2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)

2026 Ransomware Surge Targeting US Organizations (TL-2026-2125), also tracked as Identity-First Ransomware Surge 2026, is a high-severity ransomware operation, first published 2026-08-23. It is attributed to Akira with medium confidence, affects Palo Alto Networks PAN-OS GlobalProtect, references 8 CVEs (CVE-2026-0257, CVE-2026-50751, CVE-2026-50752), maps to 15 MITRE ATT&CK techniques (T1003, T1021, T1133), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2125

Threat ID
TL-2026-2125
Also known as
Identity-First Ransomware Surge 2026, 2026 US Ransomware Wave
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-08-23
Last reviewed
2026-08-23
Attribution
Akira
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
construction, manufacturing, technology, health, legal-services, financial-services
Target regions
united states of america
Detection rules
9
Indicators of compromise
26

Malware and tooling in 2026 Ransomware Surge Targeting US Organizations

Malware and tooling: AgendaCrypt, Akira ransomware, Clop, Clop ransomware, DragonForce ransomware, INC Ransom ransomware, MimiKatz, PLAY Ransomware, Playcrypt - S1162, Qilin (Agenda) ransomware, Sinobi ransomware, banana_blackmail

Bitdefender reports 53 ransomware groups claimed US-based victims in January-February 2026 (roughly 750-800 US organizations hit), with seven groups — Qilin, Akira, Clop, INC Ransom, Play, DragonForce, and Sinobi — holding Top-10 rankings for four-plus consecutive months. The cohort is converging on credential/session-token theft over exploitation, AI-assisted automated exploitation (CyberStrikeAI), BYOVD tooling (EDRKillShifter, EDRSandblast, HRSword) to blind EDR, and living-off-the-cloud exfiltration via legitimate cloud/remote-access services.

How 2026 Ransomware Surge Targeting US Organizations works

Bitdefender's March 24, 2026 threat report documents a sustained ransomware surge against US organizations across January-February 2026, with 53 distinct ransomware groups claiming US-based victims and an estimated 750-800 US organizations compromised in the period. Seven groups — Qilin, Akira, Clop, INC Ransom, Play, DragonForce, and Sinobi — have held Top-10 activity rankings for over four consecutive months, reflecting a maturing ransomware-as-a-service (RaaS) ecosystem rather than a single campaign.

Across this cohort, Bitdefender identifies a shift to 'identity-first compromise': affiliates increasingly prioritize stealing browser session tokens, OAuth keys, and VPN/SSO credentials over active exploitation of vulnerabilities, because valid identity gives equivalent access with far less detection surface. Where exploitation is used, affiliates increasingly lean on automated PoC-to-exploit tooling — Bitdefender specifically calls out the open-source, AI-orchestrated CyberStrikeAI framework, which compressed the historical 2-3 day PoC-to-mass-exploitation window (2024-2025) down to a couple of hours or less. CyberStrikeAI was independently confirmed in a March 2026 campaign that compromised 600+ FortiGate firewalls across 55 countries, with researchers observing 21 unique operator IPs (China/Singapore/Hong Kong-hosted) running the tool between January 20 and February 26, 2026; it was developed by GitHub user Ed1s0nZ, who also authored the Go-based ransomware prototype banana_blackmail.

For defense evasion, the cohort is converging on BYOVD (Bring Your Own Vulnerable Driver) EDR-killer tooling — Bitdefender names EDRSandblast, HRSword, and EDRKillShifter specifically. EDRKillShifter was first deployed by RansomHub in August 2024 and has since been adopted by Play, Medusa, and BianLian, among others; it is a loader that drops and abuses a signed-but-vulnerable legitimate driver to terminate EDR/AV processes from kernel context. Bitdefender predicts BYOVD will appear in 75%+ of ransomware intrusions going forward. For exfiltration, groups are 'living off the cloud': repurposing legitimate cloud administrative functions (Box, AWS) and remote-access/file-transfer tools (Rclone, Proton Drive, FileZilla) to move stolen data out through channels that blend into normal SaaS/cloud traffic rather than deploying custom exfiltration malware.

Each of the seven named groups shows independently sourced, real-world confirmation of these patterns in 2026: Qilin (aka Agenda) affiliates exploited PAN-OS GlobalProtect authentication bypass CVE-2026-0257 (Arctic Wolf, intrusions investigated June 2026) and the critical Check Point Remote Access VPN/IKEv1 authentication bypass CVE-2026-50751 (CVSS 9.3, exploited in the wild from May 7, 2026, at least one incident attributed to a Qilin affiliate), alongside embedded Mimikatz LSASS/token theft, Chrome browser credential theft, PsExec/RDP lateral movement, Cobalt Strike C2, AnyDesk/Ngrok/LogMeIn remote access, Rclone/Proton Drive/FileZilla exfiltration, ransomware staging under C:\PerfLogs\, Windows event-log clearing, Defender real-time-protection disabling, and a distinctive registry persistence pattern (an asterisk followed by six randomized lowercase letters). Sinobi — a closed RaaS believed to be a rebrand/successor of Lynx (itself descended from INC) that grew from 40 claimed victims in September 2025 to 215+ by January 2026 — compromises SonicWall SSL VPN credentials via CVE-2024-53704 and encrypts with Curve-25519/AES-128-CTR. INC Ransom (900 cumulative leak-site victims as of August 17, 2026, 33 in the trailing 30 days) gains access via stolen/purchased credentials, RDP, and exploitation of Citrix NetScaler CVE-2023-3519 and 'Citrix Bleed' CVE-2023-4966, then uses PsExec/RDP for lateral movement, BYOVD for EDR evasion, Cobalt Strike/AnyDesk/ScreenConnect/TeamViewer for remote access, and password-protected-archive-then-Rclone for exfiltration. DragonForce operates a white-label RaaS 'cartel' (253 claimed H1-2026 victims, 590+ cumulative, a formal August 2025 LockBit cartel partnership taking a 20% cut) whose affiliates favor phishing/vishing credential theft, unpatched edge-device and RMM exploitation, brute-forced/stolen VPN credentials, SMB scanning, and wmic.exe-driven shadow-copy deletion, with a Conti-linked mutex observed in samples. Clop has pivoted to mass zero-day exploitation of PTC Windchill PDMLink/FlexPLM deserialization flaw CVE-2026-12569 (CVSS 9.8, exploited as a zero-day from early June 2026 per Ransom-ISAC, weeks before vendor patch) via a purpose-built Java web shell that decrypts credentials and enumerates repositories, claiming Shell, General Electric, and Philips among 43 victims in that campaign alone, and prioritizing data theft over encryption. Akira remains an FBI top-five most-investigated ransomware variant, subject of a joint CISA/FBI/DC3/HHS/Europol/France/Germany/Netherlands advisory (AA24-109A, originally April 18 2024, updated November 13 2025) designating it an imminent threat to critical infrastructure, with ties to Storm-1567/Howling Scorpius/Punk Spider/Gold Sahara and possible Conti lineage. Play (Playcrypt), subject of an updated June 4 2025 CISA/FBI/ASD advisory (AA23-352A) after 900+ victims since 2022, has also adopted EDRKillShifter-style BYOVD defense evasion.

Bitdefender notes construction as the single most-targeted sector, followed by manufacturing, technology, healthcare, and legal services, with technology-sector vendors specifically targeted as a pivot point into downstream financial-services, healthcare, and manufacturing customers (trusted-relationship/supply-chain targeting). The report forecasts continued expansion of ransomware-ecosystem specialization (dedicated IABs, pentesters, negotiators), rising targeting of edge devices/hypervisors/cloud services, and hacktivist-flavored extortion messaging tied to the Iran war backdrop.

MITRE ATT&CK techniques used in TL-2026-2125

Credential Access

T1003 OS Credential Dumping; T1528 Steal Application Access Token; T1555 Credentials from Password Stores

Lateral Movement

T1021 Remote Services

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing

Command and Control

T1219 Remote Access Tools

Impact

T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

Collection

T1560 Archive Collected Data

Exfiltration

T1567 Exfiltration Over Web Service

Execution

T1569 System Services

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in 2026 Ransomware Surge Targeting US Organizations

  • Palo Alto Networks — PAN-OS GlobalProtect
    Vulnerable versions: 12.1; 11.2; 11.1; 10.2
    Fixed in: per vendor advisory security.paloaltonetworks.com/CVE-2026-0257
  • Check Point — Remote Access VPN / Mobile Access / Spark Firewall (IKEv1 deployments)
    Vulnerable versions: deployments accepting legacy IKEv1 Remote Access clients without machine certificate
    Fixed in: Check Point hotfix per CVE-2026-50751 advisory
  • SonicWall — SSL VPN
    Vulnerable versions: affected by CVE-2024-53704
    Fixed in: per SonicWall advisory
  • PTC — Windchill PDMLink / FlexPLM
    Vulnerable versions: affected by CVE-2026-12569 deserialization flaw
    Fixed in: per PTC vendor patch
  • JetBrains — TeamCity On-Premises
    Vulnerable versions: affected by CVE-2024-27198
    Fixed in: per JetBrains advisory
  • Citrix — NetScaler ADC / Gateway
    Vulnerable versions: affected by CVE-2023-3519 and CVE-2023-4966 (Citrix Bleed)
    Fixed in: per Citrix advisory

Remediation for 2026 Ransomware Surge Targeting US Organizations

Patches

  • CVE-2026-0257 — Palo Alto Networks PAN-OS GlobalProtect security advisory
  • CVE-2026-50751 / CVE-2026-50752 — Check Point Remote Access VPN hotfix
  • CVE-2024-53704 — SonicWall SSL VPN advisory
  • CVE-2026-12569 — PTC Windchill vendor patch
  • CVE-2024-27198 — JetBrains TeamCity On-Premises
  • CVE-2023-3519 / CVE-2023-4966 — Citrix NetScaler ADC/Gateway

Immediate actions

  • Patch PAN-OS GlobalProtect against CVE-2026-0257 or disable the authentication-override cookie feature / rotate the override certificate
  • Patch Check Point Remote Access VPN/Mobile Access/Spark Firewall against CVE-2026-50751 or disable deprecated IKEv1 legacy client support
  • Patch SonicWall SSL VPN against CVE-2024-53704 and rotate any SSL-VPN credentials that may have been exposed
  • Patch PTC Windchill PDMLink/FlexPLM against CVE-2026-12569; hunt for anomalous Java web shells on Windchill servers
  • Patch JetBrains TeamCity On-Premises against CVE-2024-27198 and Citrix NetScaler ADC/Gateway against CVE-2023-3519 / CVE-2023-4966 (Citrix Bleed)
  • Enforce phishing-resistant MFA on VPN, SSO, and OAuth-consented applications to blunt identity-first / session-token-theft compromise

Workarounds

  • Disable PAN-OS GlobalProtect authentication-override cookies where patching is not immediately possible
  • Disable IKEv1 legacy VPN client support on Check Point gateways
  • Restrict administrative access to PTC Windchill servers to trusted network segments pending patch

Longer-term hardening

  • Deploy kernel driver allow/deny-listing (Microsoft vulnerable-driver blocklist / WDAC) to close BYOVD paths used by EDRKillShifter, EDRSandblast, and HRSword
  • Restrict or alert on Rclone, AnyDesk, ScreenConnect, TeamViewer, Ngrok, and LogMeIn execution outside approved change windows
  • Monitor and restrict outbound traffic to cloud storage/collaboration services (Box, AWS S3 admin APIs, Proton Drive) for living-off-the-cloud exfiltration
  • Extend third-party/vendor risk management to flag technology-sector suppliers as pivot points into financial services, healthcare, and manufacturing customers
  • Harden LSASS (Credential Guard / LSA protection) and browser credential stores against Mimikatz and Chrome credential-theft techniques

CVEs associated with 2026 Ransomware Surge Targeting US Organizations

CVE-2026-0257, CVE-2026-50751, CVE-2026-50752, CVE-2024-53704, CVE-2026-12569, CVE-2024-27198, CVE-2023-3519, CVE-2023-4966

Weaknesses (CWE) in 2026 Ransomware Surge Targeting US Organizations

CWE-287, CWE-502, CWE-306

Timeline of 2026 Ransomware Surge Targeting US Organizations

  • CISA and the FBI publish the original #StopRansomware Akira advisory (AA24-109A).
  • RansomHub is first observed deploying the EDRKillShifter BYOVD loader, later adopted by Play, Medusa, and BianLian.
  • CISA, FBI, and ASD's ACSC publish an updated Play (Playcrypt) ransomware advisory (AA23-352A) after 900+ claimed victims since 2022.
  • Sinobi ransomware's first known attack, launching what researchers assess as a rebrand/successor operation to Lynx (itself descended from INC).
  • DragonForce announces a formal cartel partnership with LockBit, taking a 20% cut to provide white-label encryptors and infrastructure.
  • CISA, FBI, DC3, HHS, Europol, and France/Germany/Netherlands national agencies update the Akira advisory, designating it an imminent threat to critical infrastructure.
  • Researchers begin observing 21 unique CyberStrikeAI operator IPs (China/Singapore/Hong Kong-hosted) in a campaign that would compromise 600+ FortiGate firewalls across 55 countries.
  • End of the observed CyberStrikeAI FortiGate-targeting operator-IP window.
  • The open-source, AI-orchestrated CyberStrikeAI exploitation framework is publicly reported as adopted by threat actors for automated mass exploitation.
  • Bitdefender publishes 'Ransomware Attacks Targeting US Organizations 2026,' the primary source for this threat, covering the January-February 2026 US surge.
  • Earliest observed in-the-wild exploitation of Check Point CVE-2026-50751, per Rapid7/Arctic Wolf telemetry.
  • Palo Alto Networks publishes the security advisory for PAN-OS GlobalProtect authentication bypass CVE-2026-0257.
  • Arctic Wolf Labs investigates multiple Qilin ransomware intrusions in June 2026 that used CVE-2026-0257 for initial access.
  • Check Point publishes the advisory for critical (CVSS 9.3) Remote Access VPN IKEv1 authentication bypass CVE-2026-50751, with at least one incident linked to a Qilin affiliate.
  • INC Ransom's leak site reaches 900 cumulative claimed victims across 71 countries, including 33 in the trailing 30 days.

Sources cited for 2026 Ransomware Surge Targeting US Organizations

Threats related to 2026 Ransomware Surge Targeting US Organizations

Detection coverage for TL-2026-2125

As of 2026-08-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2125 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats