The Observatory / Document Library / EDP Monthly May 2026
Monthly Cybercrime Ecosystem Intelligence Report
Coverage period May 2026. The Stark Industries seizure, RAMP passing 120 days dark, and supply-chain compromise entering the mainstream of intrusion reporting.
Stark Industries: 800+ servers seizedMay 2026Download PDF

Confidence labels are applied throughout: CONFIRMED, CREDIBLE REPORTING, and ANALYST INFERENCE. Figures carried forward from earlier periods are dated explicitly where month-specific data was unavailable. To see which ecosystem nodes moved during this reporting period, open the map's delta view for May 2026.

SECTION 1 - EXECUTIVE SUMMARY

Five items, priority ranked by ecosystem-level strategic impact. All items confirmed. Each includes a supporting metric.

PriorityFindingConfidence
1 - HIGHEST IMPACTOperation Saffron (May 19-20) and the Dutch FIOD Stark Industries seizure (~May 18-27) simultaneously removed First VPN - anonymization infrastructure used by 25 ransomware groups - and 800 bulletproof servers hosting Russian-nexus attack and disinformation operations, the most coordinated infrastructure strike against the ecosystem since Operation Cronos.CONFIRMED
2The Gentlemen RaaS - the ecosystem's second most active operator with approximately 332 YTD victims - suffered an internal backend breach on May 4 that exposed admin identity zeta88/hastalamuerte, 8 affiliate TOX IDs, 29 campaign samples, the full cash-out chain (Tinkoff QR codes, OTC delivery), and a confirmed $190,000 ransom payment; law enforcement has a narrow 30-60 day window before operational security rebuilds.CONFIRMED
3Ransomware's payment model is structurally collapsing: 69% of victims refused payment in 2025 (Verizon 2026 DBIR), ransom payment rates have fallen from 76% (2019) to 28% (2026, Kaspersky), and 95% of illicit ransomware proceeds now transit stablecoin infrastructure - principally USDT via the $72B A7A5 token cluster - creating a single, targetable financial chokepoint.CONFIRMED
4CVE-2026-20182 (Cisco Catalyst SD-WAN Controller, CVSS 10.0) was added to CISA KEV on May 14-15 after active exploitation by at least 10 distinct threat clusters including UAT-8616 since March 2026, representing a ~70-day gap between initial exploitation and federal advisory that exposed unpatched organizations throughout the period.CONFIRMED
5The ransomware ecosystem has reconsolidated after 2025 fragmentation: Qilin, The Gentlemen, Akira, and LockBit 5.0 collectively accounted for 41% of Q1 2026 victims (2,122 total), while the top 10 groups controlled 71% - a cartel-level concentration reversing the prior quarter's fragmentation and making targeted action against the top-4 platform operators the highest-leverage disruption strategy available.CONFIRMED

SECTION 2 - RANSOMWARE ECOSYSTEM: MAY 2026 STATISTICS

2.1 Monthly Volume & Active Groups

2.2 Sector Targeting Trend (April 2026 vs. March 2026)

Source: Breachsense April 2026 Report. April actuals; March provided for comparison.

SectorApril 2026 (n)March 2026 (n)% ChangeTrend / Notes
Healthcare6447+36%Increasing - leading critical-sector target
Technology5636+56%Increasing - fastest-growing April sector
Manufacturing5076-34%Decreasing - monthly volatility; remains YTD leader
Legal Services4043-7%Stable
Consumer Goods3728+32%Increasing
Construction3753-30%Decreasing
IT Services3135-11%Stable
Education3026+15%Increasing
Engineering29No prior dataN/ANew in April top 10; no March baseline available
Finance2848-42%Decreasing - record median demand ($3M) despite lower count

2.3 Geographic Targeting Analysis

Source: Breachsense April 2026 Report.

RankCountryVictims (Apr)% of TotalNotes vs. March
1United States30439.4%-10.6 pts (was 50% in March) - absolute targeting unchanged; geographic spread widening
2Germany374.8%+0.6 pts
3United Kingdom344.4%+1.3 pts
4Canada283.6%+1.4 pts
5France273.5%-1.2 pts
6Italy263.4%+0.4 pts
7Spain212.7%+0.4 pts
8Australia192.5%Stable
9India162.1%+0.3 pts
10Thailand162.1%New in April top 10 - Southeast Asia expansion signal

2.4 Leak Site Three-Signal Composite

SignalThis MonthPrior MonthTrendNotes
Post Volume (victims published)~700 est. May; 772 confirmed April772 (April)Down ~9.4% MoMBreachsense April 2026 Report; May tracking estimate from Ransomware.live
Takedown/Relaunch CycleRAMP: seized Jan 28; no confirmed successor at 120+ days (anomalous - typical 60-90 day reconstitution)RAMP active (pre-Jan)Resilience cost HIGH120+ day absence is longest observed gap since RAMP launch in 2021

Composite interpretation: Post volume is trending down ~9.4% MoM, consistent with - though not exclusively attributable to - the Operation Saffron / Stark Industries infrastructure disruptions and the RAMP forum void. The RAMP 120+ day non-reconstitution is the single most anomalous structural signal this cycle; typical gap is 60-90 days. Time-to-publish data remains a collection gap. The volume decline combined with an unknown time-to-publish trajectory means we cannot confirm whether groups are publishing fewer victims or simply slower - analytically significant for ransom leverage assessment.

SECTION 3 - THREAT ACTOR LANDSCAPE

Russia/CIS-linked groups prioritized. Victim counts are April 2026 actuals from Breachsense April 2026 Report except where noted. Q1 counts from Check Point Research.

GroupVictims (Apr / Period)Cumul. ProceedsKey May DevelopmentThreat LevelCIS-Excl.
Qilin103 (Apr); 445 YTDNo reliable dataLed victim disclosures 4th consecutive month; formal BreachForums partnership (300,000+ users) announced March 2026; 26 confirmed healthcare victims YTD (17% of all healthcare DLS listings)Stable - dominant tierUnknown (no published CIS-exclusion policy)
The Gentlemen82 (Apr); ~332 YTDNo reliable dataMay 4 backend breach exposed admin identity zeta88/hastalamuerte, 8 affiliate TOX IDs, full cash-out chain, $190,000 confirmed payment, CVE tracking list - unprecedented intelligence windfallIncreasing - then disruptedUnknown
DragonForce63 (Apr); growing every month in 2026No reliable dataConsistent monthly growth (Feb 30 → Mar 54 → Apr 63); on trajectory to challenge Qilin volume by Q3 2026 if trend continues - ANALYST INFERENCE; shared infrastructure overlap with LockBit and Qilin confirmedIncreasingUnknown
Akira48 (Apr); volatile (Jan 71, Feb 39, Mar 84, Apr 48)No reliable dataVPN exploitation confirmed as dominant access vector: S-RM 2026 reports VPN devices account for 68% of remote-access exploit cases, with nearly 70% of those linked to Akira campaigns; BYOVD attacks confirmedStable - high volatilityAssessed (historically observed)
LockBit 5.039 (Apr); 163 Q1 2026No reliable dataComeback confirmed by Check Point (+106% vs Q4 2025); May 9 claimed VP Brands International (Bulgaria); cross-platform (Windows/Linux/ESXi); climbed from outside top 10 to 4th globally in Q1Increasing - comeback trajectory confirmedAssessed (historically observed)
INC Ransom41 (Apr)No reliable dataConsistent top-5 operator; targets US, Canada, Germany, Australia, UK; sectors include professional services, healthcare, government, manufacturing - Source: Cyfirma May 2026StableUnknown
WorldLeaks (Hunters Intl. rebrand)13 (Apr); 31 since Jan 2026 relaunchNo reliable dataEncryption-free exfiltration model since January 1 2025 relaunch; targeted American Battery Factory in May; embodies the pure-extortion trend; represents a complete operational pivot from traditional RaaSStable - pioneering the dominant 2026 attack modelUnknown
Payload~50 total since Feb 2026 launchNo reliable dataBabuk-derived source code; cross-platform (Windows + ESXi); targets healthcare, energy, real estate, agriculture; claimed 12 victims in 7 countries within hours of launchingIncreasing - new entrant, rapid accumulationUnknown
KarakurtInactive (legacy)$56M+ from 54+ victims ($15M confirmed paid)May 6: negotiator Deniss Zolotarjovs (Latvian, 35) sentenced to 8.5 years; DOJ confirmed gang used Russian government database access and paid military draft bribes - establishing state-facilitation precedentDecreasing - legacy, leadership sentencedConfirmed (leadership sanctioned)

3.2 The Gentlemen - Operational Intelligence Deep-Dive (May 4, 2026)

Source: Check Point Research 'Thus Spoke...The Gentlemen' (May 13, 2026) - verified source. The May 4 internal backend breach of The Gentlemen's Rocket database is the most significant actor-specific intelligence event of the reporting period.

3.3 Data Extortion Trend (Encryption-Free)

SECTION 4 - INITIAL ACCESS & TTP EVOLUTION

4.1 Access Vector Ranking (May 2026)

Ranked most to least common. Sources: Rapid7 H2 2025 IAB Report, S-RM 2026 Cyber Incident Insights, Check Point Research Gentlemen leak analysis.

4.2 Significant TTP Developments This Cycle

4.3 IAB Market Indicators

Note: H2 2025 $113,275 average is heavily skewed by DarkForums' premium listings; Rapid7 expanded sampling to include DarkForums and RAMP for the first time in H2 2025. Forum-normalized price comparison would show a more moderate increase. This report accepts the Rapid7 methodology while flagging the confound.

IndicatorThis Period (H2 2025-May 2026)Prior PeriodTrend
Volume of corporate access listings~530 observed threads across 5 forums in H2 2025 (Rapid7)~400 observed threads (Rapid7 2025 Report)Increasing
Average IAB base price$113,275 H2 2025 average (Rapid7); NOTE: DarkForums' premium listings heavily skew this average - forum-normalized price shows more moderate increase$2,726 (FY 2024, Rapid7)+4,055% - partially a sampling expansion artifact
Premium listing ceiling>$100,000>$100,000Stable
Most-targeted sectors (top 3)Government 14.2%, Retail 13.1%, IT 10.8% (Rapid7 H2 2025)Financial Services, IT (prior periods)Government now dominant - shift from financial services
Dominant access type (listings)RDP 21.2%, VPN 12.8%, RDWeb 11.2% (Rapid7 H2 2025); VPN devices = 68% of actual exploit cases handled by S-RMVPN 45%, RDP 41% (prior period)RDP now leads listings; VPN leads exploitation cases
Notable marketplace eventsRAMP seized Jan 28, 2026 (120+ days dark); BreachForums 323,986-user DB exposed; DarkForums grew 600% Apr-Jun 2025; Vect-BreachForums partnership Mar 2026BreachForums repeated seizures 2023-24Ecosystem migrating to DarkForums and private channels

SECTION 5 - MALWARE & STEALER ECOSYSTEM

Sources: AhnLab ASEC Feb 2026, Flare 2026 State of Enterprise Infostealer Exposure (May 25, 2026), Recorded Future, TrendMicro, SOCRadar.

FamilyMarket Share / VolumeDistribution MethodNotable DevelopmentDisruption Status
LummaC2#1 by distribution volume (ANALYST INFERENCE, high confidence); 394,000+ Windows PCs infected in 60 days prior to May 2025 takedown (Microsoft); ~400% detection increase over prior 12 monthsClickFix fake CAPTCHA (PowerShell via Windows Run dialog); GitHub repos with AI-generated READMEs promoting cheats/exploits; malvertising; social media (YouTube, Facebook)Post-May 2025 takedown: operators shifted from Cloudflare to Selectel (Russian-hosted) for C2; CastleLoader is primary delivery chain since Feb 2026 resurgence; fileless execution via .NET XOR decrypt-in-memoryActive - disrupted May 2025 by Microsoft/DOJ/Europol; infrastructure reconstituted within weeks
ACRStealerTop-4 active distribution as of Feb 2026 (AhnLab ASEC); exact market share: No reliable dataSocial engineering lures; cracked software distributionNo significant new development this cycleActive - no disruption
StealCTop-4 active; absorbed Lumma volume post-May 2025 disruption (Recorded Future); $200/month or $800/6-month MaaS subscription (SOCRadar)Telegram MaaS subscription; social engineeringGrowing market share as Lumma disruption beneficiaryActive - no disruption
VidarTop-4 active; $100-200/month subscription (Flare 2025); uses Telegram and Mastodon for C2 to blend into legitimate trafficSocial engineering; fake software; legitimate social media C2 abusePersistent macOS-targeting capability; cryptocurrency wallet theft emphasisActive - no disruption
AMOS / Atomic StealerSignificant macOS ecosystem expansion; no reliable market share percentage; includes persistent backdoor surviving reboots in latest versionsFake macOS applications; cloned Homebrew installers; ClickFix-style DMG installersConfirmed macOS expansion threat - no longer an 'emerging' concernActive - no disruption
RedLineDeclining; legacy logs still circulating in underground marketsPhishing email attachmentsOperational decline post-Operation Magnus (Oct 2024); logs remain live credential threat for months post-infectionPartially disrupted - logs still active

5.2 Infostealer-to-IAB Pipeline Assessment

SECTION 6 - FINANCIAL & INFRASTRUCTURE SIGNALS

6.1 Sanctions & Enforcement Actions

DateAuthorityTargetRationaleFinancial ExposureDisruption Impact
May 20, 2026OFAC / U.S. TreasurySinaloa Cartel fentanyl-to-crypto laundering network (Los Chapitos faction; Armando de Jesus Ojeda Aviles network); 11 individuals, 2 entitiesCrypto-laundering of fentanyl proceeds; cash-to-crypto conversion moving U.S. drug sales to MexicoNot publicly specified in SDN designationMedium - financial cell disrupted; cartel has redundant laundering infrastructure
~May 18-27, 2026Dutch FIOD (EU sanctions enforcement)Stark Industries / WorkTitans BV / MIRhosting: 2 arrests - Youssef Zinad (57, Amsterdam) and Andrey Nesterenko (39, The Hague); 800+ servers seizedProviding economic resources to EU-sanctioned entities supporting Russian hybrid warfare; sanctions law violation (not cybercrime statutes - novel prosecutorial theory)800+ servers seized; 5 locations raided (Enschede, Almere, Dronten, Schiphol-Rijk data centers)High - primary Russian-aligned BPH platform dismantled; disrupts cyberattack staging, disinformation, and influence ops against EU states
April 24, 2026OFAC / U.S. Treasury + Tether + LECentral Bank of Iran (CBI) - 2 cryptocurrency addresses added to SDN List; Tether froze $344M in USDT linked to CBI-affiliated walletsSanctions evasion; state-directed financial flows$344 million USDT frozenHigh - largest single crypto freeze tied to state-nexus actor in window; demonstrates Tether's cooperative capacity with OFAC

6.2 Ransomware Financial Flow Observations

6.3 Infrastructure Hosting Patterns

SECTION 7 - LAW ENFORCEMENT & REGULATORY ACTIONS

7.1 May 2026 Actions

OperationLead Agency/AgenciesDateOutcomeEcosystem Impact
Operation SaffronFrance, Netherlands (co-lead); Europol, Eurojust; 18 countries total; private sector: BitdefenderMay 19-20, 202633 servers seized across 27 countries; 1 operator arrested (Ukraine); domains 1vpns.com/.net/.org + Tor.onion variants seized; 83 intelligence packages on 506 identified users shared with partner countries; 5,000+ user accounts flagged in criminal traffic logs obtainedHIGH - removed primary anonymization layer used by 25 ransomware groups (incl. Avaddon, Phobos) for 12 years; 506 user exposures generate significant downstream case pipeline
Stark Industries / Dutch FIODDutch FIOD (lead); European intelligence and financial crime partners~May 18-27, 2026~800 servers seized; 2 arrests - Youssef Zinad (57) and Andrey Nesterenko (39); 5 locations raided; ledgers, laptops, and mobile phones seized; charged under Dutch sanctions lawHIGH - dismantled primary EU-facing Russian-aligned cyberattack, disinformation, and influence operation staging platform; novel sanctions-law theory, if sustained, enables prosecution of European hosting enablers
Karakurt - Zolotarjovs SentencingU.S. DOJ (Southern District of Ohio)May 6, 2026Deniss Zolotarjovs (Latvian, 35) sentenced to 8.5 years; involved in $56M+ in losses across 54+ companies; DOJ confirmed gang used Russian government database access and paid military draft bribes to officialsMEDIUM - Karakurt largely inactive; establishes state-facilitation legal precedent for treating RU-nexus ransomware gangs as state-criminal enterprises
Operation Ramz (INTERPOL MENA)INTERPOL; 13 MENA-region countriesOct 2025 - Feb 2026 (announced May 17, 2026)201 arrests; 382 suspects identified; 3,867 victims identified; 53 servers seized; phishing, malware, and cyber scam operations disruptedMEDIUM - geographic expansion of LE cooperation; primarily fraud and social engineering rather than core ransomware infrastructure
BKA Identifies REvil/GandCrab LeadersGerman Federal Criminal Police Office (BKA)April 6, 2026Public identification of Daniil Shchukin (UNKN, 31, Russian) and Anatoly Kravchuk (43, Russian-Ukrainian); 130 attacks in Germany; €35.4M ($40.8M) total damage; 25 cases, €1.9M paid; international arrest warrants issued (fugitives not in custody)LOW-MEDIUM - legacy group inactive; intelligence and warrant value for network attribution

7.2 Reconstitution Status Tracker (180-Day Window)

Standing tracker updated monthly. Status as of May 31, 2026.

OperationAction DateTargetAction Type30-Day Status90-Day Status180-Day Status
RAMP Forum SeizureJan 28, 2026RAMP Russian-language ransomware forumForum seized; FBI splash pageDark - no confirmed successor at 30 daysDark - no primary confirmed successor at 90 days (anomalous)Pending - 180-day status due July 28, 2026
BreachForums DB ExposureEarly 2026BreachForums (323,986 member accounts)DB resurfaced publicly; member data exposedPartially active - platform operational under degraded trustPartially activePending
LeakBase SeizureMarch 2026LeakBase data distribution platformSeizedNot Reconstituted at 30 daysPending - 90-day status due June 2026Pending
BKA REvil IdentificationApril 6, 2026REvil/GandCrab operators (2 individuals)International arrest warrants issued; fugitives at largeNo arrest at 30 daysPendingPending
Lumma Stealer LE ActionMay 2025Lumma C2 infrastructure (Microsoft/DOJ/Europol)2,300 domains seizedPartially reconstituted - 3-6 monthsLargely reconstituted - Selectel pivot confirmedFully Reconstituted - active at higher operational security

7.3 Cumulative Impact Assessment - May 2026

Short-term disruption (1-30 days): HIGH

Operation Saffron removed the anonymization layer for 25+ active groups simultaneously. Stark Industries dismantled the shared BPH platform used for Russian-nexus attack staging. The Gentlemen internal breach exposed operator identities creating an organic disruption event. The 9.4% MoM victim count decline in May is consistent with - though not exclusively attributable to - these events; seasonal variation and DLS publishing lag cannot be excluded.

Structural ecosystem impact (90+ days): MEDIUM

Historical reconstitution data is limiting: Lumma Stealer reconstituted within weeks post-May 2025 takedown; LockBit reconstituted as LockBit 5.0 within 8 months of Operation Cronos. Neither the Saffron nor the Stark seizure directly targeted RaaS platform operators - only enabling infrastructure. BPH customers will migrate within 1-7 days (historical pattern). The RAMP non-reconstitution at 120+ days is the one anomalous resilience-cost indicator; its cause (LE deterrence vs. private channel migration) will determine the structural significance of the January 2026 seizure.

SECTION 8 - VULNERABILITY EXPLOITATION MATRIX

Includes CVEs with confirmed or credible exploitation in ransomware/malware campaigns during the May 2026 reporting period. Sources: CISA KEV catalog (verified), THN (verified), Rapid7 blog, CERT-UA.

CVEProductCVSSExploitation Method & Post-CompromiseThreat ActorScale / VolumeCISA KEVKEV Date / Notes
CVE-2026-20182Cisco Catalyst SD-WAN Controller & Manager10.0Auth bypass; unauthenticated remote admin access; post-compromise: SSH key injection, NETCONF modification, root escalation, web shell deployment (XenShell, Godzilla, Behinder, Sliver C2, XMRig). 10 distinct clusters active since March 2026.UAT-8616 (primary, Cisco-attributed); 9 additional clusters including cryptominers, credential stealers, Sliver C2Global - 10 clusters, mass scaleYESMay 14-15, 2026; ~70-day exploitation gap before KEV listing
CVE-2025-61882Oracle E-Business Suite v12.2.3-12.2.1410.0Unauthenticated RCE via HTTP; zero-day sold on RAMP forum by Cl0p-attributed actor; financial/HR data exfiltration for subsequent extortionCl0p (attributed, Rapid7)Zero-day selling on RAMP; mass exploitation campaign likely imminent based on Cl0p historical pattern (MOVEit, GoAnywhere, Citrix Bleed)Not confirmed in KEV as of May 31CRITICAL GAP - Oracle EBS environments unprotected; KEV absent
CVE-2024-57726SimpleHelp (remote support)9.9Missing authorization; low-priv technician creates admin API keys → privilege escalation to server admin; MSP-targeting vectorMultiple ransomware groups (MSP-targeting)Actively exploited; federal deadline May 8, 2026YESApr 25, 2026 (~4-16 month KEV lag from 2024 discovery)
CVE-2024-57728SimpleHelp7.2Path traversal (zip slip); admin uploads arbitrary files → RCE; co-exploited with CVE-2024-57726 in MSP environmentsMultiple actorsActive; companion to CVE-2024-57726YESApr 25, 2026
CVE-2025-32433Erlang SSH (Cisco context)9.8RCE via unauthenticated SSH; PoC shared in The Gentlemen's TOOLS channel; zeta88 and qbit actively evaluating for operational deploymentThe Gentlemen (confirmed evaluation in leaked chats)Evaluation phase - not yet at mass-exploitation scaleConfirm with CISANot confirmed in KEV as of reporting
CVE-2025-33073NTLM relay (Active Directory)N/ANTLM relay attack; integrated into RelayKing standard reconnaissance workflow by The Gentlemen; systematic scanning documented in leaked operational chatsThe GentlemenSystematic operational use in confirmed campaignsConfirm with CISANot confirmed in KEV as of reporting
CVE-2025-48700Zimbra Collaboration Suite6.1Cross-site scripting → arbitrary JavaScript in user session; combined with CVE-2025-66376 for RCE chain; no user interaction requiredUAC-0233 (Ukraine-targeting threat actor)Active exploitation since Sept 2025 per CERT-UA; Ukraine-focusedYESApr 20, 2026
CVE-2024-55591Fortinet FortiOS management interface9.8Auth bypass on FortiOS management interface; explicitly referenced in The Gentlemen's internal CVE tracking alongside active FortiGate targeting operationsThe Gentlemen (tracked for operational use)Referenced alongside active FortiGate targetingYES (prior period)Prior to May 2026

KEV lag analysis: CVE-2026-20182 was actively exploited by 10+ clusters from March 2026 but KEV-listed May 14-15 - a ~70-day gap. CVE-2025-61882 (Oracle EBS, CVSS 10.0) is being sold as a zero-day exploit on RAMP with Cl0p attribution and is not yet in KEV - the most significant current KEV gap for organizations dependent on Oracle EBS in finance, HR, and supply chain. The SimpleHelp CVEs (assigned 2024) took 4-16 months to achieve KEV status despite active MSP-targeting exploitation. Organizations relying solely on KEV for patch prioritization are exposed in these pre-KEV windows.

SECTION 9 - SUPPLY CHAIN & THIRD-PARTY COMPROMISE

CampaignAttackerCompromised ComponentDownstream ImpactStatus
Mini Shai-Hulud / TanStack npm WormTeamPCP (linked to CipherForce ransomware group - TechCrunch/SafeDep)TanStack/router GitHub repo; 42 @tanstack/* npm packages (84 malicious artifacts); worm propagated to 317 packages total across Antv (Alibaba), TanStack, and others in ~20 minutes630 malicious versions across 317 packages; Mistral AI, UiPath, and 170+ downstream packages compromised; 2 OpenAI employee corporate devices compromised; credentials from GitHub Actions, AWS IMDS, HashiCorp Vault, Kubernetes exfiltratedDetected by Socket AI Scanner within 6 minutes; malicious packages removed; CVE-2026-45321 assigned (Critical)
DAEMON Tools Installer CompromiseUnknown criminal actorOfficial DAEMON Tools installers versions 12.5.0.2421-12.5.0.2434 (signed with legitimate developer certificates; distributed from official website)~2.5 weeks of trojanized downloads (April 8 - late April 2026); downstream environment count: No reliable dataRemediated - clean installers released; affected version range documented
TrapDoor CampaignUnknown (crypto/DeFi-targeting actor)34+ malicious packages across 384+ versions on npm, PyPI, CratesIO; earliest activity May 22, 2026Targets developers in crypto, DeFi, Solana, and AI; credential-stealing payload; downstream count: No reliable dataOngoing as of May 31 - active removal effort
Glassworm Botnet (GitHub)Glassworm threat actor300+ GitHub repositories poisoned; malicious extensions on developer marketplaces; account hijacking via stolen credentialsDeveloper credential theft at scale; downstream count: No reliable dataDisrupted May 27, 2026 - CrowdStrike and Google coordinated takedown

Trend assessment: Verizon 2026 DBIR confirms nearly 30% of all data breaches now involve a third-party supplier - double the rate from 2024 (15%). Four confirmed supply chain incidents in a single reporting period is a notable clustering. The Mini Shai-Hulud campaign is technically the most significant: it demonstrates that OIDC-authenticated CI/CD pipelines can produce malicious packages with valid SLSA provenance, fundamentally undermining software supply chain integrity controls that organizations deployed as post-SolarWinds mitigations. The DAEMON Tools compromise is the most enterprise-relevant for traditional environments: a legitimately signed installer from the official vendor website bypasses all reputation-based defenses. TeamPCP's confirmed link to the CipherForce ransomware group means the CI/CD attack vector may soon feed ransomware deployments directly - ANALYST INFERENCE, medium confidence. CONFIRMATION SIGNAL: CipherForce DLS listing of a victim whose forensics identify initial access via CI/CD pipeline compromise.

SECTION 10 - ECOSYSTEM CONTROL NODE ANALYSIS

10.1 Top Control Nodes

A 'control node' is any entity whose disruption causes measurable cascading effects on other ecosystem participants.

RankNodeTypeEst. Ecosystem ReachDependenciesSingle Point of Failure?Disruption Difficulty
1Qilin RaaSRaaS Platform~21% of Q1 2026 victims (445 YTD); 103/month; 26 confirmed healthcare victims (17% of all healthcare DLS listings); formal BreachForums partnership - CONFIRMEDExploit.in/XSS.is forums; BPH infrastructure; affiliate network; cryptocurrency cashoutPartial - distributed affiliate model; no single physical node; operator identity not publicHigh - Russian/CIS nexus suspected; no jurisdiction with enforcement authority has acted
2The Gentlemen RaaSRaaS Platform~15% of 2026 YTD victims (~332); #2 operator; admin identity now partially exposed - THRESHOLD MET4VPS (compromised); zeta88/hastalamuerte identity now partially known; Selectel-adjacent infrastructurePartial - 9 operators identified; admin identity and TOX ID now publicMedium-Low - immediate enforcement window open; see Section 11 leverage item I-1
3DarkForumsForum / IAB MarketANALYST INFERENCE, medium confidence: 30-40% of premium IAB listings now flow through DarkForums (Rapid7 H2 2025: 221 threads, highest average base prices); grew 600% during BreachForums collapseServer infrastructure; admin identity; cryptocurrency payment rails; user reputation systemPartial - admin arrest could displace listings; marketplaces reconstitute in 4-8 weeksHigh - English-language; potentially reachable by Western LE if hosted in cooperative jurisdiction
4Stablecoin Cashout Infrastructure (USDT/A7A5)Crypto Laundry$93B in sanctioned-entity flows (2025, TRM Labs); A7A5 token: $72B; 95% of illicit inflows to sanctioned entities transit stablecoins; entire ransomware payment collection chain depends on USDT accessTether Limited (USDT issuer); correspondent banking relationships; stablecoin issuance infrastructurePartial - Tether is the realistic chokepoint; alternatives exist but immature at required scale for Russian opsExtreme - requires regulatory action vs. Tether or stablecoin issuers; see Section 11 leverage item F-3
5LummaC2 MaaSStealer ServiceANALYST INFERENCE, high confidence: #1 infostealer by distribution volume; 394,000+ Windows PCs infected in 60 days pre-May 2025 takedown (Microsoft); drives majority of credential-to-IAB pipelineSelectel hosting (post-Cloudflare pivot); Telegram/forum marketing; CastleLoader delivery networkPartial - demonstrated resilience to takedown; reconstituted within weeks of May 2025 Microsoft/DOJ actionHigh - Russian origin; Selectel pivot to RU jurisdiction; see Section 11 leverage item F-2
6IAB Pipeline (Stealer Log Markets)IAB MarketANALYST INFERENCE, medium confidence: 54% of ransomware victims had credentials in stealer markets before attack; $14M+ on-chain IAB payments (Chainalysis 2025); 18.7M logs Jan-May 2026 (Flare)Distributed Telegram channels; dark web marketplaces; infostealer malware familiesNo - hundreds of channels; no single adminExtreme - decentralized; no single LE enforcement mechanism; disruption requires sustained coordinated pressure
7LockBit 5.0RaaS Platform~8% Q1 2026 (163 victims); demonstrated high reconstitution capacity (Feb 2024 disruption → LockBit 5.0 in 8 months)Affiliate network; cross-platform tooling; operator 'LockBitSupp' (Dmitry Khoroshev, identified 2024)Partial - prior disruption reconstituted; brand demonstrated extreme resilienceHigh - distributed affiliates; primary operator in Russia, beyond arrest reach

10.2 Cascade Failure Analysis

Node: The Gentlemen RaaS (Rank 2) - HIGHEST IMMEDIATE LEVERAGE

Node: Stablecoin Cashout Infrastructure (Rank 4) - HIGHEST STRUCTURAL LEVERAGE

Node: Qilin RaaS (Rank 1) - HIGHEST VOLUME LEVERAGE

10.3 Structural Vulnerability Summary

The single most critical structural weakness in the current ecosystem is the dependence of the entire payment collection chain on stablecoin infrastructure - primarily USDT via the A7A5 token cluster. With 95% of illicit ransomware-related flows using stablecoins ($72B A7A5 alone per TRM Labs 2026), Tether Limited represents an unprecedented concentration of financial chokepoint leverage for law enforcement. The ecosystem is most brittle here because: (1) ransomware groups cannot collect payment without it; (2) Tether operates in a Western-accessible jurisdiction; and (3) existing BSA/AML regulatory frameworks already apply - they are simply not enforced at the wallet-screening level required. Simultaneously, The Gentlemen admin identity disclosure creates a rare narrow-window opportunity to decapitate a top-3 operator with confirmed identity intelligence. These two leverage mechanisms are independent and should be pursued in parallel: one is an immediate 30-day tactical action; the other is a 12-18 month regulatory campaign.

SECTION 11 - STRATEGIC LEVERAGE ASSESSMENT

11.1 Financial Pressure Points

LEVERAGE F-1: The Gentlemen Cryptocurrency Cash-Out Infrastructure

TARGET Tinkoff bank QR code cash-out pathway; OTC physical cash delivery network; exchange chain ('buy desk') infrastructure identified in The Gentlemen's leaked chats.

CONDITION Admin zeta88 confirmed using Tinkoff QR cash-out (400,000 RUB minimum / ~$4,400 per transaction) and OTC delivery. ~800 transactions through buy desks documented. Confirmed in verified source (Check Point Research, May 13, 2026).

THRESHOLD THRESHOLD MET - cash-out methodology documented and publicly reported. Admin knows the data is compromised and may be migrating infrastructure.

ACTION File STR with FinCEN citing Check Point TOX IDs and wallet addresses; initiate OFAC designation review for identified non-custodial wallets (Guarda, Trust Wallet, Exodus infrastructure used by zeta88); provide TOX ID F8E24C7F... to Five Eyes partners for SIGINT/HUMINT correlation; alert Tinkoff compliance team via FinCEN SAR referral mechanism.

WINDOW 30-60 days maximum before admin migrates all financial infrastructure following acknowledgment of the breach.

PRIORITY Critical

LEVERAGE F-2: Selectel OFAC Designation (Lumma C2 Host)

TARGET Selectel (Russian hosting provider) - confirmed new Lumma Stealer C2 infrastructure post-Cloudflare pivot.

CONDITION Lumma confirmed migrated C2 to Selectel post-May 2025 disruption. Selectel is commercially registered with international payment infrastructure.

THRESHOLD THRESHOLD MET - migration confirmed in verified reporting. Each day of inaction allows stealer-to-IAB pipeline to continue at scale.

ACTION Initiate OFAC designation review for Selectel as a facilitating entity under cyber-related executive orders; engage Selectel's upstream tier-1 ISP connectivity providers (Western-accessible) to enforce abuse policies; coordinate with Europol for parallel action.

WINDOW Ongoing; most effective before Lumma migrates to a second alternative provider.

PRIORITY High

LEVERAGE F-3: USDT/Tether Stablecoin Wallet Screening Mandate

TARGET Tether Limited (USDT issuer) and A7A5 token infrastructure - the structural ransomware payment chokepoint.

CONDITION 95% of illicit flows to sanctioned entities in 2025 transited stablecoins; A7A5 token alone: $72 billion in illicit stablecoin flows (TRM Labs 2026); USDT is the confirmed cashout mechanism for major Russian-aligned operators.

THRESHOLD THRESHOLD MET - $72B A7A5 flow and $93B total sanctioned-entity stablecoin exposure already exceeds any reasonable action threshold.

ACTION OFAC shall designate the A7A5 token as blocked property under 31 CFR Part 510 (CAATSA Russia sanctions); Treasury shall issue regulatory guidance requiring Tether to implement wallet-level SDN list screening before USDT issuance/redemption under penalty of USD correspondent banking access loss; FinCEN shall issue Geographic Targeting Order covering Tether transactions above $3,000 involving Russia-linked exchanges.

WINDOW 12-18 months before alternative payment rails (CBDCs, privacy coins) become operationally viable for Russian ransomware operators at scale; acting now imposes maximum friction while alternatives are immature.

PRIORITY Critical - highest-impact available financial leverage in the ecosystem

11.2 Infrastructure Pressure Points

LEVERAGE I-1: The Gentlemen Admin Identity (zeta88 / hastalamuerte)

TARGET RaaS administrator partially deanonymized via May 4 backend breach; TOX ID: F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E; shadow file entry 'zeta88' confirmed; 4VPS hosting link.

CONDITION Admin identity exposed. Admin acknowledged breach publicly and is actively rebuilding operational security. Every week without action allows migration and identity hardening.

THRESHOLD THRESHOLD MET - identity exposure already occurred May 4. Enforcement window is narrowing.

ACTION Transmit TOX ID and shadow file hashes to Five Eyes partners for HUMINT and SIGINT correlation; issue international arrest warrant via Interpol Red Notice; coordinate with Eastern European partner services for physical location determination based on communication metadata; request 4VPS hosting provider records via MLAT.

WINDOW 30-60 days maximum before full operational security rebuild. Admin announced infrastructure overhaul on May 4 itself.

PRIORITY Critical

LEVERAGE I-2: Post-Stark Industries BPH Migration Window

TARGET Stark Industries / WorkTitans BV customers migrating to alternative BPH providers within days of May seizure.

CONDITION FIOD seized 800 servers; First VPN 506-user list in LE possession. Historical pattern: BPH customers migrate within 1-7 days. Customer lists from Stark Industries servers may identify overlapping actors.

THRESHOLD Migration window is OPEN NOW - most acute in first 14 days post-seizure (~by June 10, 2026).

ACTION Cross-reference Stark Industries server logs (FIOD custody) against First VPN 506-user list and known ransomware group infrastructure IOCs; identify migration destinations via BGP monitoring of Russian-adjacent ASNs receiving new traffic from previously Stark-hosted IPs; transmit identified new hosting providers to Europol for secondary action.

WINDOW 14 days - by approximately June 10, 2026.

PRIORITY High

LEVERAGE I-3: Operation Saffron Intelligence Package Follow-On (90-Day Window)

TARGET Active ransomware operators among the 506 identified First VPN users; 83 intelligence packages in partner country hands.

CONDITION Intelligence packages shared with 27 countries. First VPN operator logs document criminal traffic from 506 users. Historical VPN service reconstitution: 60-90 days.

THRESHOLD Threshold for action: identification of 3+ operators correlating to active ransomware victim DLS listings within the 83 intelligence packages.

ACTION Europol EC3 shall coordinate cross-referencing of 83 intelligence packages against active ransomware case files within 90 days of Saffron takedown; any operators identified in arrestable jurisdictions shall be subject to immediate MLAT requests; identified infrastructure providers shall be referred to ISPs for network suspension.

WINDOW 90 days from Operation Saffron (by ~August 18, 2026) before suspects migrate to successor VPN infrastructure and re-anonymize.

PRIORITY Critical

11.3 Jurisdictional Pressure Points

LEVERAGE J-1: Russian Deliberate Non-Enforcement - State-Facilitation Argument with SORM Evidentiary Basis

TARGET Russian federal government as the enabling actor for RU-nexus ransomware operators (Qilin, LockBit, The Gentlemen, Akira); diplomatic, financial, and legal pressure mechanisms.

CONDITION Three confirmed evidentiary pillars now support the deliberate non-enforcement argument as a policy position rather than a capability gap: (1) SORM architecture - Russian law requires all ISPs to install FSB-controlled intercept hardware, giving the FSB real-time visibility into all Russian-IP traffic; the FSB can observe ransomware operator communications, infrastructure, and financial flows in real time. (2) Karakurt/Zolotarjovs DOJ documentation (May 6, 2026) - gang used Russian government database access and paid military draft bribes; confirms active state-criminal relationship, not passive tolerance. (3) SORM + deliberate non-enforcement: Russian authorities have categorical technical capability to identify and disrupt domestic ransomware operators and have chosen not to. This is a policy posture, not a surveillance gap.

THRESHOLD THRESHOLD MET - all three evidentiary pillars are established. The April 2026 VPN crackdown and associated banking system disruption (reported; see Section 12) provides the sharpest available illustration: Russia accepted macroeconomic self-harm from VPN-dependent banking failures to enforce internet control objectives, while simultaneously operating a permissive environment for ransomware infrastructure. This is not an oversight - it is a documented policy trade-off.

ACTION DOJ/NSD shall formally designate deliberate non-enforcement of SORM-visible ransomware operators as a state-facilitation finding in indictments against Qilin and LockBit operators; State Department shall incorporate SORM non-enforcement evidence into bilateral diplomatic communications with Russian counterparts; Five Eyes intelligence community shall produce a coordinated public assessment attributing RU-nexus ransomware permissiveness to confirmed FSB technical capability combined with deliberate non-action - shifting the diplomatic framing from 'Russia can't' to 'Russia won't.'

WINDOW Ongoing; SORM evidence base is standing. April 2026 VPN crackdown banking failure is a fresh illustration that strengthens the policy-choice argument while events remain in public memory.

PRIORITY High

11.4 Coming Month Focus - Top 3 Priority Actions (June 2026)

1. [CRITICAL] Act on The Gentlemen admin identity disclosure - 30-day window.

Expected outcome: Arrest or flight-forcing of zeta88/hastalamuerte; disruption of the ~332-victim YTD pipeline; intelligence windfall from full 16.22 GB Rocket DB; potential dismantlement of 8 confirmed affiliate operations.

2. [CRITICAL] OFAC: initiate A7A5 token and Tether wallet-screening regulatory action.

Expected outcome: $72B+ annual illicit flow disruption if sustained; forces Russian ransomware operators into less liquid cryptocurrency alternatives, extending cashout timelines from days to weeks and creating new traceability opportunities.

3. [HIGH] Cross-reference Stark Industries server logs against First VPN 506-user list before June 10.

Expected outcome: Identification of Russian-nexus actors using both services simultaneously; 10-50+ actionable investigative leads; potential identification of previously unknown ransomware group infrastructure.

SECTION 12 - UNCONFIRMED SIGNALS & HORIZON INDICATORS

SECTION 13 - ANALYTIC CAVEATS & COLLECTION GAPS

13.1 Sources Blocked or Inaccessible During Collection

The following sources were unavailable or returned no substantive content during collection and are excluded from the citation pool. Information attributed to these sources in this report was corroborated via other verified sources or credited as search-result-only attribution:

13.2 Data Unavailable or Unreliable This Cycle

13.3 Known Biases in Victim Count Data

13.4 Competing Explanations for Major Observed Trends

SOURCES

Verified sources (fetched and confirmed): starred (*). All others contributed via search-result-level attribution per Section 13.1.

Ransomware Tracking Platforms

Vendor Threat Intelligence

Government & Law Enforcement

Cybersecurity News

Financial Intelligence