France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months

France Dark Web Threat Landscape (TL-2026-2564), also tracked as France Cyber Threat Outlook, is a high-severity tracked intrusion set, first published 2026-09-18. It is attributed to Qilin with medium confidence, affects Commune d'Eyguieres Municipal administrative network, maps to 17 MITRE ATT&CK techniques (T1003.001, T1021.005, T1059.001), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2564

Threat ID
TL-2026-2564
Also known as
France Cyber Threat Outlook, #BrokenByte
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-18
Last reviewed
2026-09-18
Attribution
Qilin
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
government administration, financial services, technology, telecoms, retail, ecommerce, education, health, automotive, aviation
Target regions
france, Europe
Detection rules
9
Indicators of compromise
24

Malware and tooling in France Dark Web Threat Landscape

Malware and tooling: AgendaCrypt, Dataleak, Dosia, LockBit, MedusaLocker, telegram, DDoSia

CloudSEK's 24-month dark web monitoring of France-tagged activity (mid-2024 to spring 2026) documents a 4x rise in leaks, credential dumps, ransomware advisories, and hacktivist claims, peaking above 1,400 items/month in January 2026 (~17,800 items total). Qilin and MedusaLocker ransomware repeatedly hit under-resourced French municipalities, while pro-Russian hacktivist group NoName057(16) ran a sustained #BrokenByte DDoS/access-claim campaign tied to France's support for Ukraine, alongside commodity infostealer credential resale driving the bulk of volume.

How France Dark Web Threat Landscape works

CloudSEK's "France Cyber Threat Outlook" report (published 2026-07-23, authors Abhishek Mathew and Prajwal Awasthi) analyzes 24 months of France-tagged dark web activity, finding roughly 17,800 total items across leaks, credential dumps, ransomware advisories, and hacktivist claims. Monthly volume held under 350 items through most of 2024, climbed steadily through 2025, roughly doubled between June and December 2025, and peaked above 1,400 items/month in January 2026 before plateauing above 1,000/month through spring 2026 -- an overall 4x baseline increase. Government (1,652 items), financial services (1,594), technology (1,491), telecommunications (1,480), and email (1,427) were the most-tagged sectors; account credentials and credential collections were the dominant data types (4,447 and 4,360 items respectively).

The ransomware track is dominated by RaaS groups repeatedly targeting under-resourced French local government bodies. Qilin (aka Agenda) posted 8 separate leak-site advisories re-listing the same victim, Commune d'Eyguieres, between 20-21 June 2026 -- a pressure/sustained-extortion pattern rather than eight distinct intrusions. MedusaLocker claimed an attack on Mairie Thiverval-Grignon, extracting 162 email addresses from the municipal administration. LockBit maintains a recurring, cross-sector opportunistic presence in France. Per CISA/FBI/Treasury/FinCEN joint advisory AA22-181A, MedusaLocker actors gain initial access via vulnerable RDP configurations and phishing, use a batch file to trigger a malicious PowerShell script for network propagation, and inhibit recovery by deleting shadow copies and backups before encryption. Qilin's documented technique set (MITRE ATT&CK software S1242) spans phishing and public-facing application exploitation for initial access, LSASS credential dumping, PowerShell/Windows Command Shell execution, and double-extortion data encryption.

The hacktivist track is led by NoName057(16), a pro-Russian group assessed by CISA (advisory AA25-343A) to have originated as a covert project within the Kremlin-linked Centre for the Study and Network Monitoring of the Youth Environment (CISM). Running its #BrokenByte campaign explicitly tied to France's support for Ukraine, the group claimed DDoS attacks against French drone manufacturers Xsun France and iDrone, against the Ministries of Economy, Justice, Finance, and Interior plus the Civil Aviation Authority and National Reception Office, and claimed unauthorized CCTV/video-surveillance access at the Musee National de l'Automobile (Mulhouse) and a Renault/Dacia dealership (Groupe GGP, Orange), framing the latter as part of a "special military operation in cyberspace." NoName057(16) coordinates its crowdsourced, cryptocurrency-incentivized DDoS tool DDoSia via Telegram; CISA's advisory further documents the wider pro-Russia hacktivist ecosystem (CARR, Z-Pentest, Sector16) scanning for and brute-forcing internet-exposed VNC services (port 5900+) to access OT/HMI interfaces at critical-infrastructure operators.

Commodity infostealer-driven credential resale accounts for the bulk of the volume increase rather than targeted campaigns: dark web actors SKYNET (635 France-tagged postings) and WhiteMelly (614) lead bulk PII/credential sale and leak distribution; actor 587306 sold ~2 million records described as belonging to French women for $399 via Mega; actor Saturne disclosed an 11GB Classic-Days.fr database (plaintext passwords, source code) exposed through an unsecured Apache directory listing with SQL injection attempts dating to 2024; and actor HiddenHq claimed a 1 billion+ record, 2.3TB dataset allegedly sourced via a Salesforce-linked supply-chain breach affecting 36 companies. Separately, Cegedim Sante's MonLogicielMedical.com platform exposed administrative data on ~15 million French patients.

The surge coincides with escalating French regulatory enforcement: CNIL fined Free Mobile/Free a combined EUR 42 million in January 2026 over a 2024 breach exposing 24.6 million subscriber contracts, and fined France Travail EUR 5 million over a breach exposing up to 43 million job seekers -- the largest breach in French history by record count. Under GDPR Article 33, breaches must be reported to CNIL within 72 hours; 2024 alone saw over 5,600 breach notifications covering more than 145 million records of French residents.

MITRE ATT&CK techniques used in TL-2026-2564

Credential Access

T1003.001 LSASS Memory; T1110.003 Password Spraying; T1555 Credentials from Password Stores

Lateral Movement

T1021.005 VNC

Execution

T1059.001 PowerShell

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment

Impact

T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1498.001 Direct Network Flood; T1657 Financial Theft

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Resource Development

T1583.003 Virtual Private Server

Reconnaissance

T1591 Gather Victim Org Information; T1595.002 Vulnerability Scanning

defense-impairment

T1688 Safe Mode Boot

Affected products and versions in France Dark Web Threat Landscape

  • Commune d'Eyguieres — Municipal administrative network
    Vulnerable versions: Qilin ransomware target, 8 advisories 20-21 June 2026
  • Mairie Thiverval-Grignon — Municipal administrative network
    Vulnerable versions: MedusaLocker ransomware target, 162 emails extracted
  • Xsun France / iDrone — Corporate web infrastructure
    Vulnerable versions: NoName057(16) #BrokenByte DDoS target
  • Musee National de l'Automobile — CCTV / video surveillance system
    Vulnerable versions: Unauthorized access claimed by NoName057(16)
  • Groupe GGP (Renault/Dacia dealership, Orange) — Video surveillance and internal client-data systems
    Vulnerable versions: Unauthorized access claimed by NoName057(16)
  • French government ministries (Economy, Justice, Finance, Interior); Civil Aviation Authority; National Reception Office — Public-facing web infrastructure
    Vulnerable versions: DDoS target of NoName057(16) via DDoSia
  • Cegedim Sante — MonLogicielMedical.com medical practice software
    Vulnerable versions: ~15 million French patient administrative records exposed
  • Classic-Days.fr — E-commerce web application
    Vulnerable versions: Exposed Apache directory listing; SQL injection attempts since 2024; 11GB database breach June 2026

Remediation for France Dark Web Threat Landscape

Patches

  • No CVE or vendor patch applies to this multi-actor threat landscape report; mitigation is configuration- and process-based (RDP/VNC exposure reduction, credential hygiene, backup resilience, input validation against SQL injection)

Immediate actions

  • Disable or restrict internet-facing RDP and VNC services; where required, enforce MFA and source-IP allow-listing (per CISA AA22-181A and AA25-343A)
  • Rotate credentials and audit for default, weak, or reused passwords on any internet-accessible remote administration or OT/HMI interface
  • Remediate exposed directory listings and SQL injection vectors on public-facing web/e-commerce applications (per the Classic-Days.fr breach root cause)

Workarounds

  • Restrict RDP/VNC access to VPN-only connections with MFA enforced; disable direct internet exposure of HMI, CCTV, and other OT-adjacent interfaces per CISA AA25-343A guidance

Longer-term hardening

  • Maintain offline, immutable, and tested backups to blunt ransomware double-extortion leverage from Qilin and MedusaLocker
  • Deploy DDoS mitigation/scrubbing and CDN protection for public-facing government and critical-infrastructure sites against DDoSia-style volumetric floods (T1498.001)
  • Segment OT/ICS and physical-security (CCTV/video surveillance) networks from IT and the public internet; remove default credentials from HMI and camera systems

Weaknesses (CWE) in France Dark Web Threat Landscape

CWE-89

Timeline of France Dark Web Threat Landscape

  • CloudSEK's monitoring window begins with France-tagged dark web activity under 300 items/month (mid-2024 baseline).
  • CY2024 closes with over 5,600 breach notifications to CNIL, covering more than 145 million records belonging to French residents.
  • France-tagged dark web volume roughly doubles between June 2025 and December 2025 per CloudSEK's monthly trend data.
  • CNIL fines France Travail EUR 5 million over a breach exposing up to 43 million job seekers' data, the largest breach in French history by record count.
  • CNIL fines Free Mobile/Free a combined EUR 42 million for inadequate security measures contributing to a 2024 breach exposing 24.6 million subscriber contracts.
  • France-tagged dark web activity peaks above 1,400 items/month, the highest point in CloudSEK's 24-month dataset.
  • Volume plateaus above 1,000 items/month through spring 2026, holding well above the mid-2024 baseline.
  • Dark web actor Saturne discloses an 11GB Classic-Days.fr database breach (plaintext passwords, activation keys, internal source code) traced to an exposed Apache directory listing with SQL injection attempts dating back to 2024.
  • Qilin begins re-listing Commune d'Eyguieres across at least 8 separate ransomware leak-site advisory postings, continuing through 2026-06-21.
  • CloudSEK publishes the "France Cyber Threat Outlook: Dark Web, Ransomware & Hacktivism Report," documenting the full 24-month trend.

Sources cited for France Dark Web Threat Landscape

More in threat intel

Detection coverage for TL-2026-2564

As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2564 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats