Confidence labels are applied throughout: CONFIRMED, CREDIBLE REPORTING, and ANALYST INFERENCE. Every URL in the Sources section was retrieved by direct fetch during collection; sources that failed retrieval were dropped from the citation pool and are recorded in Section 13. Figures carried forward from earlier periods are dated explicitly where July-specific data was unavailable. To see which ecosystem nodes moved during this reporting period, open the map's delta view for July 2026.
SECTION 1 - EXECUTIVE SUMMARY
Five items, ranked by ecosystem-level strategic impact. Each carries at least one supporting metric and a confidence label.
1. On 13 July the United States, European Union and United Kingdom announced simultaneous sanctions described by Chainalysis as one of the largest cyber enforcement actions to date, with the EU designating 9 individuals and 4 entities, the UK 24 individuals and entities, and OFAC 3 targets. The headline designation is Vitaly Nikolayevich Kovalev, alias Stern, senior administrator of the Trickbot and Conti syndicate, whose wallets received more than $300 million in ransom payments as his personal cut alone, likely making him the single most prolific ransomware operator ever identified. This is the first time any sanctioning body has publicly tied the Stern moniker to Kovalev by name, and it brings the total Trickbot members sanctioned to 19. CONFIRMED.
2. The same package confirms a doctrinal shift from operator-targeting to enabler-targeting, executed across six layers in nineteen days: bulletproof hosting (EU designated Media Land LLC and owner Alexander Volosovik on 13 July, the DOJ unsealed his indictment on 14 July over $62 million in losses), malware-as-a-service (EU designated LummaC2 developers Voronin and Gordienko; the UK cited at least 2,100 UK Lumma victims in six months per the NCA), VPN concealment (OFAC designated 1VPNS), cryptor services (OFAC designated Silayev), residential proxy anonymization (NetNut/Popa, at least 2 million devices, disrupted 2 to 3 July), and phishing-as-a-service (Kratos, 1,800-plus subscribers and roughly 15,000 campaigns per month, taken down 20 July with an arrest). CONFIRMED.
3. The stablecoin chokepoint was demonstrated at scale on 14 to 15 July, when OFAC added four Central Bank of Iran crypto addresses that had received $165 million in stablecoins and Tether froze $131 million of the balances immediately, bringing total Tether freezes against OFAC-identified CBI addresses to nearly $475 million. This is the strongest evidence to date that issuer-level freezing converts a designation into immediate asset denial, unlike infrastructure seizure. CONFIRMED.
4. Coveware by Veeam data published 30 July shows the ransomware payment model bifurcating: the average payment rose 176 percent quarter over quarter to $1.88 million while the median fell to $150,000 and the overall payment rate reached a record low, with the exfiltration-only payment rate at 15 percent. The ecosystem is extracting far more from far fewer payers, and encryption-free extortion has demonstrated a monetization ceiling for the first time. CONFIRMED.
5. Sysdig documented JADEPUFFER on 1 July, the first known end-to-end agentic ransomware operation, in which a large language model autonomously exploited Langflow via CVE-2025-3248, harvested credentials, moved laterally, encrypted 1,342 Nacos configuration items and dropped production databases across more than 600 distinct payloads, correcting a failed login to a working fix in 31 seconds without human intervention. CONFIRMED.
SECTION 2 - RANSOMWARE ECOSYSTEM: MONTHLY STATISTICS
No finalized July 2026 monthly analytical report had been published as of 1 August. The figures below are drawn from two independent live trackers with different inclusion rules, and are labelled accordingly.
- Total victims disclosed (July 2026): approximately 809 leak-site posts, derived from RansomLook's daily series of 731 posts across 4 to 31 July (28 days at 26.1 posts per day) extrapolated across the three days not displayed on the retrieved view. ANALYST INFERENCE, medium confidence.
- Cross-check: ransomware.live recorded 5,419 victims year to date through 26 July against 4,780 through 1 July in the prior reporting cycle, implying 639 victims across 26 days, or roughly 762 for the full month at the same daily rate. The two trackers converge on a July range of roughly 760 to 810. CREDIBLE REPORTING.
- Active group count: 115 active groups in 2026 to date across 132 countries (ransomware.live, data current to 26 July), up from 106 groups and 130 countries at the prior cycle. In the seven days to 1 August, RansomLook counted 34 active groups, down 15.0 percent week over week. CONFIRMED per source.
- New groups identified in July: five. Booba Project (added 6 July, 9 victims), Doommageddon (6 July, 8 victims), Cry0 (6 July, 1 victim), CRPxO (9 July, 6 victims) and D1R (13 July, 3 victims). This brings 2026 new-group debuts to 44. CONFIRMED (ransomware.live).
- Defunct or dormant groups: no reliable July-specific attrition count available. Structural context from Black Kite's report published 24 July: 61 new groups entered the market between April 2025 and March 2026, more than one per week, while the active group count reached 146 by June 2026.
- Estimated ransom volume: no aggregate July figure available. The closest in-window financial measure is Coveware's Q2 2026 dataset published 30 July, showing an average payment of $1.88 million (up 176 percent quarter over quarter) against a median of $150,000. CONFIRMED per source.
- Month-over-month change in total victims: approximately plus 8 to plus 12 percent against the June baseline of roughly 722. ANALYST INFERENCE, low confidence, because the July estimate and the June baseline come from different trackers. The same-methodology signal is stronger: RansomLook's final week of July was up 40.4 percent on the prior week.
Sector Targeting Trend Table
No July-specific sector breakdown was published. The table uses the two most recent finalized comparative datasets: Comparitech's H1 2026 healthcare series (published 7 July, updated 9 July) against H2 2025, and Black Kite's ecosystem-wide sector ranking for April 2025 to March 2026.
| Sector | This Period (n) | Prior Period (n) | % Change | Trend |
|---|---|---|---|---|
| Healthcare (all) | 410 (H1 2026) | 360 (H2 2025) | +13.9% | Increasing |
| Healthcare providers | 247 (H1 2026) | ~239 (derived) | +3.3% | Stable |
| Healthcare businesses | 163 (H1 2026) | ~121 (derived) | +34.7% | Increasing |
| Healthcare manufacturers | No reliable count | No reliable count | +36% | Increasing |
| Healthcare retail / wholesale | No reliable count | No reliable count | +67% | Increasing |
| Manufacturing (ecosystem-wide) | Rank 1, most targeted | No prior data | No reliable data | Stable, dominant |
| Professional / scientific / technical | Rank 2 | No prior data | No reliable data | Stable |
| Construction | Next tier | No prior data | No reliable data | Stable |
| Finance and insurance | Next tier | No prior data | No reliable data | Stable |
| Retail trade | Next tier | No prior data | No reliable data | Stable |
The healthcare sub-sector movement is the most analytically useful figure in the set. Attacks on direct-care providers were nearly flat at plus 3.3 percent while attacks on healthcare businesses, meaning pharmaceutical and device manufacturers, billing providers and health-tech firms, rose 34.7 percent. Within that, retailers such as device retailers and drug wholesalers rose 67 percent. Actors are migrating away from the patient-facing organizations that attract law-enforcement and regulatory attention, and toward the supply chain behind them, which holds comparable data with a lower political cost.
Geographic Targeting Analysis
- United States: 49.3 percent of all observed victims in the Black Kite reporting period, remaining the single most targeted country. In healthcare specifically, the US absorbed 225 of 410 H1 2026 attacks, more than half the global total, though US healthcare provider attacks fell just over 7 percent half over half. CONFIRMED per sources.
- Europe: the four most affected European countries collectively recorded more than 250 additional victims over the reporting period, with several strengthening their global top-10 position. In healthcare, Germany rose 40 percent half over half. CREDIBLE REPORTING.
- Asia: parts of Asia recorded the largest percentage increases of any region. India's healthcare provider attacks rose 700 percent half over half, the single largest national movement in the dataset. Canada rose 83 percent and Australia 33 percent. CONFIRMED per source.
- Geographic breadth is expanding faster than volume: Q2 2026 saw victims in 108 countries against 97 in Q1 2026 and 84 one year earlier, a 29 percent widening of the target aperture in twelve months. CONFIRMED (GuidePoint).
- CIS-exclusion status: resolved this cycle after four cycles as a collection gap. The Cybercrime Directorate of the Russian MVD published weekly detention summaries covering at least 8 detentions between 16 and 23 July and at least 7 between 23 and 30 July, roughly 15 in a fortnight across multiple regions. On 29 July the MVD reported more than 24,000 registered cases of Telegram used for fraud and remote theft since the start of 2026. Separately, the leadership of bulletproof hosting provider Aeza Group, arrested in Russia in April 2025 on organised criminal community charges over hosting the BlackSprut darknet market, remained in pretrial detention as of July 2026. CONFIRMED per source, STATE-ALIGNED (RUSSIA) origin noted.
- The analytic finding is that the safe harbour is selective, not absent. Russia is not failing to police cybercrime. It polices it at a tempo of roughly seven to eight detentions per week and will hold a bulletproof hosting provider's leadership in pretrial detention for fifteen months and counting. What it does not police is ransomware against foreign victims. The variable is victim nationality and domestic political salience, not capability or will. Aeza was prosecuted for hosting a drug market serving Russians, not for hosting ransomware serving no Russians. ANALYST INFERENCE, high confidence, resting on three independent legs: MVD weekly tempo, the Aeza prosecution, and the continued absence of any Russian case against a ransomware operator with foreign victims.
- Structural note on the enabler layer: the 13 July OFAC action designated a Ukrainian administrator (Dmytro Rashevskyi, 1VPNS) and a Belarusian cryptor seller (Yevgeniy Vladimirovich Silayev). The enabler tier servicing Russian-language ransomware operations is not itself exclusively Russian, and that distinction carries direct jurisdictional consequences addressed in Section 11. CONFIRMED (US Treasury).
Leak Site Three-Signal Composite
| Signal | This Month (July) | Prior Period | Trend | Notes |
|---|---|---|---|---|
| Post volume (victims published) | 731 posts, 4 to 31 July; ~809 full-month est. Final week: 240 posts | ~722 (June, prior cycle). Prior week: ~171 (derived) | Increasing, +40.4% week over week | Same-methodology weekly figure is the reliable signal; the monthly comparison is cross-tracker |
| Time-to-publish (avg days, compromise to publication) | No reliable data | No reliable data | Not assessable | Fourth consecutive cycle with this gap. Partial proxy: Anubis listed Fairlife four days after the 16 July SEC disclosure |
| Takedown / relaunch cycle (days dark to successor) | RAMP at 184 days dark as of 1 August; BreachForums with no legitimate version since April 2026 | RAMP ~150 days at prior cycle | Lengthening | RAMP passed the 180-day mark on 28 July with no successor; a suspected administrator publicly declined to rebuild |
Composite interpretation. The three signals are not moving together, and the divergence is the finding. Post volume is rising steeply into month-end while the active operator count is contracting 15 percent in the same window, which means fewer groups are publishing more victims each. Set against Coveware's record-low payment rate and 176 percent jump in average payment, the coherent reading is a volume-and-concentration strategy: publish more victims to sustain pressure across a population where fewer will pay, and price the ones who do far higher. The takedown-to-relaunch signal continues to diverge from the other two. Forum-layer disruption is imposing durable cost, with RAMP now past 184 days and an administrator publicly declining reconstitution, while the RaaS layer it once served is posting record volume. Enforcement is succeeding against the coordination layer and failing to slow the production layer. ANALYST INFERENCE, medium confidence.
SECTION 3 - THREAT ACTOR LANDSCAPE
Russia and CIS-linked groups prioritized. Where July-only victim counts are unavailable, the most recent finalized quarterly or monthly figure is used and dated explicitly.
| Group | Victims | Key Development (July) | Threat Shift | CIS-Exclusion |
|---|---|---|---|---|
| The Gentlemen | 94 (June); 238 (Q2); 44 posts and 18.3% share in final week of July | Took the number one position from Qilin for the first time in 2026; leads the leak-site feed at month-end; 31 healthcare-provider and 13 healthcare-business claims in H1 | Increasing | Assessed |
| Qilin | 71 (June, third place); 301 (Q2, 14% of all Q2 victims); 21 posts in final week of July | Fell 44.7% week over week at month-end after five consecutive quarters as most active operator; still leads healthcare-provider claims at 41 in H1 | Decreasing | Assessed |
| DragonForce | 145 (Q2, third) | Leads healthcare-business claims at 14 in H1; posting continued through 31 July | Stable | Assessed |
| Akira | Top five (Q2) | Pairs encryption with data theft rather than substituting one for the other; edge-device VPN exploitation remains the defining vector | Stable | Assessed |
| LockBit5 | Top five (Q2); 17 healthcare-provider claims (H1) | Persists as a top-five operator despite prior disruption of the LockBit brand | Stable | Assessed |
| Anubis | No reliable July count | Listed Coca-Cola subsidiary Fairlife on 20 July claiming 1 TB, four days after the parent filed an 8-K; US production temporarily suspended. On-chain payments to 1VPNS traced in Dec 2025 and Mar 2026 | Increasing | Unknown |
| ShinyHunters (UNC6240) | No reliable July count | Listed Abbott Laboratories mid-July after June vishing against employees compromised a corporate Entra SSO account; leak deadline moved from 18 to 21 July. Extortion-only | Increasing | Unknown |
| Kairos | 2 confirmed healthcare-business attacks (H1) | Reported 3 July to have received roughly $1 million (9.44 BTC) from a US county government; never encrypted, exfiltrated over 2 TB including SSNs and fingerprint files; access via password guessing where MFA was absent | Increasing | Unknown |
| Storm-2603 (Warlock) | No reliable count | Continues SharePoint exploitation; a Microsoft investigation found the actor co-resident with a second unrelated intruder in the same network and confirmed lateral movement into a second organization | Stable | Unknown |
| Deadlock | 86 cumulative since 15 June debut; last victim 25 July | Fastest-scaling 2026 debut on the tracker, concentrated in construction, engineering and professional services | Increasing | Unknown |
| Sinobi | No reliable July count | On-chain payment of $58 to 1VPNS traced to February 2026, establishing a documented operator-to-enabler payment link | Stable | Unknown |
Three new entrants appeared in the final week of July and immediately posted at scale: Global Secret Group (24 posts), Booba Team (16 posts) and Exfilsquad (14 posts). Combined, these three accounted for 54 of the week's 240 posts, or 22.5 percent, on their debut. CONFIRMED (RansomLook). This is the pattern Black Kite describes as new groups launching high-volume campaigns immediately on market entry rather than building gradually.
Legacy and Structurally Significant Actors Named in the 13 July Designations
These actors are not among July's highest-volume operators but were designated during the reporting period and carry structural significance for attribution, financial tracing and the CIS safe-harbour question.
| Actor | Attributed Proceeds | Development (13 July 2026) | CIS-Exclusion |
|---|---|---|---|
| Vitaly Nikolayevich Kovalev, alias Stern, Bentley, Bergen, Alex Konor, Benny, Ben | Wallets received more than $300 million in ransom payments, representing his personal cut only; Trickbot's total haul is substantially larger | EU-designated as senior figure of the Trickbot Group including Ryuk and Conti and their offshoots. First sanctioning body to attach the Stern moniker to Kovalev by name. Previously designated by OFAC and OFSI on 9 February 2023, and identified as Kovalev by Germany's BKA in 2025. Chainalysis Reactor shows him transacting with Ryuk, Conti, Diavol, Karakurt, Royal, 3am, Quantum and Bitpaymer. The Conti Leaks position him as a CEO-like figure with discretion over budget, procurement, hiring and attack planning. Total Trickbot members sanctioned now stands at 19 | Confirmed Russian national |
| Maksim Evgenevich Voronin and Maksim Aleksandrovich Gordienko | No reliable data | EU-designated as LummaC2 infostealer developers. Their malware-as-a-service platform was among the most used infostealer tools worldwide in 2024 and 2025 and reconstituted fully after the May 2025 takedown. UK measures cite Russian use of Lumma-harvested credentials for cyber espionage, with the NCA estimating at least 2,100 UK victims over six months | Assessed |
| Alexander Alexandrovich Volosovik (Media Land LLC) | $62 million in charged US losses | Subject to three separate actions inside eight months: OFAC designation November 2025, EU designation 13 July 2026, DOJ indictment unsealed 14 to 15 July 2026. Media Land has facilitated ransomware operations including LockBit, EvilCorp and BlackBasta since 2016 | Confirmed Russian, St. Petersburg |
| Evgeniy Viktorovich Bashev (GRU Unit 29155) | Not quantified | EU-designated. Facilitated infrastructure and payments and coordinated the GRU's collaboration with external hacker networks, including the WhisperGate campaign against Ukrainian critical infrastructure, which issued a cryptocurrency extortion demand | Confirmed Russian state |
| Cyber Army of Russia Reborn (CARR) and Z-Pentest | Not quantified | Both EU-designated. Z-Pentest has targeted energy and water critical infrastructure including a Danish water utility in December 2024. CARR was previously OFAC-designated in 2024 | Confirmed pro-Russia |
| Angelo Martino (BlackCat / ALPHV conspirator, US) | One victim paid approximately $1.2 million in Bitcoin; $10 million in assets seized | Sentenced 10 July to 70 months. A serving ransomware negotiator at a US incident response firm who covertly passed client insurance limits and negotiation strategy to BlackCat across five victim cases from April 2023 while being paid by the operators. Co-conspirators Ryan Goldberg and Kevin Martin pleaded guilty in January 2026 | Not applicable, US national |
Analytic significance. Two findings follow from this set. First, the Volosovik case establishes that layered designation is now operationally routine: an OFAC designation, an EU designation and a US indictment landed on the same individual and entity within eight months, and the EU and DOJ actions fell within 48 hours of each other. Second, the Martino sentencing is the only July action reaching inside the victim-response industry, and it documents a failure mode the ecosystem has not previously been shown to exploit at this level: the negotiator advising the victim was selling the victim's reserve price to the attacker. This bears directly on the payment-layer leverage described in Section 11. CONFIRMED.
Data Extortion Trend
- Current share of encryption-free extortion: no single July percentage is available. The strongest in-window figure is Coveware's Q2 2026 exfiltration-only payment rate of 15 percent, published 30 July, described as a historically low level. CONFIRMED per source.
- Named extortion-only actors active in July: ShinyHunters (Abbott, Medtronic), Kairos (US county government), and World Leaks carried forward from the prior cycle. CREDIBLE REPORTING.
- Month-over-month change: no reliable data. Longer-baseline context: Unit 42 recorded encryption use in extortion cases falling to 78 percent in 2025 from levels at or above 90 percent across 2021 to 2024, and Arctic Wolf recorded an elevenfold rise in data-only extortion between November 2024 and November 2025. CREDIBLE REPORTING.
- Counter-signal worth flagging: Black Kite's April 2025 to March 2026 dataset finds encryption remained the primary pressure method across the period, with Qilin and Akira pairing encryption and data theft rather than abandoning encryption. The encryption-free model is growing as a share of incidents but has not displaced encryption, and the 15 percent payment rate suggests why. CREDIBLE REPORTING.
Analytic judgement. The 15 percent exfiltration-only payment rate is the first hard quantitative evidence in this reporting series that encryption-free extortion carries a structural monetization penalty. Data theft alone gives the victim a recovery path that does not require the attacker, so the only leverage is reputational, and reputational leverage converts to payment less reliably than operational paralysis. If Q3 confirms the figure, expect volume-oriented groups to partially revert to encryption while the extortion-only model consolidates among actors targeting data-sensitive verticals with regulatory exposure. ANALYST INFERENCE, medium confidence.
SECTION 4 - INITIAL ACCESS AND TTP EVOLUTION
No net-new July initial-access ranking with published percentages was retrieved. The ranking below orders vectors by the volume of confirmed July incident reporting attached to each, and states the supporting metric for every position.
1. Paste-and-run social engineering (ClickFix class). Microsoft's Defender Experts team observed ACR Stealer activity climbing across customer environments from late April to mid-June and published two full delivery chains on 16 July, both opening with a user pasting a command into the Run dialog. Red Canary's April telemetry placed ClearFake, the web-inject cluster feeding ACR Stealer since at least March 2025, at number one on its most-prevalent-threat list for the first time, with ACR Stealer entering the top ten at a tie for sixth. Microsoft published no victim count, no affected-customer figure and no baseline for the increase it reported. CREDIBLE REPORTING with an explicit quantification gap.
2. Edge and management-plane exploitation. Six vulnerabilities were added to the CISA KEV catalog during July across ColdFusion, SharePoint, Check Point management servers, Langflow and two Joomla page builders. CVE-2026-16232, an unauthenticated authentication bypass against Check Point Security Management and Multi-Domain Security Management, was confirmed exploited with a handful of customers affected and notified; a federal remediation deadline of 25 July applied. This vector is distinguished by target selection: the compromised asset is the system that pushes policy to firewalls, not a firewall. CONFIRMED.
3. Valid accounts obtained through vishing and help-desk manipulation. ShinyHunters reached Abbott Laboratories through a June voice-phishing campaign against employees that yielded a corporate Microsoft Entra single sign-on account tied to the Cancer Diagnostics business. Microsoft's 13 July research maps a year of the same actor abusing trusted OAuth relationships and long-lived application tokens across Salesforce environments in retail, education and manufacturing, exploiting the trust relationship rather than the platform. CREDIBLE REPORTING.
4. Credentials purchased from initial access brokers. Chainalysis found that IAB on-chain inflow spikes precede increases in both global ransomware payments and US victim leak-site posts by roughly 30 days, making IAB purchasing a leading indicator rather than a coincident one. IABs received at least $14 million on-chain in 2025 against approximately $820 million in ransomware payments, a return ratio near 58 to 1. CONFIRMED per source.
5. Unauthenticated exploitation of AI orchestration infrastructure. Sysdig observed the first active exploitation of CVE-2026-55255 in Langflow on 25 June, and JADEPUFFER's initial access on the same platform used CVE-2025-3248. These hosts are attractive because they routinely hold LLM provider API keys and cloud credentials in their environment and are frequently stood up without network controls. CONFIRMED.
Significant TTP Developments
- Adaptive exploitation at machine speed. JADEPUFFER's agent diagnosed a failed login caused by a subprocess PATH issue, deleted the broken account, rebuilt the credential hash through a direct import and reinserted it, all in 31 seconds across a 15-line coordinated payload. Sysdig's assessment is that no human operator reads an error, identifies that root cause, drafts a corrective script and submits it in that window. CONFIRMED.
- Payload concealment in image pixels. The fileless ACR Stealer chain retrieves a JPEG from a public image host with the payload embedded in the pixels, carves it out, decrypts, decompresses and executes it reflectively in memory, then reads Chrome and Edge Login Data and Web Data databases and invokes DPAPI to decrypt passwords, cookies and tokens. CONFIRMED.
- EtherHiding. In a subset of ACR Stealer intrusions, a second Python loader queries public blockchain RPC endpoints and Web3 node infrastructure to retrieve a payload or C2 address from a public ledger. There is no attacker-controlled resolver left to seize, which removes the standard takedown lever. CONFIRMED.
- Same-day exploitation of maximum-severity flaws. KEVIntel researchers reported exploitation of CVE-2026-48282 in Adobe ColdFusion beginning less than two hours after details became public, from 103.207.14[.]220. For Page Builder CK, a live web shell was flagged on a production Joomla site within hours of the 27 June fix. CONFIRMED.
- Microsoft's remediation guidance for ACR Stealer instructs victims to revoke tokens rather than only rotate passwords, reflecting that session tokens, not credentials, are the operationally valuable artifact. CONFIRMED.
IAB Market Indicators Table
No July-specific IAB market telemetry was retrieved. Figures are from Chainalysis and Darkweb IQ data current to Q1 2026 and are dated explicitly as the best available baseline.
| Indicator | This Month (July 2026) | Prior Period | Trend |
|---|---|---|---|
| Volume of corporate access listings | No reliable data | 675 privately offered accesses, Jan 2026 (+4% YoY) | Flat to slightly increasing |
| Median access price | No reliable data | Average access price $439 (Q1 2026) vs $1,427 (Q1 2023) | Decreasing, -69% over three years |
| Premium listing ceiling | No reliable data | No published ceiling; validated high-privilege enterprise access still commands premium pricing | Bifurcating |
| Most-targeted sectors (top 3) | No reliable data | Ecosystem-wide victim sectors: manufacturing, professional services, construction | Stable |
| Dominant access type | No reliable data | VPN and RDP credentials named as Qilin's most frequent vector; Akira centres on SSL VPN without MFA | Stable, VPN-led |
| Notable marketplace events | RAMP not reconstituted at 184 days; no legitimate BreachForums since April 2026; migration concentrated on DarkForums and private Telegram | RAMP seized 28 Jan 2026 | Consolidating into fewer venues |
The price collapse is the analytically significant movement. Darkweb IQ attributes the fall from $1,427 to $439 to industrialized access pipelines, AI-assisted tooling and infostealer-log proliferation producing an oversupply of cheap but operationally constrained inventory. The market is bifurcated rather than uniformly cheap: validated domain-level access still commands premium pricing. For enforcement, the implication is that price pressure at the low end is not a sign of ecosystem stress, it is a sign of successful automation upstream in the stealer layer.
SECTION 5 - MALWARE AND STEALER ECOSYSTEM
Families ranked by the volume and specificity of July reporting attached to each.
ACR Stealer (Amatera)
- Market position: entered Red Canary's top-ten most-prevalent threat list at a tie for sixth on April telemetry. Microsoft observed activity climbing across customer environments from late April to mid-June. No victim count, affected-customer figure or increase baseline was published. CREDIBLE REPORTING with explicit gap.
- Pricing and model: malware-as-a-service, priced from $199 per month to $1,499 per year following the ACR to Amatera rebrand. CREDIBLE REPORTING (Proofpoint, cited secondarily).
- Distribution in July: two documented chains, both opening with ClickFix paste-and-run. One mounts a WebDAV share and executes a DLL via rundll32 with the console suppressed through conhost headless; the other runs almost entirely in memory via mshta, an embedded VBScript loader and PowerShell. CONFIRMED.
- Collection targets: saved browser passwords, live session tokens, PDFs from Desktop and Downloads, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. Persistence via a hidden scheduled task posing as a software update, with timestomping from notepad.exe and PowerShell history clearing. CONFIRMED.
- Disruption status: none. Neither chain exploits a vulnerability, so patching does not remove the path. Microsoft shipped three Defender XDR hunting queries and 16 campaign domains. CONFIRMED.
StealC, Amadey and SocGholish
- Disruption status: infrastructure actioned in the Operation Endgame phase of 15 to 24 June, with 326 servers and 142 domains taken down, approximately 27 million stolen credentials recovered from over 385,000 compromised systems, and between EUR 41 million and $46 million in criminal cryptocurrency identified and frozen depending on the reporting figure used. CONFIRMED.
- Reconstitution at 30 to 45 days: no confirmed C2 re-emergence was identified in July collection. This is a negative finding from a limited collection set, not a positive assessment of durable denial. ANALYST INFERENCE, low confidence.
LummaC2
- Assessed to lead 2026 distribution alongside StealC and Vidar per AhnLab trend data current to February 2026. Fully reconstituted following its May 2025 takedown, which disrupted over 2,300 domains. No verified July infection-volume figure was obtained. CREDIBLE REPORTING.
NetNut / Popa (residential proxy)
- Scale: Google Threat Intelligence Group estimates at least 2 million compromised devices globally, including smart TVs and streaming boxes, powered by trojanized applications and botnets such as Badbox 2.0 that package proxy plugins. CONFIRMED.
- Criminal usage intensity: in one week in June, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, spanning both cybercriminal and espionage groups, for password-spray attacks, access to their own infrastructure, and reaching victim environments. CONFIRMED.
- Disruption status: disrupted 2 to 3 July. Google disabled the accounts and services used for command and control, flagged the SDK in Play Protect, and shared SDK and backend detail with platform providers and law enforcement. The FBI and IRS seized netnut.com, proxyjet.io and divinetworks.com. CONFIRMED.
Kratos / Sneaky2FA (phishing-as-a-service)
- Scale before takedown: more than 1,800 criminal subscribers running an estimated 15,000 phishing campaigns per month, each capable of reaching thousands of recipients, with victims across more than 30 countries running into the hundreds of thousands since late 2024. The group earned more than EUR 300,000 (approximately $342,000) since 2024. CONFIRMED.
- Capability: adversary-in-the-middle relay of live Microsoft 365 authentication sessions, capturing credentials and session tokens in transit, which defeats MFA rather than merely harvesting passwords. Browser-in-the-browser login windows were added in November 2025. CONFIRMED.
- Disruption status: taken fully offline 20 July in Operation Olympus Blade, with more than 200 servers shut down and the developer and technical administrator arrested in Indonesia. CONFIRMED.
Infostealer-to-IAB Pipeline
Chainalysis identifies infostealer-log proliferation as a primary driver of the collapse in average corporate access pricing from $1,427 in Q1 2023 to $439 in Q1 2026, alongside industrialized access pipelines and AI-assisted tooling. The pipeline's timing characteristic is now measurable at the market level rather than the individual-log level: spikes in IAB on-chain inflows precede increases in global ransomware payments almost immediately, and increases in US victim leak-site posts after roughly a ten-day lull, with the full effect visible at 30 days. This makes IAB payment volume the single most useful leading indicator available to defenders and enforcement planners. CONFIRMED per source. Median time from individual infection to dark-web listing: no reliable data, a persistent gap across reporting cycles.
SECTION 6 - FINANCIAL AND INFRASTRUCTURE SIGNALS
Sanctions and Enforcement Actions
The 13 July tri-lateral package is the defining action of the reporting period and is broken out by designating authority below.
| Authority / Date | Target | Stated Rationale | Estimated Financial Exposure | Assessed Impact |
|---|---|---|---|---|
| European Union, 13 July 2026 | 9 individuals and 4 entities. Entities: Media Land LLC, ML.Cloud, Z-Pentest, LLC Impuls. Individuals: Vitaly Nikolayevich Kovalev (Stern); Alexander Volosovik; LummaC2 developers Maksim Voronin and Maksim Gordienko; Yuliya Pankratova and Denis Degtyarenko (CARR); Evgeniy Bashev (GRU Unit 29155); Ivan Kasyanenko (GRU SSD) | Denouncing Russia's malicious cyber ecosystem targeting the EU, member states and international partners. Campaigns attributed to the FSB 16th Centre, which directs threat groups including Turla and has targeted government networks and critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland | Stern wallets received over $300 million as a personal cut; Media Land tied to LockBit, EvilCorp and BlackBasta since 2016; Poland attack of 29 Dec 2025 hit 30-plus wind and solar farms, a combined heat and power plant and a manufacturer with a previously unseen OT wiper | High |
| United Kingdom FCDO, 13 July 2026 | 24 designations. GRU officers Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko; Unit 29155-linked Aleksandr Shepelev, Roman Puntus, Dmitriy Voronov and Sultan Omarov; OOO Impuls and Evgeniy Bashev; CARR figures Yuliya Pankratova and Denis Degtyarenko; Lumma-linked Maksim Voronin, Maksim Gordienko and Marat Zhurkin; and ten Rybar LLC-linked individuals | Coordinated malicious cyber ecosystem; Russian use of Lumma Stealer credentials to support cyber espionage. The Rybar tranche targets disinformation rather than cybercrime, making this a combined cyber and state-influence package rather than a purely criminal one | NCA estimates at least 2,100 UK Lumma victims over the preceding six months | Medium-High |
| OFAC, 13 July 2026 | First VPN Service (1VPNS); Dmytro Rashevskyi, Ukrainian administrator; Yevgeniy Vladimirovich Silayev, Belarusian cryptor seller | Enabling ransomware actors and other cybercriminals. 1VPNS advertised on criminal forums since 2014 with a no-logs policy and refusal to cooperate with law enforcement; Silayev sold cryptors disguising ransomware as safe software | Treasury states the groups using these services caused billions of dollars in losses. TRM traced Anubis payments (Dec 2025, Mar 2026), Qilin $120 (Jan 2026) and Sinobi $58 (Feb 2026). OFAC listed wallet addresses across Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin and Solana | Medium-High |
| OFAC, 14 to 15 July 2026 | Central Bank of Iran designation updated with four additional cryptocurrency addresses | Use of cryptocurrency to sidestep sanctions, fund the regime and funnel assets to regional partners including Hezbollah | The four wallets received $165 million in stablecoins; $131 million frozen immediately by Tether. Cumulative Tether freezes against OFAC-identified CBI addresses now approach $475 million | High |
| OFAC, 20 July 2026 | Russia-related designations updates | Not enumerated on the retrieved recent-actions index | No reliable data | No reliable data |
| DOJ, indictment unsealed 14 to 15 July 2026 | Alexander Volosovik (43), Kirill Zatolokin (34), Yulia Pankova (29); Media Land LLC and ML.Cloud LLC, St. Petersburg | Conspiracy to commit and aid and abet computer fraud, wire fraud conspiracy, wire fraud, money laundering conspiracy; deliberate shielding of customers from law enforcement demands and takedowns | $62 million in proceeds from attacks on dozens of US businesses across more than 20 states. Indictment returned under seal 5 December 2024, Case 1:24-CR-001161, N.D. Ohio, unsealed 14 July 2026 under Operation Riptide. Rewards for Justice offering up to $10 million | Medium |
Three observations. First, the 13 July package is the EU's largest-ever cyber sanctions round and, per High Representative Kaja Kallas, its biggest round of individual designations since the 2022 full-scale invasion. Second, it confirms a deliberate shift from designating operators to designating the enabler tier: VPN providers, malware-as-a-service developers, bulletproof hosting, and cryptor developers were all named in a single coordinated action. Third, the 1VPNS designation follows a repeatable and fast evidentiary model, building on on-chain payment traces from named ransomware operators to the enabler rather than on victim-impact attribution, which is substantially slower to assemble. CONFIRMED.
Financial Flow Observations
- Coveware by Veeam, Q2 2026, published 30 July: average ransom payment $1.88 million, up 176 percent quarter over quarter; median payment $150,000, down; overall payment rate at a record low; exfiltration-only payment rate at 15 percent. CONFIRMED per source.
- Chainalysis 2026 Crypto Crime Report baseline: $820 million in total on-chain ransomware payments in 2025, down 8 percent from $892 million in 2024, against a 50 percent rise in claimed attacks. The share of victims paying reached an all-time low of 28 percent. Median ransom payment rose 368 percent from $12,738 in 2024 to $59,556 in 2025. CONFIRMED per source, dated February 2026.
- INTERPOL Operation First Light 2026, results announced 9 July: $293 million in illicit assets intercepted, 31,014 bank accounts blocked, 152,808 cases analysed. A single 20-year-old suspect's digital wallet in Thailand had processed more than $122.5 million in ten months, laundering romance-scam proceeds through cross-chain token swaps. CONFIRMED.
- Operation Endgame, June phase, carried forward: between EUR 41 million and $46 million in criminal cryptocurrency identified and frozen. CONFIRMED.
- Kairos received approximately $1 million (9.44 BTC at the time) from a US government entity in a pure data-theft extortion with no encryption, reported 3 July. This is a rare confirmed single-payment figure from a public-sector victim. CREDIBLE REPORTING; neither the county nor the group has confirmed the identification.
- Stablecoin issuer freezing is now demonstrably the highest-yield financial lever available. Tether froze $131 million immediately upon the 14 to 15 July Central Bank of Iran designation update, and cumulative freezes against OFAC-identified CBI addresses approach $475 million. Chainalysis notes the upstream counterparties for the newly designated addresses were an institutional liquidity provider and an Asia-based payment processor, both of which are themselves actionable nodes. CONFIRMED.
- The Martino prosecution establishes a documented dollar figure for negotiator-side compromise: one victim paid approximately $1.2 million in Bitcoin, affiliates shared 20 percent of ransoms with BlackCat operators, and law enforcement seized $10 million in assets from Martino alone, including cryptocurrency, vehicles, a food truck and a luxury fishing boat. CONFIRMED (DOJ via Security Affairs).
Infrastructure Hosting Patterns
- Media Land LLC and ML.Cloud LLC, both headquartered in St. Petersburg, are named in the unsealed indictment as providing hosting and infrastructure support to criminal and state-backed actors. Treasury previously sanctioned both for allowing LockBit, BlackSuit and Play to use their infrastructure. CONFIRMED.
- JADEPUFFER infrastructure, from Sysdig's telemetry: command and control at 45.131.66[.]106 with a crontab beacon to port 4444 every 30 minutes, and a staging or exfiltration server at 64.20.53[.]230, attributed to InterServer, AS19318. The staging claim is the agent's own self-narrated assertion and was not independently verified as exfiltration. CONFIRMED as an indicator, ANALYST INFERENCE as to exfiltration.
- Structural finding worth carrying forward: Chainalysis assesses that the infrastructure layer has converged, with financially motivated cybercriminals and state-aligned actors using the same bulletproof hosting providers and residential proxy networks to evade detection. Dismantling or sanctioning an infrastructure node therefore generates cascading effects across ransomware affiliates, scammers and state-aligned operators simultaneously. CONFIRMED per source.
- Counter-pressure on that logic, from the same month: Mandiant told BleepingComputer that disrupting one proxy service often prompts operators to purchase replacement capacity from competing providers, turning those competitors into resellers, because the proxy industry is deeply interconnected with operators constantly buying and reselling each other's botnet capacity. CONFIRMED.
SECTION 7 - LAW ENFORCEMENT AND REGULATORY ACTIONS
New Actions This Month
| Operation | Lead Agencies | Date | Outcome | Impact |
|---|---|---|---|---|
| Stokes extradition (Scattered Spider) | US DOJ, Northern District of Illinois, with Finland | 1 July 2026 | Peter Stokes extradited from Finland and detained pending trial. Approximately $8 million extortion attempt across 100-plus intrusions. In US custody | Medium-High |
| Tri-lateral cyber sanctions package | EU Council, UK FCDO, US Treasury OFAC | 13 July 2026 | 37 designations across three jurisdictions (EU 9 individuals plus 4 entities; UK 24; OFAC 3). Stern named for the first time; LummaC2 developers, Media Land, GRU Unit 29155, CARR and Z-Pentest designated. EU's largest-ever cyber package. No arrests | High |
| Martino sentencing (BlackCat / ALPHV) | US DOJ Criminal Division | 10 July 2026 | 70 months' imprisonment for a serving ransomware negotiator who sold client negotiation strategy and insurance limits to BlackCat across five victim cases. $10 million in assets seized. Restitution hearing set for 17 September | Medium |
| NetNut / Popa disruption | Google GTIG, FBI, IRS, Lumen Technologies, Shadowserver Foundation | 2 to 3 July 2026 | At least 2 million infected devices cut off; netnut.com, proxyjet.io and divinetworks.com seized; C2 accounts and services on Google infrastructure disabled; SDK flagged in Play Protect. No arrests reported | High |
| INTERPOL Operation First Light 2026 | INTERPOL, 97 countries and territories | Operation 15 Jan to 30 Apr 2026; results announced 9 July 2026 | 5,811 arrests; $293 million intercepted; 31,014 bank accounts blocked; 15,606 suspects identified; 142,000-plus victims identified; 152,808 cases analysed | Medium |
| OFAC designation of 1VPNS | US Treasury OFAC, coordinated with UK FCDO | 13 July 2026 | Three designations (one entity, two individuals); all US-jurisdiction property and interests frozen; follows the May 2026 Operation Saffron takedown of the 1VPNS website | Medium-High |
| Media Land / ML.Cloud indictment | US DOJ; State Department Rewards for Justice | Unsealed 14 to 15 July 2026 | Three Russian nationals and two companies charged; $62 million in proceeds alleged; up to $10 million reward offered. No arrests; all defendants in Russia | Medium |
| Operation Olympus Blade (Kratos / Sneaky2FA) | Germany BKA and ZIT with US authorities and Indonesian police; Trend Micro intelligence support | 20 July 2026 | More than 200 servers shut down; platform fully offline; developer and technical administrator arrested in Indonesia; 1,800-plus subscriber base disrupted | Medium-High |
Impact rationales. The Stokes extradition is scored Medium-High because it is a completed transfer into custody of a named individual, the outcome this series most often lacks, though it reaches an English-speaking Scattered Spider subject rather than a Russia-based operator. The tri-lateral package is scored High because it names the ecosystem's most financially significant identified operator for the first time and simultaneously covers four enabler categories across three jurisdictions, which closes the forum-shopping gaps that single-jurisdiction designations leave open. NetNut is scored High because the anonymization layer is cross-cutting: 316 distinct threat clusters were observed using it in a single week, spanning criminal and espionage actors. Olympus Blade is scored Medium-High as the only July action combining infrastructure removal with the arrest of a principal. The 1VPNS designation is scored Medium-High because it establishes a repeatable evidentiary model and reaches a Ukrainian subject in a cooperating jurisdiction. The Martino sentencing is scored Medium: it is a custodial result with $10 million recovered, but it addresses an insider failure mode rather than reducing adversary capacity. The Media Land indictment is scored Medium on its own because it carries no custodial or infrastructure-seizure component, though in combination with the EU designation of the same individual one day earlier its practical effect is greater. First Light is scored Medium for ransomware specifically because its focus was social engineering fraud and associated laundering, though its impact on the broader fraud ecosystem is High.
Reconstitution Status Tracker
Prior-cycle actions updated at 30, 90 and 180-day intervals. Status options: Fully Reconstituted, Partially Reconstituted, Not Reconstituted, Pending, No Data.
| Operation | Action Date | Target | Action Type | 30-Day | 90-Day | 180-Day |
|---|---|---|---|---|---|---|
| RAMP forum seizure | 28 Jan 2026 | RAMP forum | Seized | Dark | Dark | Not Reconstituted (184 days; suspected admin publicly declined to rebuild) |
| LeakBase seizure | Mar 2026 | LeakBase | Seized | Not Reconstituted | Not Reconstituted | Pending (~150 days) |
| BKA REvil warrants | 6 Apr 2026 | REvil / GandCrab operators | Warrants | No arrest | No arrest | Pending (~117 days) |
| Stark / Dutch FIOD | 18 to 27 May 2026 | Stark BPH | ~800 servers seized | Partially Reconstituted (successor claim remains unverified) | Pending (~70 days) | Pending |
| Operation Saffron | 19 to 20 May 2026 | 1vpns anonymization | 33 servers seized | Not Reconstituted | Not Reconstituted (~73 days); reinforced by the 13 July OFAC designation | Pending |
| AudiA6 takedown | 10 Jun 2026 | Laundering service | Seized; 2 arrests | Not Reconstituted | Pending (~52 days) | Pending |
| Operation Endgame (StealC / Amadey / SocGholish) | 15 to 24 Jun 2026 | Stealer and loader infrastructure | 326 servers, 142 domains | No confirmed C2 re-emergence in retrieved sources (~45 days) | Pending | Pending |
| NetNut / Popa disruption | 2 to 3 Jul 2026 | Residential proxy, 2M devices | Domains seized, C2 disabled | Pending (~29 days) | Pending | Pending |
| Media Land indictment | 14 Jul 2026 | BPH provider | Indictment only | Pending (~18 days); no infrastructure seizure component | Pending | Pending |
| Operation Olympus Blade | 20 Jul 2026 | Kratos PhaaS | 200+ servers; 1 arrest | Pending (~12 days) | Pending | Pending |
| Lumma Stealer takedown | May 2025 | Lumma C2 (2,300 domains) | Seized | Past | Past | Fully Reconstituted |
Cumulative Impact Assessment
Short-term disruption (1 to 30 days): High. Six enablement layers were removed, degraded or designated inside nineteen days: anonymization, phishing-as-a-service, VPN concealment, cryptor services, malware-as-a-service and bulletproof hosting. The measurable capacity removed is substantial and specific: at least 2 million proxy nodes serving 316 observed threat clusters, a PhaaS platform running roughly 15,000 campaigns per month for 1,800 subscribers, a VPN service with traced payments from three named ransomware operators, and $131 million in stablecoins frozen at the issuer within a day of designation. Thirty-seven designations landed across three jurisdictions on a single day, plus one custodial sentence and one arrest.
Custodial outcomes. July produced two, which is unusual for this series and revises the standing assessment that enforcement reaches infrastructure but not people. Peter Stokes was extradited from Finland into US custody on 1 July. Angelo Martino was sentenced to 70 months on 10 July with $10 million in assets recovered. A third, the Kratos developer, was arrested in Indonesia on 20 July. Set against that, every Russia-based principal named during the month remains beyond reach.
Structural ecosystem impact (90-plus days): Medium-High, revised upward from the prior cycle. Two factors raise the score. First, the tri-lateral coordination closes jurisdictional gaps that single-authority designations leave open, and naming Stern removes the pseudonymity that has protected the Trickbot syndicate's most senior figure for a decade. Second, the Iran Central Bank action proves that issuer-level stablecoin freezing converts designation into immediate asset denial at nine-figure scale, which no infrastructure seizure in this series has achieved. Three factors hold it below High. Reconstitution history remains unfavourable, with Lumma fully reconstituted and now assessed to lead 2026 distribution even as its developers are designated, which shows designation alone does not remove capability. Mandiant's on-record assessment that disrupting one proxy service converts competitors into resellers means the NetNut action displaces capacity rather than removing it. And every Russia-based principal named in July, Kovalev, Volosovik, Zatolokin, Pankova, Voronin, Gordienko and Bashev, remains beyond custodial reach. The actions with the highest probability of durable structural results are the two that reach cooperating or domestic jurisdictions: the 1VPNS designation of a Ukrainian administrator, and the Martino sentencing. ANALYST INFERENCE, medium confidence.
SECTION 8 - VULNERABILITY EXPLOITATION MATRIX
CVEs with confirmed exploitation during the reporting period, cross-referenced against the CISA KEV catalog. All cisa.gov fetches returned empty bodies during collection (see Section 13); KEV facts are corroborated through Security Affairs, The Hacker News and Help Net Security.
| CVE | Product | CVSS | Exploitation Method | Threat Actor | Scale / Volume | CISA KEV | KEV Date |
|---|---|---|---|---|---|---|---|
| CVE-2026-45659 | Microsoft SharePoint Server | 8.8 | Deserialization of untrusted data to RCE; authenticated attacker with Site Member rights | July activity not attributed. Storm-2603 (Warlock) known for SharePoint exploitation since mid-2025 | Not quantified | Yes | 1 Jul 2026; due 4 Jul |
| CVE-2026-48282 | Adobe ColdFusion | 10.0 | Path traversal to unauthenticated arbitrary code execution | Not attributed. First exploitation from 103.207.14[.]220 | Exploited under 2 hours after public disclosure | Yes | 7 Jul 2026; due 10 Jul |
| CVE-2026-56290 | Joomlack Page Builder CK | 10.0 | Improper access control to web shell installation | Not attributed | Live web shell on a production Joomla site within hours of the 27 Jun fix | Yes | 7 Jul 2026; due 10 Jul |
| CVE-2026-48908 | JoomShaper SP Page Builder | 10.0 | Unrestricted file upload to PHP execution and admin account creation | Not attributed | Not quantified | Yes | 7 Jul 2026; due 10 Jul |
| CVE-2026-55255 | Langflow | 6.1 CISA / 9.9 Sysdig | Authorization bypass via user-controlled key; chained with CVE-2026-33017 for RCE | Financially motivated cluster, botnet or cryptojacking oriented | Exploitation 22 to 25 Jun; first active exploitation 25 Jun | Yes | 7 Jul 2026; due 10 Jul |
| CVE-2026-16232 | Check Point Security Mgmt / Multi-Domain | Critical auth bypass | Unauthenticated login-token retrieval, then SmartConsole login with full admin rights and policy modification | Not attributed. Check Point published attacker IPs | A handful of customers confirmed affected and notified | Yes | Due 25 Jul 2026 |
| CVE-2025-3248 | Langflow | 9.8 | Missing authentication on the code validation endpoint; unauthenticated Python execution | JADEPUFFER (agentic ransomware) | One documented operation; 600+ payloads; 1,342 config items encrypted | Yes | May 2025 |
Lag analysis. The reporting period contains both extremes of the KEV-to-exploitation interval. CVE-2025-3248 was KEV-listed in May 2025 and used as the entry point for the first documented agentic ransomware operation disclosed on 1 July 2026, a gap of roughly fourteen months. CVE-2026-48282 inverts it entirely, with exploitation beginning under two hours after public disclosure. Sysdig's assessment explains why both are now dangerous simultaneously: agentic tooling makes spraying the entire historical vulnerability catalogue effectively free, so the long tail of unpatched systems becomes more exposed over time rather than less. The operational implication is that KEV age is no longer a useful triage input for exposed internet-facing assets.
SECTION 9 - SUPPLY CHAIN AND THIRD-PARTY COMPROMISE
ShinyHunters OAuth and Identity Abuse (SaaS supply chain)
- Attacker: ShinyHunters, tracked as UNC6240, active since 2020, having moved from consumer telecom and retail data theft into the Salesforce ecosystem and enterprise identity infrastructure. CREDIBLE REPORTING.
- Compromised components: trusted OAuth relationships and long-lived application tokens rather than the SaaS platforms themselves. Microsoft's Defender Security Research team published research on 13 July mapping a year of this activity across Salesforce environments in retail, education and manufacturing. CREDIBLE REPORTING; the Microsoft primary post was not retrieved during collection.
- July incident: Abbott Laboratories was added to the group's leak site in mid-July after a June voice-phishing campaign against employees compromised a corporate Microsoft Entra single sign-on account tied to the Cancer Diagnostics business. The group set an 18 July leak deadline before extending negotiations to 21 July. CREDIBLE REPORTING.
- Downstream impact estimate: no reliable data on the number of affected environments. The technical fingerprint shared across the Abbott intrusion and the mapped Salesforce campaigns indicates a single reusable access pattern rather than isolated incidents.
- Related carryover: Google Threat Intelligence Group and Mandiant attributed a zero-day campaign against Oracle PeopleSoft to the same group and its affiliates in June 2026; Oracle subsequently released an out-of-band fix. CREDIBLE REPORTING.
- Detection and remediation status: Abbott investigating as of month-end; no public confirmation of scope. CREDIBLE REPORTING.
JADEPUFFER (AI orchestration platform as supply-chain entry)
- Attacker: an agentic threat actor, meaning an operator whose attack capability is delivered by an AI agent rather than a human-driven toolkit. CONFIRMED (Sysdig Threat Research Team).
- Compromised components: an internet-facing Langflow instance reached through CVE-2025-3248, then the Langflow backing Postgres database, then a MinIO object store using default credentials minioadmin:minioadmin, from which the agent listed all buckets including a terraform-state bucket and fetched credentials.json and .env from an internal configuration bucket. The true target was a separate internet-exposed production server running MySQL and an Alibaba Nacos configuration service. CONFIRMED.
- Downstream impact: 1,342 Nacos service configuration items encrypted with MySQL AES_ENCRYPT, the config_info and his_config_info tables dropped, an extortion table created, and multiple production database schemas dropped after the agent disabled foreign key checks. The AES key was generated from two UUIDs, printed to stdout and never persisted or transmitted, so the victim cannot recover the configurations even on payment. CONFIRMED.
- Detection and remediation status: documented and published 1 July with full indicators. Recommendations centre on patching Langflow, removing provider API keys and cloud credentials from AI-orchestration server environments, hardening Nacos default token signing keys, and applying egress controls. CONFIRMED.
Trend Assessment
Supply chain attacks as a percentage of total incidents: no reliable July figure is available, and none was published in the retrieved reporting. What is verifiable is a structural characterisation rather than a percentage. Black Kite's April 2025 to March 2026 dataset finds that third-party services including SaaS platforms, ERP systems, CRM applications, OAuth tokens, remote access tools and connected business software have become common attack paths, and that organizations with strong internal controls remain exposed through them. The July evidence supports a specific refinement of that finding: the two documented supply-chain vectors this month, OAuth token abuse and AI orchestration compromise, both bypass the vulnerability model entirely. Neither the ShinyHunters Abbott intrusion nor the Langflow credential harvest depended on exploiting the trusted platform. They depended on the trust relationship itself, and on credentials stored in an adjacent service. Patching does not close either path. CREDIBLE REPORTING with an explicit quantification gap.
SECTION 10 - ECOSYSTEM CONTROL NODE ANALYSIS
Top Control Nodes Table
| Rank | Node | Type | Estimated Ecosystem Reach | Dependencies | SPOF? | Disruption Difficulty |
|---|---|---|---|---|---|---|
| 1 | Stablecoin issuance and crypto cashout layer | Crypto Laundry | $820M in on-chain ransomware payments in 2025. Demonstrated chokepoint: Tether froze $131M within a day of the 14 to 15 July CBI designation, with cumulative freezes near $475M. Confirmed | A single dominant issuer's compliance function; exchange on and off-ramps; correspondent banking | Yes for USDT-denominated flows | Medium, revised down. Issuer cooperation is proven and fast |
| 1b | Victim-side negotiation and incident response layer | Other | Coveware Q2: average payment $1.88M across a shrinking payer population. Martino case: one negotiator compromised five victim cases and $10M in assets recovered. Confirmed | Professional licensing, insurer panels, employer vetting at IR firms | No | Low. Domestic, regulated, and reachable by subpoena |
| 2 | Infostealer-to-IAB credential pipeline | IAB Market | Average access price collapsed to $439 from $1,427 on log oversupply; IAB inflow spikes precede payment spikes by ~30 days. Estimate, high confidence | MaaS operators, Telegram distribution channels, ClickFix delivery clusters | No | Extreme (fully decentralized) |
| 3 | Residential proxy and anonymization layer | BPH / Other | NetNut alone at 2M+ devices with 316 distinct threat clusters observed in one June week. Confirmed for NetNut, estimate for the layer | Consumer device supply chain, SDK distribution, reseller whitelabeling agreements | No (reseller mesh) | High (reconstitutes by substitution) |
| 4 | The Gentlemen RaaS | RaaS Platform | 18.3% of leak-site posts in the final week of July; 238 Q2 victims; 94 June victims. Confirmed per tracker | Affiliate pool; 90/10 split economics; leak-site infrastructure | Partial | Medium (operator identity previously exposed) |
| 5 | Qilin RaaS | RaaS Platform | 14% of all Q2 2026 victims (301); 41 healthcare-provider claims in H1. Confirmed per source | Same affiliate pool; RAMP dispute resolution no longer exists | Partial | High (no acting jurisdiction) |
| 6 | Phishing-as-a-service (Kratos successor market) | Stealer / PhaaS Service | Kratos: 1,800+ subscribers and ~15,000 campaigns per month prior to the 20 July takedown. Confirmed | AiTM kit development talent, Telegram sales channels, domain supply | Partial | Medium (twice disrupted, twice rebranded) |
| 7 | Bulletproof hosting (Media Land / ML.Cloud tier) | BPH Provider | $62M in charged US losses; LockBit, BlackSuit and Play named as tenants. Confirmed | Upstream transit carriers, RIR resources, corporate formation agents | No | High (Russian jurisdiction) |
| 8 | Enterprise edge and management plane | Other | Six KEV additions in July across ColdFusion, SharePoint, Check Point, Langflow and two Joomla builders. Confirmed | Vendor patch cadence; exposure of management interfaces to the internet | No | Low (defender-side remediable) |
| 9 | DarkForums and private Telegram (post-RAMP forum layer) | Forum | RAMP and BreachForums both non-operational; migration concentrated on DarkForums and Telegram. Credible reporting | Hosting, administrator OPSEC, reputation escrow | Partial | Medium (RAMP precedent shows durable denial is achievable) |
| 10 | Agentic attack tooling | Other | One documented end-to-end agentic ransomware operation with 600+ payloads. Confirmed, single case | LLM API access, or stolen compute via LLMjacking | No | Extreme (dual-use, commercially available) |
Cascade Failure Analysis
Node 2, infostealer-to-IAB credential pipeline. What breaks downstream: the credential supply that sets affiliate operating cost. The measurable effect of this node functioning well is that corporate access now averages $439 against $1,427 three years ago, a 69 percent reduction in the entry cost of a ransomware operation. Remove it and affiliate unit economics invert immediately, because the 58-to-1 return ratio between ransomware payments and IAB spend collapses when access has to be earned rather than bought. Realistic reconstitution timeline: weeks. Lumma reconstituted within weeks of a takedown that removed 2,300 domains and now leads 2026 distribution. Enforcement mechanism that could realistically work: none in single-strike form. The only demonstrated approach is repeated coordinated action on the Operation Endgame model, treating each strike as one increment of sustained cost rather than a terminal event. Chainalysis's finding that IAB inflow spikes lead payment spikes by 30 days also means this node offers the ecosystem's best early-warning telemetry, which is an intelligence value independent of any disruption value.
Node 3, residential proxy and anonymization layer. What breaks downstream: attribution resistance for every actor category simultaneously. In a single week, 316 distinct threat clusters spanning criminal and espionage operations routed through one provider. Remove it and password-spray campaigns, victim-environment access and operator infrastructure management all lose their residential-IP cover at once. Realistic reconstitution timeline: 30 to 60 days, and by substitution rather than rebuild. Mandiant states directly that disrupting one proxy service prompts operators to buy replacement capacity from competitors, converting those competitors into resellers, because the industry is built on mutual capacity trading. Enforcement mechanism that could realistically work: simultaneous rather than sequential action against the reseller and whitelabel tier. Taking the largest provider offline while its whitelabel partners remain operational transfers customers instead of denying capacity.
Nodes 4 and 5 treated jointly, the RaaS affiliate labour market. What breaks downstream: nothing durable, and that is the finding. The number one position changed hands in June because a former Qilin affiliate offered a 90/10 split after a payout dispute, not because of superior tooling. Halcyon assesses roughly half the names on any given month's top-15 list were absent the month before. Removing either platform displaces its affiliates into the competing platform within weeks, which is precisely what the June transition demonstrated in reverse. Realistic reconstitution timeline: weeks, and it is not reconstitution, it is migration. Enforcement mechanism that could realistically work: nothing targeting the platforms. The mechanism that would work targets affiliate expected value directly, meaning the payment layer, which is Node 1 and the subject of Section 11.
Structural Vulnerability Summary
The single most critical structural weakness in the current ecosystem is the payment layer, and July produced the first direct proof of it. Every other node reconstitutes by substitution: proxies by reseller transfer within 30 to 60 days, stealers within weeks, RaaS platforms by affiliate migration in the same cycle they are disrupted, bulletproof hosting by re-registration under Russian jurisdiction. LummaC2 makes the point sharply, remaining operational and assessed as a 2026 distribution leader on the same day its named developers were designated by the EU. The payment layer does not substitute, because it is the only node that must interface with the regulated financial system to convert extortion into value, and on 14 to 15 July Tether froze $131 million within a day of an OFAC designation, taking cumulative freezes against those addresses to nearly $475 million. No infrastructure seizure in this reporting series has produced comparable denial on comparable timescales. Coveware's Q2 data shows the layer is already under strain from the other direction: the payment rate is at a record low, exfiltration-only extortion converts at 15 percent, and the ecosystem's revenue now flows through a shrinking population of transactions averaging $1.88 million. That concentration is a vulnerability, not a strength, because a small number of large traceable payments is a far more tractable enforcement surface than a large number of small ones. The Martino case exposes the adjacent weakness: the professional layer advising victims through those transactions is domestic, licensed and reachable, and it has now been shown to be corruptible. The ecosystem is most brittle where extorted value converts to spendable funds, and least brittle at the infrastructure and platform layers where the majority of July's operational effort was directed.
SECTION 11 - STRATEGIC LEVERAGE ASSESSMENT
Financial Pressure
TARGET Ransom payment intermediation: negotiation firms, incident response providers, cyber insurers and exchange off-ramps servicing extortion proceeds above $1 million.
CONDITION Coveware Q2 2026 records a record-low overall payment rate with average payments at $1.88 million, up 176 percent quarter over quarter, and a median of $150,000. The revenue of the entire ecosystem now passes through a small, countable population of large transactions. On 10 July a serving negotiator at a US incident response firm was sentenced to 70 months for selling client insurance limits and negotiation strategy to BlackCat across five victim cases, with $10 million in assets seized.
THRESHOLD THRESHOLD MET twice over. The divergence between a rising average and a falling median confirms revenue concentration into a tractable number of transactions, and the Martino conviction confirms the intermediation layer is already penetrated.
ACTION Impose a mandatory 72-hour on-chain destination reporting requirement on any single extortion payment above $1 million, applied at the negotiation and payment-facilitation layer rather than the victim. Pair it with a licensing and background-vetting regime for ransomware negotiators, and require disclosure to the victim of any prior contact between the negotiator and the threat actor.
WINDOW Two to three quarters, before operators adapt by fragmenting demands below the reporting threshold.
PRIORITY Critical
TARGET Dominant stablecoin issuer compliance channel, and the upstream counterparties feeding designated addresses.
CONDITION Tether froze $131 million within a day of the 14 to 15 July Central Bank of Iran designation update, with cumulative freezes against those addresses approaching $475 million. Chainalysis identified the upstream counterparties for the newly designated wallets as an institutional liquidity provider and an Asia-based payment processor.
THRESHOLD THRESHOLD MET. Issuer-level freezing has been executed at nine-figure scale within a 24-hour window and the upstream counterparties are already identified on-chain.
ACTION Extend the same designate-then-freeze sequence to ransomware-attributed wallet clusters rather than reserving it for state-nexus targets, and designate the identified institutional liquidity provider and Asia-based payment processor to close the funding path rather than only the destination.
WINDOW Open now. Narrows as illicit flows migrate to issuers with weaker compliance functions or to non-custodial rails.
PRIORITY Critical
TARGET On-chain payment traces from named ransomware operators to enabler services, replicating the 1VPNS evidentiary model.
CONDITION TRM Labs traced Anubis payments in December 2025 and March 2026, a Qilin payment of $120 in January 2026 and a Sinobi payment of $58 in February 2026 directly to 1VPNS, and those traces underpinned the 13 July designation.
THRESHOLD THRESHOLD MET. The model has been executed once and the evidentiary pathway is proven; the trigger for each subsequent action is the existence of an operator-to-enabler payment trace, not the assembly of victim-impact evidence.
ACTION Designate the next three enabler services for which operator payment traces already exist, building each action on payment evidence rather than victim harm, which shortens the evidentiary timeline by quarters.
WINDOW Open now; narrows as enablers migrate to Monero and non-custodial rails.
PRIORITY High
Infrastructure Pressure
TARGET NetNut whitelabel resellers and capacity-trading partners.
CONDITION GTIG notes NetNut operated a robust reseller program allowing whitelabeling of its network, and Mandiant states that disrupting one proxy service prompts operators to purchase replacement capacity from competitors, turning those competitors into resellers.
THRESHOLD First confirmed migration of identified NetNut customers to a named competing proxy brand.
ACTION Identify the top five NetNut whitelabel resellers now and seize their domains and disable their control infrastructure in a single simultaneous action timed to the migration, rather than sequentially as each surfaces.
WINDOW 30 to 60 days from the 2 to 3 July action, which is the observed substitution interval for this layer.
PRIORITY High
TARGET The successor adversary-in-the-middle phishing kit to Kratos, and the Telegram sales channels that carried it.
CONDITION Kratos was itself a rebrand of Sneaky2FA, which had operated since October 2024, and the takedown follows the March 2026 disruption of Tycoon 2FA. The AiTM PhaaS category has now rebranded or been disrupted twice inside eighteen months while retaining its subscriber base.
THRESHOLD First advertisement of a new AiTM kit on the Telegram channels that previously carried Kratos.
ACTION Seize the Telegram sales channels and subscriber records at first advertisement rather than waiting for infrastructure maturity. The 1,800-subscriber base, not the 200 servers, is the reconstitution asset.
WINDOW 60 to 90 days, based on the Sneaky2FA to Kratos rebrand interval.
PRIORITY High
TARGET Internet-exposed AI orchestration platforms, specifically Langflow and Alibaba Nacos instances.
CONDITION JADEPUFFER used CVE-2025-3248, KEV-listed since May 2025. CVE-2026-55255 and CVE-2026-33017 were exploited between 22 and 25 June. These hosts routinely hold LLM provider API keys and cloud credentials and are frequently deployed without network controls. Nacos ships an unchanged default JWT signing key publicly documented since 2020.
THRESHOLD THRESHOLD MET. Two Langflow CVEs are KEV-listed, one has a documented end-to-end ransomware outcome, and the Nacos default key is a known unremediated condition.
ACTION Extend binding KEV remediation to AI orchestration platforms as a named asset class, and run a Shadowserver-model notification sweep of internet-exposed Langflow and Nacos instances with direct victim notification.
WINDOW Immediate. Agentic tooling makes spraying the historical CVE catalogue effectively free, so exposure converts to compromise faster each cycle rather than decaying.
PRIORITY Critical
Jurisdictional Pressure
TARGET Dmytro Rashevskyi, Ukrainian national, administrator of 1VPNS.
CONDITION OFAC designated Rashevskyi on 13 July. Unlike the Russia-based principals in the Media Land indictment, he is in a jurisdiction with a demonstrated record of cybercrime cooperation, including the July 2025 action against the XSS administrator. His co-designee Silayev is Belarusian.
THRESHOLD THRESHOLD MET. A cooperating-jurisdiction nexus exists and the designation is already in force.
ACTION Convert the designation into a Ukrainian criminal referral with a request for arrest and device seizure, prioritising recovery of 1VPNS subscriber records, which would identify by name the ransomware groups that purchased concealment.
WINDOW 90 days before the subject relocates to a non-cooperating jurisdiction; the designation itself creates the relocation incentive.
PRIORITY Critical
TARGET Alexander Volosovik, Kirill Zatolokin and Yulia Pankova, and the corporate entities Media Land LLC and ML.Cloud LLC.
CONDITION Volosovik is now subject to three separate actions in eight months: OFAC designation November 2025, EU designation 13 July 2026, DOJ indictment unsealed 14 July 2026, alleging $62 million in proceeds with a Rewards for Justice offer of up to $10 million. Media Land has served LockBit, EvilCorp and BlackBasta since 2016. All three defendants reside in St. Petersburg and extradition from Russia is not realistically available.
THRESHOLD THRESHOLD MET for the non-custodial elements. Triple designation across two jurisdictions plus a standing reward is the trigger for travel interdiction and corporate measures.
ACTION Circulate provisional arrest requests to third countries with US diplomatic agreements that these defendants have previously travelled to, and place both corporate entities on procurement and payment-processor deny lists across Five Eyes and EU jurisdictions to force successor registration into the open. Task the upstream transit carriers serving Media Land prefixes with termination notices citing the EU designation, which reaches European carriers that the US designation alone did not.
WINDOW Indefinite for arrest; 30 to 90 days for the corporate deny-list and carrier-notice action before successor entities are registered under new names.
PRIORITY High
TARGET Third-country interdiction coverage for CIS-national cybercrime subjects.
CONDITION The Russian MFA has published its own list of jurisdictions where it assesses US detention capability as effective and has advised citizens to avoid them: much of Europe and Latin America, plus Australia, Canada, Armenia, Israel, the Maldives, South Korea, Singapore, Thailand, Fiji, Sri Lanka, Liberia and Morocco. The Stokes extradition from Finland on 1 July demonstrates the mechanism completing. Read in reverse, the advisory is the adversary enumerating for its own criminal diaspora exactly where interdiction works.
THRESHOLD THRESHOLD MET. The list is published and one extradition completed inside the reporting month.
ACTION Prioritise provisional arrest request coverage across the named jurisdictions, and open liaison with jurisdictions conspicuously absent from the list before subjects relocate to them. Armenia's inclusion despite CSTO membership and Serbia's absence are the two most actionable anomalies.
WINDOW Open now. Degrades as subjects redistribute toward unlisted jurisdictions, which the advisory itself will accelerate.
PRIORITY High
TARGET Vitaly Nikolayevich Kovalev, alias Stern.
CONDITION EU-designated 13 July as senior administrator of the Trickbot and Conti syndicate, with wallets receiving more than $300 million as a personal cut. First public attribution of the Stern moniker to Kovalev by a sanctioning body, following BKA identification in 2025 and OFAC and OFSI designations in February 2023. Chainalysis Reactor maps his transactions across Ryuk, Conti, Diavol, Karakurt, Royal, 3am, Quantum and Bitpaymer.
THRESHOLD THRESHOLD MET. Public moniker-to-name attribution is the trigger, and it has now occurred across three jurisdictions.
ACTION Publish the wallet clusters underpinning the $300 million figure to enable exchange-level screening, and use the cross-strain transaction map to designate the downstream affiliates and service providers he paid, converting one designation into a network action against the 19-member sanctioned Trickbot cohort's remaining unsanctioned counterparties.
WINDOW 12 to 24 months. Historical wallet clusters do not decay, so this window is unusually long, but attribution value falls once the cohort migrates to new infrastructure.
PRIORITY High
Coming Month Focus (Top 3)
1. Apply the designate-then-freeze sequence proven against the Central Bank of Iran to ransomware-attributed wallet clusters, starting with the Stern clusters published in the 13 July EU designation. Expected outcome: nine-figure asset denial on a 24-hour timeline, replicating the $131 million Tether freeze, against a target set where the wallet attribution is already complete and public. This is the highest expected-value action available because it requires no new investigation and no foreign cooperation.
2. Pursue Rashevskyi through a Ukrainian criminal referral and seek seizure of 1VPNS subscriber records. Expected outcome: the first custodial result against a named ransomware enabler in this reporting series, and a subscriber list identifying the ransomware operations that purchased concealment, converting a single designation into a multi-target evidentiary base.
3. Pre-position the simultaneous NetNut reseller and whitelabel takedown inside the 30-to-60-day substitution window. Expected outcome: denial of replacement proxy capacity rather than transfer of it, producing the first measurable net reduction in available anonymization supply rather than a redistribution among providers.
SECTION 12 - UNCONFIRMED SIGNALS AND HORIZON INDICATORS
[UNCONFIRMED REPORTING] AsyncAPI npm organization compromise, 14 July 2026. Five package versions across four package names were reportedly republished within roughly ninety minutes, each carrying the same injected loader, with an actor identifying as TeamPCP claiming credit. The Microsoft Threat Intelligence primary post was not retrieved during collection and no downstream install count is available.
Confirm via: retrieval of the Microsoft Security Blog post and an npm advisory carrying affected-version download counts.
[UNCONFIRMED REPORTING] A malicious jscrambler npm package, version 8.14.0, reportedly reached the registry on 11 July carrying a preinstall hook that dropped a Rust infostealer on Windows, macOS and Linux, targeting cloud credentials and CI tokens.
Confirm via: an npm security advisory or a vendor writeup with affected-version download figures.
[UNCONFIRMED REPORTING] Q2 2026 initial-access telemetry placing phishing at 65 percent of intrusions. The figure surfaced in collection but the primary quarterly dataset was not retrievable, so it is excluded from the Section 4 ranking.
Confirm via: a retrievable ReliaQuest or LevelBlue Q2 2026 dataset with methodology.
[RESOLVED, RE-DATED] The Spanish arrest of an individual linked to CARR, Z-Pentest and NoName057(16) is substantively confirmed but is a July disclosure of a March 2026 action, not a July arrest. The investigation opened in August 2025 on an FBI tip; the arrest took place in Palencia in March 2026; reporting appeared 7 July 2026. The suspect allegedly provided logistical and operational support to a Ukrainian hacker operating for CARR and attempted to facilitate that hacker's escape to Russia via Poland and Belarus. Charges include membership of and collaboration with a terrorist organisation. The case sits under Operation Riptide. Significance is higher than first assessed: the EU designated both CARR and Z-Pentest on 13 July, pairing designation with custody against the same network inside one quarter.
Status: CREDIBLE REPORTING. Corroborated across five named outlets at search level; primary not yet fetched. Verification pending next cycle.
[UNCONFIRMED REPORTING] Medtronic reportedly notified 3.8 million individuals following a ShinyHunters breach. Headline-level verification only. If accurate, this materially raises the assessed downstream impact of the ShinyHunters identity-abuse campaign described in Section 9.
Confirm via: an HHS OCR breach portal entry with the affected-individual count.
[ANALYST INFERENCE] The final-week volume surge (240 posts, up 40.4 percent) may reflect three new entrants front-loading their leak sites to attract affiliates rather than a genuine rise in compromises. Global Secret Group, Booba Team and Exfilsquad accounted for 54 of the 240 posts, or 22.5 percent, on their debut week.
Refute via: August post volume from the same three groups. A debut spike that decays within one month is an affiliate-recruitment signal; one that sustains indicates real capacity.
[ANALYST INFERENCE] The 15 percent exfiltration-only payment rate indicates the encryption-free extortion model has reached a monetization ceiling. If confirmed, expect partial reversion to encryption among volume-oriented groups while extortion-only consolidates among actors targeting verticals with heavy regulatory exposure.
Confirm or refute via: the Coveware Q3 2026 exfiltration-only payment rate and Unit 42's updated encryption-use percentage. A Q3 figure below 15 percent confirms; above 20 percent refutes.
[ANALYST INFERENCE] Early warning for August: expect a second documented agentic ransomware operation, and expect StealC or Amadey command-and-control re-emergence at the 60-to-90-day mark from the June Operation Endgame action, which falls between mid-August and late September.
Confirm via: new C2 telemetry attributed to those families on fresh infrastructure, and vendor disclosure of a second LLM-driven end-to-end intrusion chain. Sysdig has already published a JADEPUFFER follow-on describing ransomware built to destroy AI models, which suggests the case count is already moving.
[ANALYST INFERENCE] Qilin's 44.7 percent week-over-week decline at month-end may mark a durable position change rather than cadence variance. The group held the top position for five consecutive quarters and lost it in June on affiliate economics, and the RAMP forum that once arbitrated its affiliate disputes no longer exists.
Confirm via: August and September monthly counts. Two further consecutive months below The Gentlemen confirms a structural shift; recovery within one month indicates variance.
SECTION 13 - ANALYTIC CAVEATS AND COLLECTION GAPS
Sources Blocked or Dropped During Verification
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog - fetch succeeded at the transport level but returned an empty body with no content. Dropped from the citation pool. All KEV facts in Section 8 are corroborated through Security Affairs, The Hacker News and Help Net Security.
- https://www.europol.europa.eu/media-press/newsroom - returned only the JavaScript application shell with the message that JavaScript must be enabled. No article content rendered. Dropped from the citation pool. Operation Endgame figures are corroborated through secondary reporting carried forward from the prior cycle.
Data Unavailable or Unreliable This Cycle
- No finalized July 2026 monthly analytical report was published as of 1 August. The July total is an estimate derived from two live trackers.
- RansomLook's retrieved daily series covers 4 to 31 July only; 1 to 3 July were not displayed. The full-month estimate extrapolates those three days at the observed daily mean.
- The ransomware.live dataset was last updated 26 July, so its year-to-date figure understates the month by approximately five days.
- July-specific sector and geographic victim breakdowns were unavailable. Section 2 substitutes Black Kite's April 2025 to March 2026 dataset and Comparitech's H1 2026 healthcare series, both dated explicitly in the tables.
- Time-to-publish, meaning the interval from compromise to leak-site publication, remains unresolved for a fourth consecutive cycle. The only in-window proxy is the four-day gap between Coca-Cola's 16 July 8-K filing and Anubis listing Fairlife on 20 July, which measures disclosure-to-publication rather than compromise-to-publication.
- No CIS-exclusion enforcement event was identified in July. The June Nova and Eriell case remains the most recent confirmed instance. Absence of an observed event is not evidence the norm has lapsed.
- IAB market metrics derive from Chainalysis and Darkweb IQ figures current to Q1 2026, not July telemetry.
- Microsoft published no victim count, affected-customer figure or increase baseline for the ACR Stealer surge, a gap noted explicitly in the secondary reporting.
- No supply-chain-as-percentage-of-incidents figure was published for the period. Section 9 states this rather than estimating.
Known Inflation and Deflation Biases in Victim Count Data
- Leak-site counts are simultaneously an overcount and an undercount. They include unverified claims, and they exclude victims who paid quietly. Comparitech's H1 2026 healthcare series illustrates the scale of the problem directly: 333 of 410 attacks were unconfirmed by the victim organization.
- Arete told Chainalysis that some groups repost old victims or victims taken from other groups' leak sites, which skews posting rates upward independent of any change in operational tempo.
- Cross-tracker comparison bias applies to the headline month-over-month figure. The July estimate comes from RansomLook and the June baseline from BreachSense via the prior cycle, and the two use different inclusion rules. The same-methodology weekly figure of plus 40.4 percent is the more defensible number.
- Vendor quarterly datasets from Coveware, GuidePoint, Black Kite and Halcyon each reflect their own client and telemetry populations. Coveware's payment figures in particular describe cases where a negotiation firm was engaged, which skews toward larger and better-resourced victims.
- Disclosure lag distorts monthly attribution. Comparitech notes that group claims often arrive a month or more after the attack, so a July-claimed attack may be a May or June compromise.
Competing Explanations for Major Observed Trends
- July volume rise: genuine growth in compromises, versus three new entrants front-loading leak sites for affiliate recruitment, versus a publication-cadence shift within existing groups. Unresolved pending August data.
- Qilin's 44.7 percent weekly decline: affiliate migration to The Gentlemen, which is Halcyon's reading and is supported by the documented 90/10 split differential, versus ordinary posting-cadence variance measured across a single seven-day window. A one-week sample cannot distinguish these.
- Record-low payment rates: improved defensive posture, backups and regulation suppressing payment, which is the Chainalysis reading, versus attackers succeeding in extracting far more per remaining payer, which Coveware's 176 percent average-payment jump equally supports. Both mechanisms are probably operating and they are not mutually exclusive.
- Lengthening takedown-to-relaunch cycles: durable enforcement cost imposed on the forum layer, versus voluntary operator dormancy to evade attention. The RAMP administrator's public statement declining to rebuild is weak evidence for the first reading, but it is a statement by an interested party.
- Healthcare business attacks rising 35 percent while provider attacks rose 3 percent: deliberate migration toward lower-political-cost targets holding comparable data, versus a reporting artifact in which business-sector victims are simply more likely to appear on leak sites because they are less likely to be covered by mandatory breach disclosure regimes.
Sections Omitted
No sections were omitted. All thirteen standing sections met the minimum data threshold, with explicit no-reliable-data notation applied wherever July-specific figures were unavailable rather than substituting hedged language.
Publication note: this is the published edition of the July 2026 cycle. It carries the full analytic content, figures, confidence labels and source list, together with a supplementary pass dated 2 August 2026 covering the Stokes extradition, the full 13 July designee roster including the Rybar tranche, and the Aeza pretrial-detention datapoint.
SOURCES
Every URL below was retrieved by direct fetch during verification. URLs that failed retrieval are listed in Section 13 and appear nowhere in the report body.
Ransomware Tracking Platforms
RansomLook - open ransomware intelligence, live post and group statistics - https://www.ransomlook.io
Ransomware.live - 2026 statistics, active groups and new-group registry - https://www.ransomware.live/stats/2026
Comparitech - Healthcare Ransomware Roundup, H1 2026 - https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
Government and Law Enforcement
US Treasury - Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans, 13 July 2026 - https://home.treasury.gov/news/press-releases/sb0559
OFAC - Recent Actions index - https://ofac.treasury.gov/recent-actions
TechCrunch - US charges Russian bulletproof web hosts over cyberattacks that netted $62M, 15 July 2026 - https://techcrunch.com/2026/07/15/us-charges-russian-bulletproof-web-hosts-over-cyberattacks-that-netted-62m-from-cybercrime-victims/
Security Affairs - INTERPOL Operation First Light nets 5,811 arrests and seizes $293 million, 9 July 2026 - https://securityaffairs.com/195056/security/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million.html
Security Affairs - Former ransomware negotiator sentenced to 70 months for secretly helping the BlackCat gang, 10 July 2026 - https://securityaffairs.com/195081/cyber-crime/former-ransomware-negotiator-sentenced-to-70-months-in-prison-for-secretly-helping-blackcat-gang.html
Vendor Threat Intelligence
Sysdig - JADEPUFFER: Agentic ransomware for automated database extortion, 1 July 2026 - https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
Trend Micro - Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, 22 July 2026 - https://www.trendmicro.com/en_us/research/26/g/kratos-takedown.html
Halcyon - Why The Gentlemen Beat Qilin: A Lesson in Ransomware Affiliate Economics, 14 July 2026 - https://www.halcyon.ai/blog/why-the-gentlemen-beat-qilin-a-lesson-in-ransomware-affiliate-economics
GuidePoint Security - Ransomware Insights from Q2 2026 (GRIT Q2 2026 Report), 9 July 2026 - https://www.guidepointsecurity.com/blog/ransomware-insights-q2-2026/
Cybersecurity News
The Hacker News - SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation, 2 July 2026 - https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html
The Hacker News - ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files, 17 July 2026 - https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
Security Affairs - CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow and JoomShaper SP Page Builder flaws to KEV, 8 July 2026 - https://securityaffairs.com/194927/hacking/u-s-cisa-adds-adobe-coldfusion-joomlack-page-builder-langflow-and-joomshaper-sp-page-builder-flaws-to-its-known-exploited-vulnerabilities-catalog.html
Help Net Security - Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232), 23 July 2026 - https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/
Help Net Security - Ransomware in 2026: More groups, more victims, no slowdown (Black Kite 2026 Ransomware Report), 24 July 2026 - https://www.helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report/
BleepingComputer - NetNut proxy network disrupted, 2 million infected devices cut off, 3 July 2026 - https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/
SWK Technologies - Cybersecurity News Recap July 2026 - https://www.swktech.com/swk-cybersecurity-news-recap-july-2026/
Financial Intelligence
Coveware by Veeam - Ransomware Payment Trends Q2 2026, 30 July 2026 - https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
Chainalysis - Crypto Ransomware: 2026 Crypto Crime Report - https://www.chainalysis.com/blog/crypto-ransomware-2026/
Chainalysis - Stern, likely most prolific ransomware operator ever, sanctioned by EU, 14 July 2026 - https://www.chainalysis.com/blog/cyber-sanctions-trickbot-administrator-july-2026/
Chainalysis - OFAC sanctions Iran Central Bank crypto wallets, freezing $131 million in stablecoins, 15 July 2026 - https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins/
Help Net Security - EU and UK blacklist Russia's cyber operators over efforts to destabilize Europe, 13 July 2026 - https://www.helpnetsecurity.com/2026/07/13/eu-uk-russia-cyber-activity-sanctions/
Infrastructure Intelligence
BleepingComputer - NetNut disruption, Google GTIG, FBI, Lumen and Shadowserver coordination detail - https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/
Chainalysis - infrastructure convergence between criminal and state-linked actors; bulletproof hosting and residential proxy analysis - https://www.chainalysis.com/blog/crypto-ransomware-2026/
END OF REPORT