Threat reportRansomwareTL-2026-3135

Q3 2026 Record Ransomware Surge: 2,627 Claimed Attacks, Qilin and The Gentlemen Lead, Clop Resurgence via PTC Windchill CVE-2026-12569

highACTIVE

Q3 2026 Record Ransomware Surge (TL-2026-3135), also tracked as Q3 2026 Ransomware Surge, is a high-severity ransomware operation, first published 2026-10-09. It is attributed to Qilin with medium confidence, affects PTC Windchill, references 5 CVEs (CVE-2026-12569, CVE-2025-3248, CVE-2021-29441), maps to 17 MITRE ATT&CK techniques (T1003, T1021.001, T1047), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
5Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
3Qilin
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-3135

Threat ID
TL-2026-3135
Also known as
Q3 2026 Ransomware Surge, Cl0p PTC Windchill data-theft campaign, JadePuffer agentic ransomware
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Qilin, The Gentlemen, Clop
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, technology, education, health, government administration, utilities, manufacturing, aerospace, automotive, retail
Target regions
North America, Europe, india, 005 - South America
Detection rules
9
Indicators of compromise
15

Malware and tooling in Q3 2026 Record Ransomware Surge

Malware and tooling: AgendaCrypt, AnyDesk, Clop, Cobalt Strike, ENCFORGE, Everest, G-BOT, MimiKatz, direwolf, rhysida, the gentlemen, AnyDesk

How Q3 2026 Record Ransomware Surge works

Comparitech data shows a record 2,627 claimed ransomware attacks in Q3 2026 (61% above Q3 2025), led by Qilin (357) and The Gentlemen (342), with Clop jumping from 1 claimed attack in Q2 to 48 after exploiting PTC Windchill/FlexPLM CVE-2026-12569. Finance, technology, education, healthcare, government and utilities all grew quarter over quarter.

Comparitech's Q3 2026 ransomware roundup (published 2026-10-07; reported by Infosecurity Magazine on 2026-10-09) logged 2,627 claimed ransomware attacks, nearly 29 per day, a record quarter. Only 247 were confirmed by victims; 2,380 remain unconfirmed claims. The quarter-over-quarter increase is reported as 27% by Infosecurity Magazine and 29% by Comparitech (Q2 2026: 2,030 attacks); year-over-year growth is 61% (Q3 2025: 1,636). Average ransom demand was $602,400 and median $150,000; more than 641 TB of data was reportedly stolen, and 1,611,971 records were compromised in confirmed attacks.

Qilin led with 357 claims (27 confirmed, +24% vs Q2) followed by The Gentlemen with 342 (26 confirmed, +29%). Clop rose from 1 claimed attack in Q2 to 48 in Q3, and Direwolf rose 1,450%. Sector growth versus Q2: finance +72%, technology +70%, education +50% (75 attacks), healthcare +39% (188), government +36% (124) and utilities +32%; businesses accounted for 2,234 attacks (+27%). The US had 1,066 attacks (41%, +34%), followed by Germany (121), Canada (103), Italy (86) and India (80, +116%); Argentina rose 150%. The largest reported demands were $12.3M against Stadler Rail by Everest (July 2026), $2.3M against the State of Berlin and $674,000 against Kreishandwerkerschaft Borken, both by Rhysida. Largest confirmed data breaches: Saber Healthcare Group (427,084 people), Austrian Chamber of Labour (270,000) and Greenberg Traurig LLP (150,000).

The Clop resurgence is tied to a data-theft extortion campaign against internet-exposed PTC Windchill and FlexPLM instances exploiting CVE-2026-12569 (CVSS 9.3, unauthenticated RCE via unsafe deserialization/improper input validation). PTC warned on 2026-06-17 and patched on 2026-06-18, CISA added the flaw to KEV on 2026-06-25, and JSP webshells (hex-named, under Windchill login paths) were used to enumerate filesystems and exfiltrate engineering data. Extortion emails were sent from previously compromised accounts to many employees of victim organizations, and GE and Philips confirmed they were investigating Clop claims. Targeted sectors include aerospace, defense, automotive, heavy machinery, retail/apparel and medtech.

Other actors and trends reported for the quarter: The Gentlemen (RaaS-style operation tracked by PRODAFT as led by LARVA-368; active since March 2025) uses Fortinet FortiGate exploitation (CVE-2024-55591), stolen VPN/OWA credentials, Mimikatz variants, a custom G-BOT C2 framework, a modified Velociraptor, Rclone, AnyDesk, PsExec/WMI/GPO lateral movement, and an XChaCha20/Curve25519 cross-platform locker (Windows, Linux, NAS, BSD, ESXi) dropping README-GENTLEMEN.txt. Qilin affiliates use ConnectWise ScreenConnect (CVE-2024-1708) and VPN appliance flaws, Cobalt Strike, RDP/PsExec/WMI, shadow copy removal, and a Rust encryptor. The JadePuffer campaign (Sysdig, July 2026) is the first documented ransomware operation driven end-to-end by an LLM agent: it exploited Langflow CVE-2025-3248, pivoted to Alibaba Nacos (CVE-2021-29441 auth bypass) and MySQL, encrypted 1,342 Nacos configuration items with AES_ENCRYPT(), installed a cron beacon, and later staged the Go-based ENCFORGE binary aimed at AI/ML artifacts. The Gentlemen also reportedly targeted clients of MIP Holdings (South Africa, breached June 2026) via triple extortion.

Caveat: the headline statistics come from leak-site claims, most of which are unconfirmed. Network IOCs (IPs, domains, hashes) are not published in the primary sources; IOCs below are family, tool, filename, path and behavioral indicators only.

MITRE ATT&CK techniques used in TL-2026-3135

Credential Access

T1003 OS Credential Dumping

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1569.002 Service Execution

Persistence

T1053.003 Scheduled Task/Job: Cron; T1505.003 Server Software Component: Web Shell

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Command and Control

T1219 Remote Access Tools

defense-impairment

T1484.001 Domain or Tenant Policy Modification: Group Policy Modification; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Q3 2026 Record Ransomware Surge

  • PTC — Windchill
    Vulnerable versions: Unpatched versions prior to the June 2026 PTC fix
    Fixed in: Per PTC advisory (patch released 2026-06-18)
  • PTC — FlexPLM
    Vulnerable versions: Unpatched versions prior to the June 2026 PTC fix
    Fixed in: Per PTC advisory (patch released 2026-06-18)
  • Fortinet — FortiGate (FortiOS)
    Vulnerable versions: Versions affected by CVE-2024-55591
    Fixed in: Per Fortinet advisory
  • ConnectWise — ScreenConnect
    Vulnerable versions: Versions affected by CVE-2024-1708
    Fixed in: Per ConnectWise advisory
  • Langflow — Langflow
    Vulnerable versions: Versions affected by CVE-2025-3248
    Fixed in: Fix released 2025-04-01
  • Alibaba — Nacos
    Vulnerable versions: Versions affected by CVE-2021-29441
    Fixed in: Per Nacos advisory

Remediation for Q3 2026 Record Ransomware Surge

Patches

  • PTC security advisory patches for CVE-2026-12569 (released 2026-06-18)
  • Fortinet fix for CVE-2024-55591
  • Langflow fix for CVE-2025-3248 (April 2025)
  • ConnectWise ScreenConnect fix for CVE-2024-1708

Immediate actions

  • Patch PTC Windchill/FlexPLM for CVE-2026-12569, restrict internet exposure, and hunt for hex-named JSP files under Windchill login paths and flst.txt artifacts
  • Patch or isolate Fortinet FortiGate (CVE-2024-55591), ConnectWise ScreenConnect (CVE-2024-1708) and Langflow (CVE-2025-3248) instances; rotate VPN/OWA credentials
  • Alert on Rclone, WinSCP, AnyDesk, PsExec and unexpected GPO changes on servers and domain controllers
  • Treat extortion emails from known partner or employee accounts as possible account compromise

Workarounds

  • Remove Windchill/FlexPLM from direct internet exposure pending patching
  • Block egress to file-sharing services for non-approved hosts to limit exfiltration

Longer-term hardening

  • Maintain offline, immutable backups including ESXi and NAS and test restores
  • Enforce MFA on VPN, OWA and remote-access tools and monitor for stolen-credential reuse
  • Deploy EDR with behavioral detection for shadow copy deletion, event log clearing and mass encryption
  • Segment engineering/PLM and AI/ML infrastructure from the general network and limit database root credential reuse

CVEs associated with Q3 2026 Record Ransomware Surge

CVE-2026-12569, CVE-2025-3248, CVE-2021-29441, CVE-2024-55591, CVE-2024-1708

Weaknesses (CWE) in Q3 2026 Record Ransomware Surge

CWE-502, CWE-20

Timeline of Q3 2026 Record Ransomware Surge

  • Langflow fixes CVE-2025-3248 (unauthenticated RCE); later exploited by the JadePuffer operation.
  • PTC first flags the Windchill/FlexPLM flaw CVE-2026-12569 and proposes remediation.
  • PTC releases a patch and confirms in-the-wild exploitation with JSP webshells.
  • CISA adds CVE-2026-12569 to the Known Exploited Vulnerabilities catalog.
  • Everest makes a $12.3M ransom demand against Stadler Rail in July 2026, the largest demand of the quarter (day not stated in sources; date set to month start).
  • Sysdig publishes the first findings on JadePuffer, an LLM-agent-driven ransomware operation using Langflow CVE-2025-3248.
  • Sysdig reports JadePuffer returned to the same Langflow instance with the ENCFORGE Go ransomware binary targeting AI/ML artifacts.
  • Public disclosure of the Clop data-theft extortion campaign against Windchill and FlexPLM; GE and Philips investigate claims.
  • Cl0p affiliation with the Windchill exploitation is confirmed per Help Net Security reporting.
  • Comparitech publishes its Q3 2026 roundup: 2,627 claimed attacks, a record quarter.
  • Infosecurity Magazine reports the record Q3 2026 ransomware figures.

Sources cited for Q3 2026 Record Ransomware Surge

Detection coverage for TL-2026-3135

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3135 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats