Threat reportRansomwareTL-2026-3135
Q3 2026 Record Ransomware Surge: 2,627 Claimed Attacks, Qilin and The Gentlemen Lead, Clop Resurgence via PTC Windchill CVE-2026-12569
Q3 2026 Record Ransomware Surge (TL-2026-3135), also tracked as Q3 2026 Ransomware Surge, is a high-severity ransomware operation, first published 2026-10-09. It is attributed to Qilin with medium confidence, affects PTC Windchill, references 5 CVEs (CVE-2026-12569, CVE-2025-3248, CVE-2021-29441), maps to 17 MITRE ATT&CK techniques (T1003, T1021.001, T1047), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 5Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 3Qilin
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-3135
- Threat ID
- TL-2026-3135
- Also known as
- Q3 2026 Ransomware Surge, Cl0p PTC Windchill data-theft campaign, JadePuffer agentic ransomware
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Qilin, The Gentlemen, Clop
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- finance, technology, education, health, government administration, utilities, manufacturing, aerospace, automotive, retail
- Target regions
- North America, Europe, india, 005 - South America
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Q3 2026 Record Ransomware Surge
Malware and tooling: AgendaCrypt, AnyDesk, Clop, Cobalt Strike, ENCFORGE, Everest, G-BOT, MimiKatz, direwolf, rhysida, the gentlemen, AnyDesk
How Q3 2026 Record Ransomware Surge works
Comparitech data shows a record 2,627 claimed ransomware attacks in Q3 2026 (61% above Q3 2025), led by Qilin (357) and The Gentlemen (342), with Clop jumping from 1 claimed attack in Q2 to 48 after exploiting PTC Windchill/FlexPLM CVE-2026-12569. Finance, technology, education, healthcare, government and utilities all grew quarter over quarter.
Comparitech's Q3 2026 ransomware roundup (published 2026-10-07; reported by Infosecurity Magazine on 2026-10-09) logged 2,627 claimed ransomware attacks, nearly 29 per day, a record quarter. Only 247 were confirmed by victims; 2,380 remain unconfirmed claims. The quarter-over-quarter increase is reported as 27% by Infosecurity Magazine and 29% by Comparitech (Q2 2026: 2,030 attacks); year-over-year growth is 61% (Q3 2025: 1,636). Average ransom demand was $602,400 and median $150,000; more than 641 TB of data was reportedly stolen, and 1,611,971 records were compromised in confirmed attacks.
Qilin led with 357 claims (27 confirmed, +24% vs Q2) followed by The Gentlemen with 342 (26 confirmed, +29%). Clop rose from 1 claimed attack in Q2 to 48 in Q3, and Direwolf rose 1,450%. Sector growth versus Q2: finance +72%, technology +70%, education +50% (75 attacks), healthcare +39% (188), government +36% (124) and utilities +32%; businesses accounted for 2,234 attacks (+27%). The US had 1,066 attacks (41%, +34%), followed by Germany (121), Canada (103), Italy (86) and India (80, +116%); Argentina rose 150%. The largest reported demands were $12.3M against Stadler Rail by Everest (July 2026), $2.3M against the State of Berlin and $674,000 against Kreishandwerkerschaft Borken, both by Rhysida. Largest confirmed data breaches: Saber Healthcare Group (427,084 people), Austrian Chamber of Labour (270,000) and Greenberg Traurig LLP (150,000).
The Clop resurgence is tied to a data-theft extortion campaign against internet-exposed PTC Windchill and FlexPLM instances exploiting CVE-2026-12569 (CVSS 9.3, unauthenticated RCE via unsafe deserialization/improper input validation). PTC warned on 2026-06-17 and patched on 2026-06-18, CISA added the flaw to KEV on 2026-06-25, and JSP webshells (hex-named, under Windchill login paths) were used to enumerate filesystems and exfiltrate engineering data. Extortion emails were sent from previously compromised accounts to many employees of victim organizations, and GE and Philips confirmed they were investigating Clop claims. Targeted sectors include aerospace, defense, automotive, heavy machinery, retail/apparel and medtech.
Other actors and trends reported for the quarter: The Gentlemen (RaaS-style operation tracked by PRODAFT as led by LARVA-368; active since March 2025) uses Fortinet FortiGate exploitation (CVE-2024-55591), stolen VPN/OWA credentials, Mimikatz variants, a custom G-BOT C2 framework, a modified Velociraptor, Rclone, AnyDesk, PsExec/WMI/GPO lateral movement, and an XChaCha20/Curve25519 cross-platform locker (Windows, Linux, NAS, BSD, ESXi) dropping README-GENTLEMEN.txt. Qilin affiliates use ConnectWise ScreenConnect (CVE-2024-1708) and VPN appliance flaws, Cobalt Strike, RDP/PsExec/WMI, shadow copy removal, and a Rust encryptor. The JadePuffer campaign (Sysdig, July 2026) is the first documented ransomware operation driven end-to-end by an LLM agent: it exploited Langflow CVE-2025-3248, pivoted to Alibaba Nacos (CVE-2021-29441 auth bypass) and MySQL, encrypted 1,342 Nacos configuration items with AES_ENCRYPT(), installed a cron beacon, and later staged the Go-based ENCFORGE binary aimed at AI/ML artifacts. The Gentlemen also reportedly targeted clients of MIP Holdings (South Africa, breached June 2026) via triple extortion.
Caveat: the headline statistics come from leak-site claims, most of which are unconfirmed. Network IOCs (IPs, domains, hashes) are not published in the primary sources; IOCs below are family, tool, filename, path and behavioral indicators only.
MITRE ATT&CK techniques used in TL-2026-3135
Credential Access
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1569.002 Service Execution
Persistence
T1053.003 Scheduled Task/Job: Cron; T1505.003 Server Software Component: Web Shell
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Command and Control
defense-impairment
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery
Exfiltration
Affected products and versions in Q3 2026 Record Ransomware Surge
- PTC — Windchill
Vulnerable versions: Unpatched versions prior to the June 2026 PTC fix
Fixed in: Per PTC advisory (patch released 2026-06-18) - PTC — FlexPLM
Vulnerable versions: Unpatched versions prior to the June 2026 PTC fix
Fixed in: Per PTC advisory (patch released 2026-06-18) - Fortinet — FortiGate (FortiOS)
Vulnerable versions: Versions affected by CVE-2024-55591
Fixed in: Per Fortinet advisory - ConnectWise — ScreenConnect
Vulnerable versions: Versions affected by CVE-2024-1708
Fixed in: Per ConnectWise advisory - Langflow — Langflow
Vulnerable versions: Versions affected by CVE-2025-3248
Fixed in: Fix released 2025-04-01 - Alibaba — Nacos
Vulnerable versions: Versions affected by CVE-2021-29441
Fixed in: Per Nacos advisory
Remediation for Q3 2026 Record Ransomware Surge
Patches
- PTC security advisory patches for CVE-2026-12569 (released 2026-06-18)
- Fortinet fix for CVE-2024-55591
- Langflow fix for CVE-2025-3248 (April 2025)
- ConnectWise ScreenConnect fix for CVE-2024-1708
Immediate actions
- Patch PTC Windchill/FlexPLM for CVE-2026-12569, restrict internet exposure, and hunt for hex-named JSP files under Windchill login paths and flst.txt artifacts
- Patch or isolate Fortinet FortiGate (CVE-2024-55591), ConnectWise ScreenConnect (CVE-2024-1708) and Langflow (CVE-2025-3248) instances; rotate VPN/OWA credentials
- Alert on Rclone, WinSCP, AnyDesk, PsExec and unexpected GPO changes on servers and domain controllers
- Treat extortion emails from known partner or employee accounts as possible account compromise
Workarounds
- Remove Windchill/FlexPLM from direct internet exposure pending patching
- Block egress to file-sharing services for non-approved hosts to limit exfiltration
Longer-term hardening
- Maintain offline, immutable backups including ESXi and NAS and test restores
- Enforce MFA on VPN, OWA and remote-access tools and monitor for stolen-credential reuse
- Deploy EDR with behavioral detection for shadow copy deletion, event log clearing and mass encryption
- Segment engineering/PLM and AI/ML infrastructure from the general network and limit database root credential reuse
CVEs associated with Q3 2026 Record Ransomware Surge
CVE-2026-12569, CVE-2025-3248, CVE-2021-29441, CVE-2024-55591, CVE-2024-1708
Weaknesses (CWE) in Q3 2026 Record Ransomware Surge
Timeline of Q3 2026 Record Ransomware Surge
- Langflow fixes CVE-2025-3248 (unauthenticated RCE); later exploited by the JadePuffer operation.
- PTC first flags the Windchill/FlexPLM flaw CVE-2026-12569 and proposes remediation.
- PTC releases a patch and confirms in-the-wild exploitation with JSP webshells.
- CISA adds CVE-2026-12569 to the Known Exploited Vulnerabilities catalog.
- Everest makes a $12.3M ransom demand against Stadler Rail in July 2026, the largest demand of the quarter (day not stated in sources; date set to month start).
- Sysdig publishes the first findings on JadePuffer, an LLM-agent-driven ransomware operation using Langflow CVE-2025-3248.
- Sysdig reports JadePuffer returned to the same Langflow instance with the ENCFORGE Go ransomware binary targeting AI/ML artifacts.
- Public disclosure of the Clop data-theft extortion campaign against Windchill and FlexPLM; GE and Philips investigate claims.
- Cl0p affiliation with the Windchill exploitation is confirmed per Help Net Security reporting.
- Comparitech publishes its Q3 2026 roundup: 2,627 claimed attacks, a record quarter.
- Infosecurity Magazine reports the record Q3 2026 ransomware figures.
Sources cited for Q3 2026 Record Ransomware Surge
- Q3 2026 Sets New Record for Ransomware Attacks (Infosecurity Magazine)
- Ransomware roundup Q3 2026: stats on attacks, ransoms and active gangs (Comparitech)
- Clop ransomware targets Windchill, FlexPLM in data theft attacks (BleepingComputer)
- JSP webshells being dropped on unpatched PTC Windchill instances (Help Net Security)
- The Gentlemen ransomware: Inside one of the fastest-growing extortion operations (Barracuda)
- The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm (The Hacker News)
- JadePuffer ransomware used AI agent to automate entire attack (BleepingComputer)
- JadePuffer Ransomware - First Reported Use of Agentic Ransomware (WaterISAC, TLP:CLEAR)
- Watch Guard! Qilin affiliate exploits network appliances for initial access (CtrlAltIntel)
- Qilin ransomware: Attack Chain, MITRE ATT&CK TTPs, and Incident Response Guide (Proven Data)
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-3135
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3135 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.