France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months
France Dark Web Threat Landscape (TL-2026-2564), also tracked as France Cyber Threat Outlook, is a high-severity tracked intrusion set, first published 2026-09-18. It is attributed to Qilin with medium confidence, affects Commune d'Eyguieres Municipal administrative network, maps to 17 MITRE ATT&CK techniques (T1003.001, T1021.005, T1059.001), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-2564
- Threat ID
- TL-2026-2564
- Also known as
- France Cyber Threat Outlook, #BrokenByte
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-18
- Last reviewed
- 2026-09-18
- Attribution
- Qilin
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- government administration, financial services, technology, telecoms, retail, ecommerce, education, health, automotive, aviation
- Target regions
- france, Europe
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in France Dark Web Threat Landscape
Malware and tooling: AgendaCrypt, Dataleak, Dosia, LockBit, MedusaLocker, telegram, DDoSia
CloudSEK's 24-month dark web monitoring of France-tagged activity (mid-2024 to spring 2026) documents a 4x rise in leaks, credential dumps, ransomware advisories, and hacktivist claims, peaking above 1,400 items/month in January 2026 (~17,800 items total). Qilin and MedusaLocker ransomware repeatedly hit under-resourced French municipalities, while pro-Russian hacktivist group NoName057(16) ran a sustained #BrokenByte DDoS/access-claim campaign tied to France's support for Ukraine, alongside commodity infostealer credential resale driving the bulk of volume.
How France Dark Web Threat Landscape works
CloudSEK's "France Cyber Threat Outlook" report (published 2026-07-23, authors Abhishek Mathew and Prajwal Awasthi) analyzes 24 months of France-tagged dark web activity, finding roughly 17,800 total items across leaks, credential dumps, ransomware advisories, and hacktivist claims. Monthly volume held under 350 items through most of 2024, climbed steadily through 2025, roughly doubled between June and December 2025, and peaked above 1,400 items/month in January 2026 before plateauing above 1,000/month through spring 2026 -- an overall 4x baseline increase. Government (1,652 items), financial services (1,594), technology (1,491), telecommunications (1,480), and email (1,427) were the most-tagged sectors; account credentials and credential collections were the dominant data types (4,447 and 4,360 items respectively).
The ransomware track is dominated by RaaS groups repeatedly targeting under-resourced French local government bodies. Qilin (aka Agenda) posted 8 separate leak-site advisories re-listing the same victim, Commune d'Eyguieres, between 20-21 June 2026 -- a pressure/sustained-extortion pattern rather than eight distinct intrusions. MedusaLocker claimed an attack on Mairie Thiverval-Grignon, extracting 162 email addresses from the municipal administration. LockBit maintains a recurring, cross-sector opportunistic presence in France. Per CISA/FBI/Treasury/FinCEN joint advisory AA22-181A, MedusaLocker actors gain initial access via vulnerable RDP configurations and phishing, use a batch file to trigger a malicious PowerShell script for network propagation, and inhibit recovery by deleting shadow copies and backups before encryption. Qilin's documented technique set (MITRE ATT&CK software S1242) spans phishing and public-facing application exploitation for initial access, LSASS credential dumping, PowerShell/Windows Command Shell execution, and double-extortion data encryption.
The hacktivist track is led by NoName057(16), a pro-Russian group assessed by CISA (advisory AA25-343A) to have originated as a covert project within the Kremlin-linked Centre for the Study and Network Monitoring of the Youth Environment (CISM). Running its #BrokenByte campaign explicitly tied to France's support for Ukraine, the group claimed DDoS attacks against French drone manufacturers Xsun France and iDrone, against the Ministries of Economy, Justice, Finance, and Interior plus the Civil Aviation Authority and National Reception Office, and claimed unauthorized CCTV/video-surveillance access at the Musee National de l'Automobile (Mulhouse) and a Renault/Dacia dealership (Groupe GGP, Orange), framing the latter as part of a "special military operation in cyberspace." NoName057(16) coordinates its crowdsourced, cryptocurrency-incentivized DDoS tool DDoSia via Telegram; CISA's advisory further documents the wider pro-Russia hacktivist ecosystem (CARR, Z-Pentest, Sector16) scanning for and brute-forcing internet-exposed VNC services (port 5900+) to access OT/HMI interfaces at critical-infrastructure operators.
Commodity infostealer-driven credential resale accounts for the bulk of the volume increase rather than targeted campaigns: dark web actors SKYNET (635 France-tagged postings) and WhiteMelly (614) lead bulk PII/credential sale and leak distribution; actor 587306 sold ~2 million records described as belonging to French women for $399 via Mega; actor Saturne disclosed an 11GB Classic-Days.fr database (plaintext passwords, source code) exposed through an unsecured Apache directory listing with SQL injection attempts dating to 2024; and actor HiddenHq claimed a 1 billion+ record, 2.3TB dataset allegedly sourced via a Salesforce-linked supply-chain breach affecting 36 companies. Separately, Cegedim Sante's MonLogicielMedical.com platform exposed administrative data on ~15 million French patients.
The surge coincides with escalating French regulatory enforcement: CNIL fined Free Mobile/Free a combined EUR 42 million in January 2026 over a 2024 breach exposing 24.6 million subscriber contracts, and fined France Travail EUR 5 million over a breach exposing up to 43 million job seekers -- the largest breach in French history by record count. Under GDPR Article 33, breaches must be reported to CNIL within 72 hours; 2024 alone saw over 5,600 breach notifications covering more than 145 million records of French residents.
MITRE ATT&CK techniques used in TL-2026-2564
Credential Access
T1003.001 LSASS Memory; T1110.003 Password Spraying; T1555 Credentials from Password Stores
Lateral Movement
Execution
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment
Impact
T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1498.001 Direct Network Flood; T1657 Financial Theft
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Resource Development
T1583.003 Virtual Private Server
Reconnaissance
T1591 Gather Victim Org Information; T1595.002 Vulnerability Scanning
defense-impairment
Affected products and versions in France Dark Web Threat Landscape
- Commune d'Eyguieres — Municipal administrative network
Vulnerable versions: Qilin ransomware target, 8 advisories 20-21 June 2026 - Mairie Thiverval-Grignon — Municipal administrative network
Vulnerable versions: MedusaLocker ransomware target, 162 emails extracted - Xsun France / iDrone — Corporate web infrastructure
Vulnerable versions: NoName057(16) #BrokenByte DDoS target - Musee National de l'Automobile — CCTV / video surveillance system
Vulnerable versions: Unauthorized access claimed by NoName057(16) - Groupe GGP (Renault/Dacia dealership, Orange) — Video surveillance and internal client-data systems
Vulnerable versions: Unauthorized access claimed by NoName057(16) - French government ministries (Economy, Justice, Finance, Interior); Civil Aviation Authority; National Reception Office — Public-facing web infrastructure
Vulnerable versions: DDoS target of NoName057(16) via DDoSia - Cegedim Sante — MonLogicielMedical.com medical practice software
Vulnerable versions: ~15 million French patient administrative records exposed - Classic-Days.fr — E-commerce web application
Vulnerable versions: Exposed Apache directory listing; SQL injection attempts since 2024; 11GB database breach June 2026
Remediation for France Dark Web Threat Landscape
Patches
- No CVE or vendor patch applies to this multi-actor threat landscape report; mitigation is configuration- and process-based (RDP/VNC exposure reduction, credential hygiene, backup resilience, input validation against SQL injection)
Immediate actions
- Disable or restrict internet-facing RDP and VNC services; where required, enforce MFA and source-IP allow-listing (per CISA AA22-181A and AA25-343A)
- Rotate credentials and audit for default, weak, or reused passwords on any internet-accessible remote administration or OT/HMI interface
- Remediate exposed directory listings and SQL injection vectors on public-facing web/e-commerce applications (per the Classic-Days.fr breach root cause)
Workarounds
- Restrict RDP/VNC access to VPN-only connections with MFA enforced; disable direct internet exposure of HMI, CCTV, and other OT-adjacent interfaces per CISA AA25-343A guidance
Longer-term hardening
- Maintain offline, immutable, and tested backups to blunt ransomware double-extortion leverage from Qilin and MedusaLocker
- Deploy DDoS mitigation/scrubbing and CDN protection for public-facing government and critical-infrastructure sites against DDoSia-style volumetric floods (T1498.001)
- Segment OT/ICS and physical-security (CCTV/video surveillance) networks from IT and the public internet; remove default credentials from HMI and camera systems
Weaknesses (CWE) in France Dark Web Threat Landscape
CWE-89
Timeline of France Dark Web Threat Landscape
- CloudSEK's monitoring window begins with France-tagged dark web activity under 300 items/month (mid-2024 baseline).
- CY2024 closes with over 5,600 breach notifications to CNIL, covering more than 145 million records belonging to French residents.
- France-tagged dark web volume roughly doubles between June 2025 and December 2025 per CloudSEK's monthly trend data.
- CNIL fines France Travail EUR 5 million over a breach exposing up to 43 million job seekers' data, the largest breach in French history by record count.
- CNIL fines Free Mobile/Free a combined EUR 42 million for inadequate security measures contributing to a 2024 breach exposing 24.6 million subscriber contracts.
- France-tagged dark web activity peaks above 1,400 items/month, the highest point in CloudSEK's 24-month dataset.
- Volume plateaus above 1,000 items/month through spring 2026, holding well above the mid-2024 baseline.
- Dark web actor Saturne discloses an 11GB Classic-Days.fr database breach (plaintext passwords, activation keys, internal source code) traced to an exposed Apache directory listing with SQL injection attempts dating back to 2024.
- Qilin begins re-listing Commune d'Eyguieres across at least 8 separate ransomware leak-site advisory postings, continuing through 2026-06-21.
- CloudSEK publishes the "France Cyber Threat Outlook: Dark Web, Ransomware & Hacktivism Report," documenting the full 24-month trend.
Sources cited for France Dark Web Threat Landscape
- France Cyber Threat Outlook: Dark Web, Ransomware & Hacktivism Report
- Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure (AA25-343A)
- #StopRansomware: MedusaLocker (AA22-181A)
- MedusaLocker - JOINT CYBERSECURITY ADVISORY (PDF)
- Qilin, Software S1242
- Qilin Ransomware Analysis: Critical TTPs and Defense
- Unmasking NoName057(16): Botnets, DDoSia, and NATO
- Noname057(16)
More in threat intel
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)
Detection coverage for TL-2026-2564
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2564 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.