Confidence labels are applied throughout: CONFIRMED, CREDIBLE REPORTING, and ANALYST INFERENCE. Figures carried forward from earlier periods are dated explicitly where month-specific data was unavailable. To see which ecosystem nodes moved during this reporting period, open the map's delta view for March 2026.
SECTION 1 - EXECUTIVE SUMMARY
The following strategic findings represent the highest-signal developments in the cybercrime ecosystem for March 2026. Coverage period is 1-30 March 2026 with contextual reference to late-February and January 2026 events where operationally relevant.
- Q1 2026 ransomware activity maintained elevated operational tempo, with approximately 2,505 victims disclosed on dark web leak sites through the first quarter, led by Qilin, Akira, and DragonForce. The United States accounted for 50.8% of global victims. [CONFIRMED]
- The January 28, 2026 FBI seizure of the RAMP forum - the primary dark web venue for RaaS affiliate recruitment - continues to fracture centralized coordination. Post-seizure, the ecosystem is migrating toward closed, referral-gated forums including T1erOne and Rehub, reducing defender visibility. [CONFIRMED]
- Operation Leak (March 3-4, 2026): The FBI and Europol dismantled LeakBase, one of the world's largest credential trading forums, with 142,000 members and 215,000 messages. Thirteen arrests, 32 searches, and seizure of the full user database represent a significant operational disruption to credential supply chains. [CONFIRMED]
- Interlock ransomware exploited Cisco FMC CVE-2026-20131 (CVSS 10.0) as a zero-day for 36 days prior to disclosure, beginning January 26, 2026. The vulnerability enables unauthenticated root RCE. CISA added to KEV on March 19. Known victims include DaVita, Kettering Health, and the Texas Tech University System. [CONFIRMED]
- A coordinated March 2026 supply chain campaign attributed to TeamPCP compromised five developer ecosystems simultaneously (GitHub Actions, Docker Hub, PyPI, NPM, OpenVSX), including Aqua Security's Trivy scanner and the LiteLLM AI proxy. Over 1,000 downstream enterprise environments estimated affected. [CREDIBLE REPORTING]
- Data extortion without encryption grew from 2% of IR cases in November 2024 to 22% in November 2025, representing an elevenfold increase. The trend continues into Q1 2026, driven by groups including PEAR and Silent Ransom that have adopted encryption-free operating models. [CONFIRMED]
- UK government sanctioned Xinbi, a Chinese-language cryptocurrency marketplace processing $19.9 billion in transactions (2021-2025), on March 26, 2026 - the first country to take such action against the platform. The FBI and Thai police froze $580 million in crypto linked to Southeast Asian scam networks in the same period. [CONFIRMED]
- Lumma infostealer, disrupted by Microsoft-led action in May 2025 (2,300 domains seized), has fully reconstituted by March 2026. As of February-March 2026, Lumma is operating at scale via ClickFix and CastleLoader delivery chains, with C2 infrastructure leveraging Russian cloud providers. [CONFIRMED]
SECTION 2 - RANSOMWARE ECOSYSTEM - MONTHLY STATISTICS
The ransomware ecosystem remains at historically elevated activity levels through Q1 2026. Victim counts are sourced primarily from dark web leak site monitoring (ransomware.live, ransom-db.com, Purple Ops daily reporting) and represent disclosed extortion events, not total incident volume. Actual incident counts are assessed to be significantly higher than disclosed figures.
2.1 Aggregate Statistics - Q1 2026 / March 2026
Total Q1 2026 victims (disclosed): ~2,505
Active ransomware groups (Q1 2026): 30+
New groups identified (2025 full year): 57 ransomware + 27 extortion
Week of March 10-17, 2026 - total victims: 177
Most active group (week of March 10-17): Qilin (30 victims)
Second most active (same period): Akira (18 victims)
Single-day disclosure peak (recent): 29 new victims
US share of global victims: 50.8%
North America share: 81%
Average ransom payment (2025): $1 million (50% decrease from $2M in 2024)
2.2 Sector Targeting Trend Table
The following table reflects sector-level targeting trends based on Q1 2026 victim disclosures compared to Q4 2025 baseline data. Prior month figures represent the February 2026 / Q4 2025 aggregate where February-specific data was not available.
| Sector | This Month (Mar 2026) | Prior Period (Q4 2025) | % Change | Trend |
|---|---|---|---|---|
| Manufacturing | High (29% of Q1 attacks) | High (led 2025 with 1,653) | Stable | Sustained |
| Professional Services | High (top-3 in March) | High (11% of IAB listings) | +5% est. | Increasing |
| Healthcare | High (27 incidents, early Q1) | Moderate-High | +15% est. | Increasing |
| Construction & Engineering | Significant | Significant (6.64% IAB) | Stable | Stable |
| Financial Services | Significant | Moderate-High | Stable | Stable |
| Technology / IT | Moderate | Moderate (6.42% IAB) | Stable | Stable |
| Education | Moderate | Moderate | Stable | Stable |
| Government / Public Sector | Moderate (11 incidents early Q1) | Moderate | +8% est. | Slight increase |
| Energy / OT / ICS | Low-Moderate | Low-Moderate (50% of 2025 attacks on critical infra) | Stable | Watch |
| Retail / Consumer | Moderate | Moderate (DragonForce targeting) | Stable | Stable |
2.3 Geographic Targeting Analysis
United States targeting remains dominant at 50.8% of global disclosed victims, consistent with the prior quarter. North America as a whole accounts for 81% of attacks per Bitsight CTI Q1 2026 tracking. CIS-exclusion patterns continue to hold for major RaaS platforms including Qilin, Akira, LockBit5, and DragonForce, which maintain logic to terminate operations on systems using Russian, Ukrainian, or select Central Asian locale settings. This restraint is assessed as operationally motivated to avoid domestic law enforcement friction rather than ideological. No observed targeting of Russian critical infrastructure by major Western-facing RaaS groups, with the exception of the Ukrainian-linked Bearlyfy/Labubi operation deploying GenieLocker against Russian firms (70+ Russian entities targeted since January 2025). The United Kingdom, Canada, Germany, France, and Australia follow the US in relative targeting frequency, consistent with prior reporting.
SECTION 3 - THREAT ACTOR LANDSCAPE
The ransomware threat actor landscape in March 2026 is characterized by continued fragmentation following the January 2026 RAMP forum seizure, emergence of selective new RaaS entrants, and an acceleration of the data extortion-only operating model. Russia/CIS-linked groups continue to dominate by victim volume and financial impact.
3.1 Key Group Assessments
Qilin: Leading threat actor for the period. Surged to top position in Q3 2025 via aggressive affiliate recruiting including banner advertising on dark web forums. Rust-based encryption with sophisticated double-extortion. Maintained 30 victims in the week of March 10-17, 2026 alone. Expanding reach into US market, with recent victims in professional services, architecture, and financial consulting. CIS-exclusion pattern assessed as present. [CONFIRMED]
Akira: Maintained strong second-position with 18 victims in the week of March 10-17. Cumulative proceeds estimated at $244 million as of late 2025. High-confidence links to former Conti members. Among the FBI's top five investigated ransomware variants. Recent March 2026 victims include BHS Bau (construction), Frontier Technologies, Sheladia Associates, and Quality Carton and Converting. CIS-exclusion logic assessed as present. [CONFIRMED]
LockBit5: Rebrand announced September 2025, introducing a cross-platform variant targeting Windows, Linux, and VMware ESXi simultaneously. Despite cumulative law enforcement pressure including the February 2024 Operation Cronos infrastructure seizure and public identification of alleged leader Dmitry Khoroshev, the group continues to operate with 11 victims reported in the week of March 13, 2026. Assessed as Russia/CIS-based with broad affiliate network. [CONFIRMED]
Interlock: Emerged September 2024. Demonstrated advanced zero-day exploitation capability by targeting Cisco FMC CVE-2026-20131 for 36 days before public disclosure. Identified victims include DaVita (dialysis provider), Kettering Health, Texas Tech University System, and the city of Saint Paul, Minnesota. Associated with ClickFix social engineering and NodeSnake RAT deployment. Exploitation chain provides unauthenticated root access to enterprise firewall infrastructure - high-value initial access for subsequent lateral movement. [CONFIRMED]
DragonForce: Listed 363 victims by January 2026, with activity peaking at 35 victims in December 2025. Operates as a cartel-style platform offering affiliates 80% of ransom proceeds plus attack automation tools. Variants are based on LockBit3.0 and ContiV3 codebases. DragonForce's cartel model is assessed as a key structural development - it absorbs smaller operators who lack development capacity while expanding total attack volume. [CONFIRMED]
BravoX: New entry, first observed January 2026. Operates at low current volume but employs selective affiliate screening: applicants must demonstrate access to unpublished data from targets with over $5 million in revenue, provide a financial deposit, or pass trusted-referral verification. This vetting model is consistent with a quality-over-quantity affiliate strategy designed to avoid low-skill operators who generate law enforcement attention. [CREDIBLE REPORTING]
AtomSilo: Dormant since 2021, reappeared February 2026. Motivations and re-launch context not yet established. Threat level currently assessed as low-moderate; monitor for victim disclosures and affiliate recruitment signals. [CREDIBLE REPORTING]
Bearlyfy / Labubi: Pro-Ukrainian operator. Has targeted over 70 Russian firms since January 2025. Deployed custom Windows ransomware named GenieLocker since March 2026. Assessed as a hybrid hacktivist-cybercriminal actor with potential state-adjacent motivations. Not a RaaS operator; direct attribution as Ukrainian-linked remains credible but unconfirmed by authoritative source. [CREDIBLE REPORTING]
PEAR (Pure Extortion and Ransom): Encryption-free operator. Emerged 2025 and exclusively conducts data-theft extortion with no encryption component. Represents a leading example of the structural shift away from ransomware-as-disruption toward ransomware-as-leverage. Silent Ransom group has also adopted this model. [CONFIRMED]
Clop: Russia/CIS-linked. Increasingly operating extortion-only via mass exploitation of file transfer vulnerabilities. Industry estimates place cumulative proceeds in the hundreds of millions since 2019. Maintains strategic value as a model for non-encryption extortion at enterprise scale. [CONFIRMED]
3.2 Data Extortion Trend - Encryption-Free Operations
The structural shift toward encryption-free data extortion represents the most significant tactical evolution in the ransomware ecosystem for the reporting period. Key indicators:
- Elevenfold increase in data-only extortion attacks from November 2024 to November 2025 (2% to 22% of IR cases). Trend assessed as continuing into Q1 2026.
- Nearly 1,500 incidents relied on data theft alone for extortion in 2025, compared to only 28 in 2024 - a 53x increase.
- Operating rationale: no encryption means no immediate operational disruption, enabling stealthy multi-week exfiltration. Detection rates are lower as defenders optimized for encryption triggers miss theft-only intrusions.
- PEAR and Silent Ransom have adopted encryption-free models exclusively. Clop continues its long-running encryption-optional approach via mass file-transfer exploitation.
- Victim leverage: stolen intellectual property, source code, and internal documentation used as extortion levers. The Nike breach in early 2026 exemplified this model.
- Counter-pressure: ransomware groups may pivot back to encryption if pure extortion payment rates decline (SecurityWeek reporting notes this risk for groups that cannot sustain victim pressure without disruption).
- Insurance implication: encryption-free attacks complicate cyber insurance claims processes, which have historically been triggered by operational disruption metrics.
SECTION 4 - INITIAL ACCESS AND TTP EVOLUTION
Initial access vectors in March 2026 reflect a continued convergence of vulnerability exploitation, credential markets, and social engineering. The Interlock/Cisco FMC zero-day campaign demonstrates that leading RaaS operators are investing in zero-day capability - previously a nation-state TTR. Key TTP shifts for the month:
- Zero-day exploitation by ransomware actors: Interlock's 36-day exploitation of CVE-2026-20131 prior to disclosure represents a maturation of ransomware operator investment in pre-patch vulnerability research. BeyondTrust CVE-2026-1731 (auth bypass/RCE) also being leveraged by ransomware groups in the period.
- ClickFix social engineering chains: ClickFix lure pages continue as a primary Lumma and Interlock delivery mechanism. Victims are directed to execute malicious PowerShell commands under the guise of browser or application repair prompts. Distribution via malicious advertising, compromised websites, and phishing.
- CastleLoader distribution: CastleLoader observed as a delivery vehicle for Lumma stealer in late 2025 and early 2026 campaigns, particularly in Eastern European and global distribution chains.
- VPN and edge device exploitation: VPN vulnerabilities remain primary IAB supply channels. Ivanti EPM CVE-2026-1603 (auth bypass) added to CISA KEV March 9. F5 BIG-IP APM CVE-2025-53521 (CVSS 9.3, RCE) added to CISA KEV in the period.
- Credential-based intrusion: IAB market continues to supply ransomware affiliates with pre-validated corporate access. Infostealer-sourced credentials represent a growing share of IAB listings as Lumma, ACRStealer, and StealC maintain high infection volumes.
- Supply chain as access vector: TeamPCP's March 2026 campaign demonstrates that developer toolchain compromise provides a scalable method to achieve code execution in enterprise CI/CD environments - bypassing perimeter defenses entirely.
4.1 Initial Access Broker (IAB) Market Indicators
| Indicator | This Period (Mar 2026) | Trend vs. Prior Period |
|---|---|---|
| Volume of corporate access listings | Elevated; infostealer-sourced credentials expanding supply. IAB market minimum value estimated $6.3M in 2024 based on advertised prices. | Increasing |
| Median access pricing | $1,295 (2024 average; down ~60% from 2023). 58% of listings now under $1,000. Premium listings up to $120,000+ for high-value unique access. | Decreasing (price compression, volume increase) |
| Most-targeted sectors | Professional Services (11%), Manufacturing (8.22%), Construction (6.64%), IT (6.42%), Education (5.33%), Financial (5.22%) | Stable distribution; Professional Services increasing |
| Preferred access types | VPN (primary), RDP, Citrix, OWA/Exchange. Infostealer-sourced credentials increasingly feeding VPN access listings. | VPN dominant; infostealer feed increasing |
| Geographic concentration | US accounts for 34.12% of all listings. Brazil 4.65%, UK 4.13%, Canada 3.38%, France 3.34%. | US dominance stable |
| Notable marketplace activity | RAMP forum (primary RaaS venue) seized January 28, 2026. Migration to T1erOne (closed, $450 entry or verified referral) and Rehub. Reduced open advertising of RaaS affiliate programs. | Disrupted; fragmentation ongoing |
| IAB-to-affiliate pipeline | BravoX requires proof of access to targets with >$5M revenue or financial deposit for affiliate entry. Represents selective screening trend. | Selective quality gating emerging |
SECTION 5 - MALWARE AND STEALER ECOSYSTEM - MONTHLY ANALYSIS
5.1 Market State and Dominant Families
As of February-March 2026, the infostealer ecosystem is dominated by four actively distributed families: LummaC2, ACRStealer, StealC, and Vidar. The top three families - Lumma, StealC, and RedLine - collectively accounted for over 75% of infections in the preceding period, all operating as Malware-as-a-Service (MaaS) with subscriptions starting at $250/month. Operational and forensic data indicates that stealers are increasingly functioning as an upstream supply chain for both IAB listings and ransomware intrusions.
- LummaC2 (Lumma Stealer): Dominant family. Disrupted by Microsoft-led global operation in May 2025 (2,300 domains seized, including 2 key administration domains and 1,300 redirected to sinkholes). Recovery was rapid: C2 URLs increased from 1 in late May 2025 to 450+ by mid-June 2025. By February-March 2026, Lumma is assessed as fully reconstituted and operating at scale. Post-disruption infrastructure leverages Russian cloud providers (Selectel) and legitimate cloud services to evade detection. New capabilities include expanded MFA bypass functionality. Distribution via ClickFix social engineering chains and CastleLoader. Subscription model starts at $250/month. [CONFIRMED]
- ACRStealer: Actively distributed as of Q1 2026. Malware-as-a-Service. Favored for credential exfiltration from browsers, cryptocurrency wallets, and FTP/SSH clients. No major disruption action in the reporting period. [CONFIRMED]
- StealC: Remained in top-3 by infection volume. Distribution overlaps with Lumma in some campaigns. Targets browser credentials, cryptocurrency wallets, and application-stored secrets. [CONFIRMED]
- Vidar: Remained in top-4 active distributions. Long-standing MaaS family with established underground distribution infrastructure. [CONFIRMED]
- RedLine: Significant decline following Operation Magnus in October 2024. RedLine's infrastructure was dismantled in a Dutch-led international operation. However, pre-operation log archives continue to circulate in underground markets, representing a persistent but diminishing credential threat. RedLine logs from 2023-2024 remain active in dark web sales. [CONFIRMED]
- Raccoon: Substantially disrupted. Operator arrested in 2022; v2 operations degraded. Minimal new infection volume but legacy log data persists. [CONFIRMED - reduced threat]
5.2 Volume Trends and Supply Chain Implications
- 1.8 billion credentials stolen by infostealers in H1 2025 alone, from 5.8 million infected devices - representing an 800% increase over the previous six months (IBM X-Force/Huntress reporting).
- One in four cyberattacks in 2024 was traced to an infostealer precursor (Huntress). This ratio is assessed as holding or increasing into 2026.
- New research (cybersecuritynews.com, March 2026) demonstrates that infostealer infections convert to dark web credential listings within 48 hours on average - significantly shortening the attacker exploitation window.
- The infostealer-to-IAB pipeline: stolen credentials are sold to initial access brokers who validate and resell corporate VPN/RDP access to ransomware affiliates. This multi-step supply chain creates structural dependency between stealer operators and RaaS ecosystems.
- MFA bypass expansion in Lumma (March 2026 reporting): new versions include enhanced capability to steal session cookies and bypass time-based OTP mechanisms, reducing the defensive value of legacy MFA deployments.
- GlassWorm supply chain campaign (March 2026): developer-targeting malware using invisible Unicode encoding to conceal payloads across 433 compromised packages. Targets SSH keys, cryptocurrency wallet data, access tokens, and developer environment secrets. C2 infrastructure uses Solana blockchain transaction memos for resilience.
SECTION 6 - FINANCIAL AND INFRASTRUCTURE SIGNALS
6.1 Cryptocurrency Ecosystem Assessment
The illicit cryptocurrency ecosystem reached a new scale marker in 2025. Chainalysis 2026 Crypto Crime Report documents illicit addresses received at least $154 billion in 2025 - an increase that is attributable in part to nation-state actors (primarily DPRK) integrating with previously cybercriminal-only infrastructure. The convergence of state and criminal financial flows creates compounded enforcement complexity.
- Illicit crypto volume (2025): $154 billion (Chainalysis). Nation-state actors are described as 'tapping into professionalized service providers and standing up their own bespoke infrastructure' at scale.
- Average ransom payment (2025): $1 million - a 50% decrease from the $2 million average in 2024. Assessed as a response to improved organizational defenses, backup resilience, and non-payment guidance from governments rather than reduced actor activity.
- Ransomware remains the dominant cryptocurrency crime category by operational impact despite declining average payments, with overall ecosystem revenue sustained by volume increase.
- Session cookie theft and chain-hopping (converting crypto through multiple chains to obscure origin) remain primary obfuscation methods for ransomware proceeds.
- Tornado Cash successor infrastructure remains active. The May 2024 conviction of Tornado Cash co-founder Roman Storm has not eliminated mixer/tumbler availability; decentralized alternatives and private chain bridges continue operating.
6.2 Sanctions and Enforcement Actions - Infrastructure Focus
Xinbi Cryptocurrency Marketplace - UK Sanction (March 26, 2026): The UK sanctioned Xinbi, a Chinese-language cryptocurrency marketplace, making it the first country globally to take such action. Xinbi processed more than $19.9 billion in transactions between 2021 and 2025. The platform served as a financial pillar for Southeast Asian scam center operations and human trafficking-linked fraud networks. FBI and Thai police simultaneously froze $580 million in crypto linked to organized scam gangs targeting US nationals. Cumulative impact: significant disruption to the financial infrastructure underpinning Southeast Asian pig butchering and human trafficking operations. [CONFIRMED]
Media Land LLC - Bulletproof Hosting - US/UK/Australia Joint Sanction (November 2025, context): OFAC, Australia DFAT, and UK FCDO jointly sanctioned Media Land LLC (St. Petersburg, Russia) - the largest coordinated BPH infrastructure sanction in the period. Media Land provided services to LockBit, BlackSuit, and Play ransomware operations. Three leadership members and three sister companies designated. Aeza Group (previously sanctioned July 2025) was also re-sanctioned for sanctions evasion through rebranding as Hypercore (UK-based front). Cumulative impact: Media Land's infrastructure was used by multiple active RaaS groups; sanction blocks US person dealings and requires reporting of blocked property. [CONFIRMED]
DPRK IT Worker Networks - OFAC Sanction (March 12, 2026): OFAC sanctioned six individuals and two entities facilitating North Korean government IT worker fraud schemes. The designated networks generated nearly $800 million in 2024 alone to fund DPRK weapons programs. Operations spanned Vietnam, Laos, and Spain. Key designee Nguyen Quang Viet (CEO, Vietnam-based company) converted approximately $2.5 million into cryptocurrency for the regime (mid-2023 to mid-2025). DPRK operatives have evolved from job application infiltration to operating elaborate fake hiring processes targeting Web3 and AI companies for credential and source code harvesting. [CONFIRMED]
OFAC - Additional Crypto Exchange Targeting (context, SB0225): Treasury designated a cryptocurrency exchange and associated network for enabling sanctions evasion and facilitating cybercriminals. Full details of SB0225 not available due to collection access restriction; see source reference for complete designation list. [CONFIRMED - partial detail]
6.3 Infrastructure Hosting Patterns
The Media Land/Aeza/Hypercore sanction chain illustrates a core infrastructure evasion tactic: BPH operators responding to sanctions by establishing rebranded UK or Western-registered front companies to continue operations. This pattern degrades the deterrent value of individual designations without complementary network disruption. Russian BPH operators continue to provide resilient hosting for LockBit5, Play, BlackSuit, and associated leak sites, leveraging hosting in jurisdictions with limited cooperation with Western law enforcement. Post-RAMP seizure, RaaS recruitment and communication is assessed as migrating toward Jabber/XMPP, Tox, and invitation-only Telegram channels, reducing visibility for human intelligence and open-source collection.
SECTION 7 - LAW ENFORCEMENT AND REGULATORY ACTIONS
7.1 Significant Actions - Reporting Period
Operation Leak - LeakBase Forum Takedown (March 3-4, 2026): FBI and Europol dismantled LeakBase, one of the world's largest open-web credential trading forums, in a 14-country coordinated operation hosted by Europol in The Hague. LeakBase had 142,000 members and 215,000+ messages containing continuously updated hacked database archives including hundreds of millions of account credentials. 100 law enforcement actions against 45 targets; 13 arrests; 32 searches; 33 suspect interviews. Infrastructure seized from Netherlands to Malaysia. Entire forum database captured for evidentiary purposes including user accounts, posts, credit details, private messages, and IP logs. Assessed impact: significant disruption to credential trading supply chain; however, alternative platforms (XSS, Exploit, Genesis successor markets) are expected to absorb displaced user base within 30-90 days. [CONFIRMED]
RAMP Forum Seizure (January 28, 2026 - ongoing operational context): FBI seized RAMP in a coordinated action with the US Attorney's Office (Southern District of Florida) and DOJ CCIPS. RAMP was the only known dark web forum where RaaS affiliate recruitment was explicitly permitted; hosted LockBit, ALPHV/BlackCat, Conti, DragonForce, Qilin, Nova, Radiant, and RansomHub operations at various points. Alleged admin 'Stallman' confirmed the seizure via XSS forum posts, describing the takedown as destroying 'years of work.' Post-seizure ecosystem impact: T1erOne (closed forum, $450 entry fee or verified referral) and Rehub emerging as migration points. Critically reduces open-market affiliate recruitment visibility. [CONFIRMED]
Operation Synergia III (ran July 18, 2025 to January 31, 2026 - results published March 2026): INTERPOL-coordinated operation across 72 countries targeting phishing, romance scams, and credit card fraud infrastructure. Results: 94 people arrested, 110 under investigation, 212 devices seized, 45,000+ malicious IP addresses sinkholed. Supported by private sector partners including Group-IB, Trend Micro, and S2W. Third iteration of the Synergia initiative launched in 2023. [CONFIRMED]
Aleksei Volkov Sentencing - Russian IAB (sentenced March 24, 2026): Russian citizen Aleksei Volkov, 26, sentenced to 81 months (6.75 years) in federal prison by the Southern District of Indiana. Volkov served as an IAB providing access to US corporate networks and sold that access to cybercrime groups including the Yanluowang ransomware operation. Caused over $9 million in actual losses and $24 million in intended losses. Facilitated dozens of ransomware attacks against US organizations. [CONFIRMED]
Ilya Angelov Sentencing - Russian Botnet Operator (sentenced March 2026): Russian national Ilya Angelov, 40, of Tolyatti, Russia, sentenced to 24 months in US federal prison for operating a TA551-linked botnet used by ransomware gangs to break into corporate networks. FBI identified over 70 US corporations infected with ransomware via Angelov's botnet, resulting in over $14 million in extortion payments. [CONFIRMED]
ALPHV/BlackCat Sentencings (March 12, 2026): Two American defendants sentenced following guilty pleas to conspiracy charges for conducting attacks using ALPHV/BlackCat ransomware. Both face maximum of 20 years imprisonment. [CONFIRMED]
White House Executive Action on Cybercrime (signed March 2026): The United States government signed an executive action directing law enforcement, diplomatic, and potential offensive responses to cybercrime attacks against Americans. Directs support for victims and prioritizes protection for high-risk populations. Signals continued executive-level prioritization of cybercrime disruption. [CONFIRMED]
UK Xinbi Sanctions (March 26, 2026): UK became first country globally to sanction the Xinbi cryptocurrency marketplace, processing $19.9 billion linked to Southeast Asian scam operations. Part of a broader UK action targeting 'scam centers' in Cambodia and Southeast Asia, including sanctions on operators of the '#8 Park' compound (Cambodia's largest scam compound, 20,000 worker capacity). [CONFIRMED]
7.2 Cumulative Impact Assessment
The March 2026 reporting period represents one of the highest-density LE action months in recent history, with major forum takedowns (RAMP, LeakBase), multiple significant sentencings, and a multi-country infrastructure sanction regime. Assessment of cumulative ecosystem impact:
- RAMP Seizure: High ecosystem disruption, sustained. The loss of the primary RaaS recruitment forum is structurally significant. The shift to closed, referral-only successor forums reduces open advertising but does not stop recruitment - it makes it less observable and potentially more selective.
- LeakBase Seizure: Moderate disruption to credential trade, expected to recover within 60-90 days. Credential trading markets are highly resilient; XSS, Exploit.in, and specialized Telegram channels will absorb demand. However, 142,000 user records now in FBI possession represent a significant HUMINT windfall for attribution.
- Sentencings (Volkov, Angelov, BlackCat defendants): Moderate deterrence value, concentrated in US-extraditable individuals. Actors protected by Russian jurisdiction are minimally deterred. Sentencings are most effective as signals to Western-based enablers and affiliate participants.
- BPH Sanctions (Media Land/Aeza/Hypercore): Moderate-low infrastructure impact, high symbolic value. BPH operators can rebrand and reconstitute within weeks. The Aeza/Hypercore pattern shows active sanctions evasion already underway. Impact is primarily felt in financial access and banking relationships.
- OFAC DPRK designations: Targeted, moderate financial disruption. Represents escalation of US pressure on state-sponsored crypto revenue streams feeding weapons programs.
- Most active LE jurisdictions: United States (FBI/DOJ), European Union (Europol/NCA/national agencies), United Kingdom. Least cooperative: Russia (assessed as providing continued state-adjacent protection to major ransomware operators).
SECTION 8 - VULNERABILITY EXPLOITATION - MONTHLY MATRIX
The following matrix covers CVEs with confirmed or credible ransomware/malware campaign exploitation during the reporting period. Focused on vulnerabilities driving enterprise-scale intrusions. Cross-referenced against CISA Known Exploited Vulnerabilities (KEV) catalog.
| CVE | Product | CVSS | Exploitation Method | Threat Actor | Scale | CISA KEV |
|---|---|---|---|---|---|---|
| CVE-2026-20131 | Cisco FMC (Firepower Mgmt Center) | 10.0 | Insecure Java deserialization; unauth RCE as root via crafted HTTP requests to mgmt interface | Interlock ransomware | High - zero-day since Jan 26; DaVita, Kettering Health, Texas Tech, Saint Paul MN confirmed victims | Yes (Mar 19, 2026) |
| CVE-2026-20963 | Microsoft SharePoint | High | Deserialization flaw; unauth remote attacker achieves RCE on SharePoint server | Multiple / opportunistic | Moderate - active exploitation confirmed at KEV listing | Yes (Mar 18, 2026) |
| CVE-2025-53521 | F5 BIG-IP APM | 9.3 | RCE via unauthenticated access to APM component | Multiple | Moderate | Yes (Mar period) |
| CVE-2026-22719 | VMware Aria Operations | High | Authentication bypass / privilege escalation in monitoring platform | Multiple | Moderate - added CISA KEV March 4 | Yes (Mar 4, 2026) |
| CVE-2026-1731 | BeyondTrust (PAM/PRA) | Critical | Unauthenticated RCE - attackers bypass authentication in privileged access management platform | Ransomware groups | Moderate | Credible reporting |
| CVE-2026-1603 | Ivanti EPM | High | Authentication bypass in endpoint management platform | Multiple | Moderate | Yes (Mar 9, 2026) |
| CVE-2025-26399 | SolarWinds Web Help Desk | High | Deserialization of untrusted data - RCE potential | Multiple | Low-Moderate | Yes (Mar 9, 2026) |
| CVE-2026-3909 | Google Skia / Chrome | High | Out-of-bounds write in Skia graphics library - browser exploitation chain | APT / crimeware | Browser-scope | Yes (Mar 13, 2026) |
| CVE-2025-32432 | Craft CMS | High | Server-side code injection via user-controlled template input | Multiple / ransomware | Moderate | Yes (Mar 20, 2026) |
| CVE-2025-54068 | Laravel Livewire | High | Code injection in popular PHP web framework component | Multiple | Moderate - web-facing assets | Yes (Mar 20, 2026) |
| CVE-2026-33017 / CVE-2026-33634 | Langflow / Trivy (supply chain) | Critical | RCE in Langflow AI workflow platform; Trivy supply chain compromise (not a traditional CVE - injected malicious binaries) | TeamPCP supply chain campaign | High - 1,000+ enterprise environments est. affected | Yes (Mar 27, 2026) |
| CVE-2021-22054 | Omnissa Workspace ONE | High | Server-side request forgery - legacy vulnerability re-emerging in active exploitation | Multiple | Low-Moderate | Yes (Mar 9, 2026) |
| CVE-2026-47813 | Wing FTP Server | High | Information disclosure enabling credential theft or lateral movement | Multiple | Low-Moderate | Yes (Mar 16, 2026) |
Analysis note: The March 2026 KEV catalog additions show a concentration in enterprise management platforms (Cisco FMC, VMware Aria, Ivanti EPM, BeyondTrust, SolarWinds WHD) and web application frameworks (Craft CMS, Laravel Livewire). This pattern is consistent with the observed IAB strategy of targeting edge devices and management infrastructure to achieve persistent enterprise-wide access rather than individual endpoint compromise.
SECTION 9 - SUPPLY CHAIN AND THIRD-PARTY COMPROMISE TRACKING
March 2026 represents an exceptionally active month for supply chain attacks, with two distinct large-scale developer toolchain campaigns identified. Supply chain attacks as a percentage of total incidents is assessed as increasing, driven by attacker recognition that developer tools and CI/CD infrastructure provide high-density access to enterprise environments at scale.
9.1 TeamPCP / PCPcat Campaign (March 2026)
- Attribution: TeamPCP (also tracked as PCPcat, ShellForce). March 2026 campaign represents a significant escalation in scope.
- Scope: Simultaneously breached five major developer ecosystems - GitHub Actions, Docker Hub, PyPI, NPM, and OpenVSX.
- Method: Leveraged previously compromised credentials with tag write access. Attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted version references to malicious commits. Triggered release automation to publish infected Trivy binary (v0.69.4) to official distribution channels including GitHub Releases and container registries.
- Additional targets: Checkmarx KICS (infrastructure-as-code scanner) and LiteLLM (PyPI - AI proxy package). LiteLLM compromise involved a three-stage payload: credential harvesting, Kubernetes lateral movement, and persistent backdoor for remote code execution.
- Scale estimate: Over 1,000 downstream enterprise SaaS environments assessed as affected. Security-adjacent tooling (scanners, proxies) provides high-trust access to production CI/CD pipelines.
- Detection: Microsoft Security Blog published guidance on March 24, 2026. CrowdStrike published technical analysis. CISA added CVE-2026-33634 (Trivy-related) to KEV March 27.
- Defensive implication: Pin dependency versions by cryptographic hash (SHA256), not semantic version tags. Tags are mutable; hashes are not. Verify integrity of security tooling against known-good checksums.
9.2 GlassWorm Campaign (February-March 2026)
- First appeared February 2026 via compromised developer account on OpenVSX registry. Returned in March 2026 with expanded scope.
- Scope: 72 malicious OpenVSX extensions; 151 GitHub repositories; 433 total compromised components across GitHub, npm, VSCode, and OpenVSX.
- Method: Injected invisible Unicode characters to encode payloads within repository source code, evading conventional string-matching detection. Malware poses as developer utilities (linters, formatters, code runners, AI coding assistants). Exploits extensionPack and extensionDependencies to propagate as transitive dependencies after initial trust establishment.
- C2 resilience: Primary C2 channel uses the Solana public blockchain - malware queries the attacker's wallet address for transaction memo fields containing Base64-encoded C2 URLs. Fallback C2 via hardcoded Google Calendar event URL containing encoded instructions. Both mechanisms are resistant to traditional domain-based blocking.
- Targets: Cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment secrets. Primary risk is developer-to-enterprise pivot: compromised developer credentials enable lateral movement into source code repositories, cloud infrastructure, and CI/CD pipelines.
9.3 Supply Chain Trend Assessment
Supply chain attacks as a percentage of total incidents are increasing. The March 2026 clustering of TeamPCP and GlassWorm campaigns - both targeting developer tooling - reflects a strategic recognition that CI/CD pipeline access bypasses endpoint and network perimeter defenses entirely. The MOVEit-style mass exploitation template established by Clop in 2023 demonstrated the scalability of single-vendor compromise; TeamPCP's multi-ecosystem simultaneous breach represents an evolution of this model. Expect continued targeting of: (1) widely used open-source security tooling, (2) AI/LLM-adjacent libraries and proxies, (3) package registries with limited vetting processes.
SECTION 10 - STRATEGIC LEVERAGE ASSESSMENT
Analyst assessment of the month's highest-value pressure points based on observed structural weaknesses, enforcement opportunities, and ecosystem dependencies identified during the reporting period.
10.1 Financial Pressure Points
- Xinbi-style marketplace targeting (HIGH VALUE): The UK Xinbi sanction demonstrates that Chinese-language cryptocurrency marketplaces processing billions in illicit flows remain insufficiently targeted. Xinbi's $19.9 billion in transactions represents only one platform in a broader ecosystem of similar Southeast Asia-linked exchanges. Coordinated multi-jurisdiction designation of additional exchanges in this ecosystem would constrain financial infrastructure for scam/BEC operations. The Philippines, Thailand, and Singapore are key jurisdictions for complementary action.
- BPH Operator Financial Isolation (MEDIUM-HIGH VALUE): Media Land/Aeza/Hypercore sanction chain demonstrates the pattern: Russia-based BPH operators establish Western-registered front entities for banking access. Targeting the banking relationships of these front entities (UK, Cyprus, UAE registered entities specifically) before they rebrand is a higher-yield intervention than pursuing primary BPH operators in Russia.
- Ransom Payment Infrastructure (MEDIUM VALUE): The 50% decline in average ransom payments ($2M to $1M from 2024 to 2025) suggests that organizational resilience improvements are reducing payment leverage. Continued pressure on cryptocurrency exchanges handling ransomware proceeds - particularly smaller non-KYC exchanges - would further constrain cash-out options.
- DPRK IT Worker Cryptocurrency Networks (HIGH STRATEGIC VALUE): The March 12, 2026 OFAC designations targeting DPRK IT worker network facilitators in Vietnam and Laos represent high-yield enforcement: these networks generate $800M+ annually for weapons programs. The geographic concentration in Southeast Asia and use of Vietnamese/Laotian front companies creates actionable enforcement targets in jurisdictions with improving cooperation frameworks.
10.2 Infrastructure Pressure Points
- RAMP Successor Forums (HIGH PRIORITY - time-sensitive): T1erOne and Rehub are now the primary migration destinations for displaced RaaS affiliates post-RAMP. T1erOne's $450 entry fee model and referral gating reduces open intelligence but creates a finite, traceable user population. Disruption within 60-90 days of RAMP seizure - while the ecosystem is still fragmenting - has asymmetric value. Window of opportunity is narrowing.
- RaaS Leak Site Infrastructure (MEDIUM VALUE): Qilin, Akira, LockBit5, DragonForce, and Interlock all maintain active Tor-based leak sites used for victim pressure. These sites depend on BPH infrastructure that is increasingly concentrated among a small number of sanctioned or sanction-adjacent Russian providers. Disrupting the Tor hosting layer for multiple simultaneous leak sites would degrade the double-extortion pressure mechanism.
- Lumma C2 Infrastructure (MEDIUM-HIGH VALUE): Despite the May 2025 takedown, Lumma C2 reconstituted within weeks. New C2 leverages legitimate Russian cloud providers (Selectel) and distributed legitimate cloud infrastructure. A follow-on action targeting the Selectel-hosted infrastructure with Russian regulatory engagement (unlikely but possible) or provider-level blocks would impose higher reconstitution costs than domain seizure alone.
- GlassWorm / TeamPCP C2 Blockchain Infrastructure (LOW CURRENT VALUE): C2 via Solana blockchain transaction memos is a novel evasion mechanism that is difficult to block without blocking Solana access broadly. Registry-level action (GitHub, npm, OpenVSX) removing malicious packages is the primary available countermeasure and has been partially executed.
10.3 Jurisdictional Pressure Points
- Russia (CRITICAL STRUCTURAL GAP): Russia continues to provide effective safe harbor for major RaaS operators. CIS-exclusion logic in Qilin, Akira, LockBit5, and DragonForce is functionally a declaration of jurisdictional protection. No extradition treaty with the US or EU exists. Aleksei Volkov and Ilya Angelov sentencings (both caught outside Russia) demonstrate that enforcement is possible only when actors leave the safe harbor perimeter. Structural leverage requires either third-country interdiction or internal political shifts.
- Southeast Asia - Cambodia, Myanmar, Thailand (HIGH PRIORITY): The UK's '#8 Park' Cambodia sanctions and FBI/Thai crypto freezes indicate improving enforcement cooperation in Southeast Asia, specifically targeting scam center financial infrastructure. This is a tractable jurisdiction gap compared to Russia, with active bilateral cooperation frameworks.
- Vietnam, Laos - DPRK IT Worker Networks (ACTIONABLE): DPRK IT worker network facilitators are concentrated in Vietnam and Laos. Recent OFAC designations name Vietnamese front companies. Both countries have existing AML cooperation frameworks; coordinated Financial Intelligence Unit (FIU) engagement with Vietnamese and Laotian authorities targeting designated entities represents a tractable near-term action.
- Netherlands, Germany, UK - Infrastructure Hosting (ACTIVE COOPERATION): The LeakBase takedown's seizure of infrastructure from the Netherlands to Malaysia demonstrates that Western European hosting infrastructure is fully cooperative. Continue to exploit cooperative hosting provider relationships for rapid takedown actions.
10.4 Recommended Focus Areas - April 2026
- PRIORITY 1: Monitor T1erOne and Rehub forums for affiliate recruitment activity. Identify early indicators of new RaaS platform launches to enable proactive disruption before operational maturation.
- PRIORITY 2: Track Interlock ransomware campaign expansion. CVE-2026-20131 zero-day capability suggests continued investment in pre-patch vulnerability research; assess whether additional enterprise network management CVEs are being held for future campaigns.
- PRIORITY 3: Assess impact of LeakBase database seizure on IAB market credential supply. 142,000 user records and full forum database in FBI custody represents high attribution value; anticipate indictments targeting forum users in the 30-90 day window.
- PRIORITY 4: Monitor Lumma stealer distribution metrics for post-recovery volume normalization. New MFA bypass capabilities represent a structural risk increase for enterprise accounts using legacy OTP MFA.
- PRIORITY 5: Evaluate financial intelligence engagement with Vietnamese and Laotian FIUs regarding OFAC-designated DPRK IT worker network facilitators identified in the March 12, 2026 designations.
SECTION 11 - UNCONFIRMED SIGNALS AND HORIZON INDICATORS
The following items are credible but unverified signals with potential strategic significance. All items are labeled [UNCONFIRMED REPORTING] unless otherwise indicated.
Chaos Ransomware Group - BlackSuit Successor / Rebrand: Reporting indicates that a group operating as 'Chaos' in 2026 may represent a rebrand of BlackSuit, which itself was assessed as a Royal ransomware successor. The Chaos branding reportedly offers DDoS capabilities to affiliates in addition to encryption - an unusual affiliate incentive. Timeline and attribution are unconfirmed; the relationship to previous BlackSuit operations requires corroboration from independent technical indicators. [UNCONFIRMED REPORTING]
Sinobi Ransomware Group: Listed among top-3 most active groups in Q1 2026 by Bitsight CTI. Limited independent technical reporting available on group TTP, origin, or affiliate structure. Credibly active based on victim disclosures but attribution and infrastructure details are not confirmed. Assess as emerging group requiring closer monitoring. [UNCONFIRMED REPORTING - LIMITED COLLECTION]
NightSpire: Appearing in Q1 2026 victim disclosure tracking alongside Akira and Qilin. No detailed technical analysis of NightSpire available at time of writing. Origin and RaaS vs. direct-operation model not confirmed. [UNCONFIRMED REPORTING - LIMITED COLLECTION]
DragonForce Cartel Model - Absorption of Smaller Groups: Reporting suggests DragonForce is actively marketing its RaaS platform to former ALPHV/BlackCat and RansomHub affiliates following those groups' disruptions. The extent of affiliate absorption and whether DragonForce is consolidating into a dominant platform analogous to LockBit's 2022-2024 dominance is unconfirmed. [UNCONFIRMED REPORTING]
DaVita Ransom Payment Status: DaVita (dialysis provider) confirmed as an Interlock ransomware victim via CVE-2026-20131. Payment status and data exfiltration scope not publicly confirmed. Given patient data sensitivity and regulatory exposure, DaVita represents a high-pressure target where payment remains possible. [UNCONFIRMED - MONITOR]
RaaS Platform - Zero-Day Acquisition Market Activity: Interlock's demonstrated zero-day exploitation capability (CVE-2026-20131 held 36 days pre-disclosure) suggests either direct vulnerability research capability or acquisition from a broker. The existence of a zero-day brokerage relationship feeding ransomware operators - analogous to nation-state zero-day procurement - would represent a significant ecosystem maturation event. No confirmed second instance of ransomware-linked zero-day brokerage at time of writing. [ANALYST INFERENCE]
SECTION 12 - ANALYTIC CAVEATS AND COLLECTION GAPS
- Victim Count Inflation: Ransomware victim counts sourced from dark web leak site monitoring may be inflated due to group re-posting of the same victim across multiple platforms, delayed posting of historical victims for pressure purposes, and unverified claims by new or low-credibility groups. The 2,505 Q1 2026 figure is a disclosed extortion count, not a confirmed incident count. Actual incidents are likely higher; disclosed figures should be treated as a floor, not a ceiling.
- Collection Access Restrictions: During the collection period for this report, direct access to BleepingComputer (www.bleepingcomputer.com), The Record (therecord.media), and Bitdefender Business Insights (businessinsights.bitdefender.com) was blocked by network egress proxy. Content from these sources was accessed via web search result excerpts only. Some nuance and technical detail from these sources may be missing. Treasury.gov direct fetch was also blocked; SB0225 designation details are incomplete.
- RAMP Successor Forum Visibility: The seizure of RAMP and migration to closed forums (T1erOne, Rehub) has materially reduced open-source visibility into affiliate recruitment activity. This report's assessment of the post-RAMP ecosystem is based on secondary reporting and may not fully reflect current affiliate coordination patterns.
- February 2026 Sector Disaggregation: February 2026 sector-specific victim counts were not available as disaggregated monthly figures at the time of reporting. The Sector Targeting Trend Table in Section 2 uses Q4 2025 baseline figures and Q1 2026 aggregate data; month-over-month precision is limited.
- Lumma Recovery Metrics: Lumma's reconstitution timeline and current scale (as of March 2026) are based on vendor threat intelligence reporting and trend data, not direct infrastructure measurement. Claims that Lumma is 'at scale' represent vendor assessments; independent verification via C2 enumeration was not available for this report.
- DragonForce and Sinobi Attribution: Attribution for DragonForce's country of origin remains unconfirmed in authoritative public reporting. Origin indicators suggest possible Malaysian or Middle Eastern origin, inconsistent with the predominantly Russian/CIS RaaS landscape. Sinobi group origin and infrastructure not confirmed. Both groups are treated as unattributed with respect to nation-state nexus.
- Supply Chain Impact Estimates: The '1,000+ downstream enterprise environments affected' figure for the TeamPCP/Trivy campaign is an early estimate from vendor reporting and has not been independently verified. Actual impact scope may be higher or lower depending on how quickly organizations patched or detected the compromised tooling.
- Tor Instability and Reporting Gaps: Periodic Tor instability and DDoS activity against dark web infrastructure can cause ransomware group leak sites to appear offline without reflecting actual operational pause. Apparent gaps in group activity disclosures during the period may reflect infrastructure instability rather than reduced operational tempo.
SOURCES
Ransomware Tracking Platforms
- Ransomware.live - Victim tracking and group activity monitoring: https://www.ransomware.live/
- Ransom-DB.com - Weekly ransomware trend analysis: https://www.ransom-db.com/blog/weekly-ransomware-trends-qilin-akira-march-2026
- Purple Ops - Daily ransomware reporting, Q1 2026: https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/daily-ransomware-3-21-2026/
- RansomLook - Group activity and leak site monitoring: https://www.ransomlook.io
Government and Law Enforcement
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- CISA - Five KEVs Added March 20, 2026: https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog
- US Department of Justice - LeakBase Dismantlement: https://www.justice.gov/opa/pr/united-states-leads-dismantlement-one-worlds-largest-hacker-forums
- US Department of Justice - Aleksei Volkov Sentencing: https://www.justice.gov/opa/pr/russian-citizen-sentenced-prison-hacking-us-companies-and-enabling-major-cybercrime-groups
- US Treasury OFAC - Media Land BPH Sanctions (SB0319): https://home.treasury.gov/news/press-releases/sb0319
- US Treasury OFAC - Crypto Exchange Sanctions (SB0225): https://home.treasury.gov/news/press-releases/sb0225
- White House Executive Action on Cybercrime (March 2026): https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/
- INTERPOL - Operation Synergia III Results: https://www.theregister.com/2026/03/13/interpol_operation_synergia/
- UK Government - Xinbi Cryptocurrency Marketplace Sanctions: https://www.gov.uk/government/news/uk-crackdown-on-vile-scam-centres-steps-up-with-sanctions-on-illicit-crypto-network
- National Crime Agency - Media Land Sanctions: https://www.nationalcrimeagency.gov.uk/news/prolific-bulletproof-hosting-service-sanctioned-by-the-uk-and-allies
- Federal Register - Combating Cybercrime Executive Order: https://www.federalregister.gov/documents/2026/03/11/2026-04826/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens
Vendor Threat Intelligence
- Bitdefender Threat Debrief March 2026: https://www.bitdefender.com/en-us/blog/businessinsights/bitdefender-threat-debrief-march-2026
- Microsoft Security Blog - Trivy Supply Chain Compromise: https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/
- CrowdStrike - From Scanner to Stealer: Trivy Supply Chain: https://www.crowdstrike.com/en-us/blog/from-scanner-to-stealer-inside-the-trivy-action-supply-chain-compromise/
- Trend Micro - Lumma Stealer Returns: https://www.trendmicro.com/en_us/research/25/g/lumma-stealer-returns.html
- Trend Micro - LiteLLM Supply Chain Compromise: https://www.trendmicro.com/en_us/research/26/c/inside-litellm-supply-chain-compromise.html
- AWS Security Blog - Interlock Ransomware Cisco FMC Campaign: https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/
- Chainalysis - 2026 Crypto Crime Report Introduction: https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/
- Chainalysis - OFAC DPRK IT Workers Designations: https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/
- Darktrace - Rise of Lumma Info Stealer: https://www.darktrace.com/blog/the-rise-of-the-lumma-info-stealer
- SecurityAffairs - Interlock Exploits Cisco FMC 36 Days Before Disclosure: https://securityaffairs.com/189636/malware/interlock-group-exploiting-the-cisco-fmc-flaw-cve-2026-20131-36-days-before-disclosure.html
- Group-IB - Operation Synergia III Contribution: https://www.intelligentciso.com/2026/03/16/group-ib-supports-interpols-operation-synergia-iii-contributing-intelligence-to-global-cybercrime-takedown/
- Flare - RAMP Seizure Analysis: https://flare.io/learn/resources/blog/ramp-seizure
- Bitsight CTI - Q1 2026 Ransomware Statistics: https://www.bitsight.com/underground/ransomware
- KELA Cyber - LeakBase Seizure Analysis: https://www.kelacyber.com/blog/law-enforcement-seizes-leakbase-/
- Cyble - 10 New Ransomware Groups of 2025 and 2026 Trends: https://cyble.com/knowledge-hub/10-new-ransomware-groups-of-2025-threat-trend-2026/
- Recorded Future - New Ransomware Tactics 2026: https://www.recordedfuture.com/blog/ransomware-tactics-2026
Cybersecurity News
- The Hacker News - Interlock Exploits Cisco FMC CVE-2026-20131: https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html
- The Hacker News - FBI and Europol Seize LeakBase: https://thehackernews.com/2026/03/fbi-and-europol-seize-leakbase-forum.html
- The Hacker News - GlassWorm Supply Chain Attack (OpenVSX): https://thehackernews.com/2026/03/glassworm-supply-chain-attack-abuses-72.html
- The Hacker News - Aleksei Volkov Sentenced 6.75 Years: https://thehackernews.com/2026/03/us-sentences-russian-hacker-to-675.html
- The Hacker News - Russian Hacker Sentenced 2 Years (TA551): https://thehackernews.com/2026/03/russian-hacker-sentenced-to-2-years-for.html
- Help Net Security - Cisco FMC Flaw Exploited by Interlock: https://www.helpnetsecurity.com/2026/03/20/cisco-fmc-interlock-ransomware-cve-2026-20131/
- Help Net Security - CISA CVE-2026-33017/33634 Exploited: https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/
- SecurityWeek - Cisco Firewall Vulnerability Zero-Day: https://www.securityweek.com/cisco-firewall-vulnerability-exploited-as-zero-day-in-interlock-ransomware-attacks/
- SecurityWeek - Ransomware Groups May Pivot Back to Encryption: https://www.securityweek.com/ransomware-groups-may-pivot-back-to-encryption-as-data-theft-tactics-falter/
- Dark Reading - RAMP Forum Seizure Fractures Ecosystem: https://www.darkreading.com/threat-intelligence/ramp-forum-seizure-fractures-ransomware-ecosystem
- The Register - Interpol Sinkholes 45,000 IPs (Synergia III): https://www.theregister.com/2026/03/13/interpol_operation_synergia/
- The Register - FBI Seizes RAMP Forum: https://www.theregister.com/2026/01/28/fbi_seizes_ramp_forum/
- CyberScoop - LeakBase Cybercrime Forum Seized: https://cyberscoop.com/leakbase-cybercrime-forum-seized/
- Infosecurity Magazine - Interpol Operation Synergia III: https://www.infosecurity-magazine.com/news/interpol-operation-synergia3-94/
- Infosecurity Magazine - UK/US Australia Media Land Sanctions: https://www.infosecurity-magazine.com/news/uk-us-sanction-russian-bulletproof/
- Infosecurity Magazine - Infostealers Lumma 400% Surge: https://www.infosecurity-magazine.com/news/infostealers-lumma-stealer/
- CyberGEN Security - Ransomware Groups Overview 2026: https://www.cybergensecurity.co.uk/ransomware-in-2026-an-overview-of-active-and-emerging-threat-groups
- HIPAA Journal - Elevenfold Increase in Data-Only Extortion: https://www.hipaajournal.com/data-shows-elevenfold-increase-data-only-extortion-attacks/
- Industrial Cyber - 50% of 2025 Ransomware Attacks on Critical Sectors: https://industrialcyber.co/reports/half-of-2025-ransomware-attacks-hit-critical-sectors-as-manufacturing-healthcare-and-energy-top-global-targets/
- Nextgov/FCW - European Officials on Private Sector Cybercrime Takedowns: https://www.nextgov.com/cybersecurity/2026/03/european-officials-highlight-private-sector-help-major-cybercrime-takedowns/412388/
- LiveBitcoinNews - Crypto Crime Hits $154B in 2026 (Chainalysis): https://www.livebitcoinnews.com/crypto-crime-hits-154b-in-2026-says-chainalysis-report/
- Crypto.news - UK Sanctions Xinbi $19.9B Fraud Empire: https://crypto.news/uk-becomes-first-country-to-sanction-crypto-marketplace-xinbi-over-19-9b-fraud-empire/