
- Sinobi ransomware's first known attack, launching what researchers assess as a rebrand/successor operation to Lynx (itself descended from INC).
- DragonForce announces a formal cartel partnership with LockBit, taking a 20% cut to provide white-label encryptors and infrastructure.
- CISA, FBI, DC3, HHS, Europol, and France/Germany/Netherlands national agencies update the Akira advisory, designating it an imminent threat to critical infrastructure.
- Researchers begin observing 21 unique CyberStrikeAI operator IPs (China/Singapore/Hong Kong-hosted) in a campaign that would compromise 600+ FortiGate firewalls across 55 countries.
- End of the observed CyberStrikeAI FortiGate-targeting operator-IP window.
- The open-source, AI-orchestrated CyberStrikeAI exploitation framework is publicly reported as adopted by threat actors for automated mass exploitation.
- Bitdefender publishes 'Ransomware Attacks Targeting US Organizations 2026,' the primary source for this threat, covering the January-February 2026 US surge.
- Earliest observed in-the-wild exploitation of Check Point CVE-2026-50751, per Rapid7/Arctic Wolf telemetry.
- Palo Alto Networks publishes the security advisory for PAN-OS GlobalProtect authentication bypass CVE-2026-0257.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2026-0257, CVE-2026-50751, CVE-2026-50752, CVE-2024-53704, CVE-2026-12569, CVE-2024-27198, CVE-2023-3519, CVE-2023-4966, T1190, T1133, T1566, T1199, T1569, T1547, T1685, T1555, T1003, T1528