The Observatory / Document Library / EDP Monthly July 2026
Monthly Cybercrime Ecosystem Intelligence Report
Coverage period July 2026. The month the enforcement posture shifted from operators to enablers: 37 designations across three jurisdictions in a single day, the first public attribution of the Stern moniker, and the first demonstration of issuer-level asset freezing at nine-figure scale.
13 July: 37 designations2 Jul to 1 Aug 202613 sections

Confidence labels are applied throughout: CONFIRMED, CREDIBLE REPORTING, and ANALYST INFERENCE. Every URL in the Sources section was retrieved by direct fetch during collection; sources that failed retrieval were dropped from the citation pool and are recorded in Section 13. Figures carried forward from earlier periods are dated explicitly where July-specific data was unavailable. To see which ecosystem nodes moved during this reporting period, open the map's delta view for July 2026.

SECTION 1 - EXECUTIVE SUMMARY

Five items, ranked by ecosystem-level strategic impact. Each carries at least one supporting metric and a confidence label.

1. On 13 July the United States, European Union and United Kingdom announced simultaneous sanctions described by Chainalysis as one of the largest cyber enforcement actions to date, with the EU designating 9 individuals and 4 entities, the UK 24 individuals and entities, and OFAC 3 targets. The headline designation is Vitaly Nikolayevich Kovalev, alias Stern, senior administrator of the Trickbot and Conti syndicate, whose wallets received more than $300 million in ransom payments as his personal cut alone, likely making him the single most prolific ransomware operator ever identified. This is the first time any sanctioning body has publicly tied the Stern moniker to Kovalev by name, and it brings the total Trickbot members sanctioned to 19. CONFIRMED.

2. The same package confirms a doctrinal shift from operator-targeting to enabler-targeting, executed across six layers in nineteen days: bulletproof hosting (EU designated Media Land LLC and owner Alexander Volosovik on 13 July, the DOJ unsealed his indictment on 14 July over $62 million in losses), malware-as-a-service (EU designated LummaC2 developers Voronin and Gordienko; the UK cited at least 2,100 UK Lumma victims in six months per the NCA), VPN concealment (OFAC designated 1VPNS), cryptor services (OFAC designated Silayev), residential proxy anonymization (NetNut/Popa, at least 2 million devices, disrupted 2 to 3 July), and phishing-as-a-service (Kratos, 1,800-plus subscribers and roughly 15,000 campaigns per month, taken down 20 July with an arrest). CONFIRMED.

3. The stablecoin chokepoint was demonstrated at scale on 14 to 15 July, when OFAC added four Central Bank of Iran crypto addresses that had received $165 million in stablecoins and Tether froze $131 million of the balances immediately, bringing total Tether freezes against OFAC-identified CBI addresses to nearly $475 million. This is the strongest evidence to date that issuer-level freezing converts a designation into immediate asset denial, unlike infrastructure seizure. CONFIRMED.

4. Coveware by Veeam data published 30 July shows the ransomware payment model bifurcating: the average payment rose 176 percent quarter over quarter to $1.88 million while the median fell to $150,000 and the overall payment rate reached a record low, with the exfiltration-only payment rate at 15 percent. The ecosystem is extracting far more from far fewer payers, and encryption-free extortion has demonstrated a monetization ceiling for the first time. CONFIRMED.

5. Sysdig documented JADEPUFFER on 1 July, the first known end-to-end agentic ransomware operation, in which a large language model autonomously exploited Langflow via CVE-2025-3248, harvested credentials, moved laterally, encrypted 1,342 Nacos configuration items and dropped production databases across more than 600 distinct payloads, correcting a failed login to a working fix in 31 seconds without human intervention. CONFIRMED.

SECTION 2 - RANSOMWARE ECOSYSTEM: MONTHLY STATISTICS

No finalized July 2026 monthly analytical report had been published as of 1 August. The figures below are drawn from two independent live trackers with different inclusion rules, and are labelled accordingly.

Sector Targeting Trend Table

No July-specific sector breakdown was published. The table uses the two most recent finalized comparative datasets: Comparitech's H1 2026 healthcare series (published 7 July, updated 9 July) against H2 2025, and Black Kite's ecosystem-wide sector ranking for April 2025 to March 2026.

SectorThis Period (n)Prior Period (n)% ChangeTrend
Healthcare (all)410 (H1 2026)360 (H2 2025)+13.9%Increasing
Healthcare providers247 (H1 2026)~239 (derived)+3.3%Stable
Healthcare businesses163 (H1 2026)~121 (derived)+34.7%Increasing
Healthcare manufacturersNo reliable countNo reliable count+36%Increasing
Healthcare retail / wholesaleNo reliable countNo reliable count+67%Increasing
Manufacturing (ecosystem-wide)Rank 1, most targetedNo prior dataNo reliable dataStable, dominant
Professional / scientific / technicalRank 2No prior dataNo reliable dataStable
ConstructionNext tierNo prior dataNo reliable dataStable
Finance and insuranceNext tierNo prior dataNo reliable dataStable
Retail tradeNext tierNo prior dataNo reliable dataStable

The healthcare sub-sector movement is the most analytically useful figure in the set. Attacks on direct-care providers were nearly flat at plus 3.3 percent while attacks on healthcare businesses, meaning pharmaceutical and device manufacturers, billing providers and health-tech firms, rose 34.7 percent. Within that, retailers such as device retailers and drug wholesalers rose 67 percent. Actors are migrating away from the patient-facing organizations that attract law-enforcement and regulatory attention, and toward the supply chain behind them, which holds comparable data with a lower political cost.

Geographic Targeting Analysis

Leak Site Three-Signal Composite

SignalThis Month (July)Prior PeriodTrendNotes
Post volume (victims published)731 posts, 4 to 31 July; ~809 full-month est. Final week: 240 posts~722 (June, prior cycle). Prior week: ~171 (derived)Increasing, +40.4% week over weekSame-methodology weekly figure is the reliable signal; the monthly comparison is cross-tracker
Time-to-publish (avg days, compromise to publication)No reliable dataNo reliable dataNot assessableFourth consecutive cycle with this gap. Partial proxy: Anubis listed Fairlife four days after the 16 July SEC disclosure
Takedown / relaunch cycle (days dark to successor)RAMP at 184 days dark as of 1 August; BreachForums with no legitimate version since April 2026RAMP ~150 days at prior cycleLengtheningRAMP passed the 180-day mark on 28 July with no successor; a suspected administrator publicly declined to rebuild

Composite interpretation. The three signals are not moving together, and the divergence is the finding. Post volume is rising steeply into month-end while the active operator count is contracting 15 percent in the same window, which means fewer groups are publishing more victims each. Set against Coveware's record-low payment rate and 176 percent jump in average payment, the coherent reading is a volume-and-concentration strategy: publish more victims to sustain pressure across a population where fewer will pay, and price the ones who do far higher. The takedown-to-relaunch signal continues to diverge from the other two. Forum-layer disruption is imposing durable cost, with RAMP now past 184 days and an administrator publicly declining reconstitution, while the RaaS layer it once served is posting record volume. Enforcement is succeeding against the coordination layer and failing to slow the production layer. ANALYST INFERENCE, medium confidence.

SECTION 3 - THREAT ACTOR LANDSCAPE

Russia and CIS-linked groups prioritized. Where July-only victim counts are unavailable, the most recent finalized quarterly or monthly figure is used and dated explicitly.

GroupVictimsKey Development (July)Threat ShiftCIS-Exclusion
The Gentlemen94 (June); 238 (Q2); 44 posts and 18.3% share in final week of JulyTook the number one position from Qilin for the first time in 2026; leads the leak-site feed at month-end; 31 healthcare-provider and 13 healthcare-business claims in H1IncreasingAssessed
Qilin71 (June, third place); 301 (Q2, 14% of all Q2 victims); 21 posts in final week of JulyFell 44.7% week over week at month-end after five consecutive quarters as most active operator; still leads healthcare-provider claims at 41 in H1DecreasingAssessed
DragonForce145 (Q2, third)Leads healthcare-business claims at 14 in H1; posting continued through 31 JulyStableAssessed
AkiraTop five (Q2)Pairs encryption with data theft rather than substituting one for the other; edge-device VPN exploitation remains the defining vectorStableAssessed
LockBit5Top five (Q2); 17 healthcare-provider claims (H1)Persists as a top-five operator despite prior disruption of the LockBit brandStableAssessed
AnubisNo reliable July countListed Coca-Cola subsidiary Fairlife on 20 July claiming 1 TB, four days after the parent filed an 8-K; US production temporarily suspended. On-chain payments to 1VPNS traced in Dec 2025 and Mar 2026IncreasingUnknown
ShinyHunters (UNC6240)No reliable July countListed Abbott Laboratories mid-July after June vishing against employees compromised a corporate Entra SSO account; leak deadline moved from 18 to 21 July. Extortion-onlyIncreasingUnknown
Kairos2 confirmed healthcare-business attacks (H1)Reported 3 July to have received roughly $1 million (9.44 BTC) from a US county government; never encrypted, exfiltrated over 2 TB including SSNs and fingerprint files; access via password guessing where MFA was absentIncreasingUnknown
Storm-2603 (Warlock)No reliable countContinues SharePoint exploitation; a Microsoft investigation found the actor co-resident with a second unrelated intruder in the same network and confirmed lateral movement into a second organizationStableUnknown
Deadlock86 cumulative since 15 June debut; last victim 25 JulyFastest-scaling 2026 debut on the tracker, concentrated in construction, engineering and professional servicesIncreasingUnknown
SinobiNo reliable July countOn-chain payment of $58 to 1VPNS traced to February 2026, establishing a documented operator-to-enabler payment linkStableUnknown

Three new entrants appeared in the final week of July and immediately posted at scale: Global Secret Group (24 posts), Booba Team (16 posts) and Exfilsquad (14 posts). Combined, these three accounted for 54 of the week's 240 posts, or 22.5 percent, on their debut. CONFIRMED (RansomLook). This is the pattern Black Kite describes as new groups launching high-volume campaigns immediately on market entry rather than building gradually.

Legacy and Structurally Significant Actors Named in the 13 July Designations

These actors are not among July's highest-volume operators but were designated during the reporting period and carry structural significance for attribution, financial tracing and the CIS safe-harbour question.

ActorAttributed ProceedsDevelopment (13 July 2026)CIS-Exclusion
Vitaly Nikolayevich Kovalev, alias Stern, Bentley, Bergen, Alex Konor, Benny, BenWallets received more than $300 million in ransom payments, representing his personal cut only; Trickbot's total haul is substantially largerEU-designated as senior figure of the Trickbot Group including Ryuk and Conti and their offshoots. First sanctioning body to attach the Stern moniker to Kovalev by name. Previously designated by OFAC and OFSI on 9 February 2023, and identified as Kovalev by Germany's BKA in 2025. Chainalysis Reactor shows him transacting with Ryuk, Conti, Diavol, Karakurt, Royal, 3am, Quantum and Bitpaymer. The Conti Leaks position him as a CEO-like figure with discretion over budget, procurement, hiring and attack planning. Total Trickbot members sanctioned now stands at 19Confirmed Russian national
Maksim Evgenevich Voronin and Maksim Aleksandrovich GordienkoNo reliable dataEU-designated as LummaC2 infostealer developers. Their malware-as-a-service platform was among the most used infostealer tools worldwide in 2024 and 2025 and reconstituted fully after the May 2025 takedown. UK measures cite Russian use of Lumma-harvested credentials for cyber espionage, with the NCA estimating at least 2,100 UK victims over six monthsAssessed
Alexander Alexandrovich Volosovik (Media Land LLC)$62 million in charged US lossesSubject to three separate actions inside eight months: OFAC designation November 2025, EU designation 13 July 2026, DOJ indictment unsealed 14 to 15 July 2026. Media Land has facilitated ransomware operations including LockBit, EvilCorp and BlackBasta since 2016Confirmed Russian, St. Petersburg
Evgeniy Viktorovich Bashev (GRU Unit 29155)Not quantifiedEU-designated. Facilitated infrastructure and payments and coordinated the GRU's collaboration with external hacker networks, including the WhisperGate campaign against Ukrainian critical infrastructure, which issued a cryptocurrency extortion demandConfirmed Russian state
Cyber Army of Russia Reborn (CARR) and Z-PentestNot quantifiedBoth EU-designated. Z-Pentest has targeted energy and water critical infrastructure including a Danish water utility in December 2024. CARR was previously OFAC-designated in 2024Confirmed pro-Russia
Angelo Martino (BlackCat / ALPHV conspirator, US)One victim paid approximately $1.2 million in Bitcoin; $10 million in assets seizedSentenced 10 July to 70 months. A serving ransomware negotiator at a US incident response firm who covertly passed client insurance limits and negotiation strategy to BlackCat across five victim cases from April 2023 while being paid by the operators. Co-conspirators Ryan Goldberg and Kevin Martin pleaded guilty in January 2026Not applicable, US national

Analytic significance. Two findings follow from this set. First, the Volosovik case establishes that layered designation is now operationally routine: an OFAC designation, an EU designation and a US indictment landed on the same individual and entity within eight months, and the EU and DOJ actions fell within 48 hours of each other. Second, the Martino sentencing is the only July action reaching inside the victim-response industry, and it documents a failure mode the ecosystem has not previously been shown to exploit at this level: the negotiator advising the victim was selling the victim's reserve price to the attacker. This bears directly on the payment-layer leverage described in Section 11. CONFIRMED.

Data Extortion Trend

Analytic judgement. The 15 percent exfiltration-only payment rate is the first hard quantitative evidence in this reporting series that encryption-free extortion carries a structural monetization penalty. Data theft alone gives the victim a recovery path that does not require the attacker, so the only leverage is reputational, and reputational leverage converts to payment less reliably than operational paralysis. If Q3 confirms the figure, expect volume-oriented groups to partially revert to encryption while the extortion-only model consolidates among actors targeting data-sensitive verticals with regulatory exposure. ANALYST INFERENCE, medium confidence.

SECTION 4 - INITIAL ACCESS AND TTP EVOLUTION

No net-new July initial-access ranking with published percentages was retrieved. The ranking below orders vectors by the volume of confirmed July incident reporting attached to each, and states the supporting metric for every position.

1. Paste-and-run social engineering (ClickFix class). Microsoft's Defender Experts team observed ACR Stealer activity climbing across customer environments from late April to mid-June and published two full delivery chains on 16 July, both opening with a user pasting a command into the Run dialog. Red Canary's April telemetry placed ClearFake, the web-inject cluster feeding ACR Stealer since at least March 2025, at number one on its most-prevalent-threat list for the first time, with ACR Stealer entering the top ten at a tie for sixth. Microsoft published no victim count, no affected-customer figure and no baseline for the increase it reported. CREDIBLE REPORTING with an explicit quantification gap.

2. Edge and management-plane exploitation. Six vulnerabilities were added to the CISA KEV catalog during July across ColdFusion, SharePoint, Check Point management servers, Langflow and two Joomla page builders. CVE-2026-16232, an unauthenticated authentication bypass against Check Point Security Management and Multi-Domain Security Management, was confirmed exploited with a handful of customers affected and notified; a federal remediation deadline of 25 July applied. This vector is distinguished by target selection: the compromised asset is the system that pushes policy to firewalls, not a firewall. CONFIRMED.

3. Valid accounts obtained through vishing and help-desk manipulation. ShinyHunters reached Abbott Laboratories through a June voice-phishing campaign against employees that yielded a corporate Microsoft Entra single sign-on account tied to the Cancer Diagnostics business. Microsoft's 13 July research maps a year of the same actor abusing trusted OAuth relationships and long-lived application tokens across Salesforce environments in retail, education and manufacturing, exploiting the trust relationship rather than the platform. CREDIBLE REPORTING.

4. Credentials purchased from initial access brokers. Chainalysis found that IAB on-chain inflow spikes precede increases in both global ransomware payments and US victim leak-site posts by roughly 30 days, making IAB purchasing a leading indicator rather than a coincident one. IABs received at least $14 million on-chain in 2025 against approximately $820 million in ransomware payments, a return ratio near 58 to 1. CONFIRMED per source.

5. Unauthenticated exploitation of AI orchestration infrastructure. Sysdig observed the first active exploitation of CVE-2026-55255 in Langflow on 25 June, and JADEPUFFER's initial access on the same platform used CVE-2025-3248. These hosts are attractive because they routinely hold LLM provider API keys and cloud credentials in their environment and are frequently stood up without network controls. CONFIRMED.

Significant TTP Developments

IAB Market Indicators Table

No July-specific IAB market telemetry was retrieved. Figures are from Chainalysis and Darkweb IQ data current to Q1 2026 and are dated explicitly as the best available baseline.

IndicatorThis Month (July 2026)Prior PeriodTrend
Volume of corporate access listingsNo reliable data675 privately offered accesses, Jan 2026 (+4% YoY)Flat to slightly increasing
Median access priceNo reliable dataAverage access price $439 (Q1 2026) vs $1,427 (Q1 2023)Decreasing, -69% over three years
Premium listing ceilingNo reliable dataNo published ceiling; validated high-privilege enterprise access still commands premium pricingBifurcating
Most-targeted sectors (top 3)No reliable dataEcosystem-wide victim sectors: manufacturing, professional services, constructionStable
Dominant access typeNo reliable dataVPN and RDP credentials named as Qilin's most frequent vector; Akira centres on SSL VPN without MFAStable, VPN-led
Notable marketplace eventsRAMP not reconstituted at 184 days; no legitimate BreachForums since April 2026; migration concentrated on DarkForums and private TelegramRAMP seized 28 Jan 2026Consolidating into fewer venues

The price collapse is the analytically significant movement. Darkweb IQ attributes the fall from $1,427 to $439 to industrialized access pipelines, AI-assisted tooling and infostealer-log proliferation producing an oversupply of cheap but operationally constrained inventory. The market is bifurcated rather than uniformly cheap: validated domain-level access still commands premium pricing. For enforcement, the implication is that price pressure at the low end is not a sign of ecosystem stress, it is a sign of successful automation upstream in the stealer layer.

SECTION 5 - MALWARE AND STEALER ECOSYSTEM

Families ranked by the volume and specificity of July reporting attached to each.

ACR Stealer (Amatera)

StealC, Amadey and SocGholish

LummaC2

NetNut / Popa (residential proxy)

Kratos / Sneaky2FA (phishing-as-a-service)

Infostealer-to-IAB Pipeline

Chainalysis identifies infostealer-log proliferation as a primary driver of the collapse in average corporate access pricing from $1,427 in Q1 2023 to $439 in Q1 2026, alongside industrialized access pipelines and AI-assisted tooling. The pipeline's timing characteristic is now measurable at the market level rather than the individual-log level: spikes in IAB on-chain inflows precede increases in global ransomware payments almost immediately, and increases in US victim leak-site posts after roughly a ten-day lull, with the full effect visible at 30 days. This makes IAB payment volume the single most useful leading indicator available to defenders and enforcement planners. CONFIRMED per source. Median time from individual infection to dark-web listing: no reliable data, a persistent gap across reporting cycles.

SECTION 6 - FINANCIAL AND INFRASTRUCTURE SIGNALS

Sanctions and Enforcement Actions

The 13 July tri-lateral package is the defining action of the reporting period and is broken out by designating authority below.

Authority / DateTargetStated RationaleEstimated Financial ExposureAssessed Impact
European Union, 13 July 20269 individuals and 4 entities. Entities: Media Land LLC, ML.Cloud, Z-Pentest, LLC Impuls. Individuals: Vitaly Nikolayevich Kovalev (Stern); Alexander Volosovik; LummaC2 developers Maksim Voronin and Maksim Gordienko; Yuliya Pankratova and Denis Degtyarenko (CARR); Evgeniy Bashev (GRU Unit 29155); Ivan Kasyanenko (GRU SSD)Denouncing Russia's malicious cyber ecosystem targeting the EU, member states and international partners. Campaigns attributed to the FSB 16th Centre, which directs threat groups including Turla and has targeted government networks and critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and FinlandStern wallets received over $300 million as a personal cut; Media Land tied to LockBit, EvilCorp and BlackBasta since 2016; Poland attack of 29 Dec 2025 hit 30-plus wind and solar farms, a combined heat and power plant and a manufacturer with a previously unseen OT wiperHigh
United Kingdom FCDO, 13 July 202624 designations. GRU officers Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko; Unit 29155-linked Aleksandr Shepelev, Roman Puntus, Dmitriy Voronov and Sultan Omarov; OOO Impuls and Evgeniy Bashev; CARR figures Yuliya Pankratova and Denis Degtyarenko; Lumma-linked Maksim Voronin, Maksim Gordienko and Marat Zhurkin; and ten Rybar LLC-linked individualsCoordinated malicious cyber ecosystem; Russian use of Lumma Stealer credentials to support cyber espionage. The Rybar tranche targets disinformation rather than cybercrime, making this a combined cyber and state-influence package rather than a purely criminal oneNCA estimates at least 2,100 UK Lumma victims over the preceding six monthsMedium-High
OFAC, 13 July 2026First VPN Service (1VPNS); Dmytro Rashevskyi, Ukrainian administrator; Yevgeniy Vladimirovich Silayev, Belarusian cryptor sellerEnabling ransomware actors and other cybercriminals. 1VPNS advertised on criminal forums since 2014 with a no-logs policy and refusal to cooperate with law enforcement; Silayev sold cryptors disguising ransomware as safe softwareTreasury states the groups using these services caused billions of dollars in losses. TRM traced Anubis payments (Dec 2025, Mar 2026), Qilin $120 (Jan 2026) and Sinobi $58 (Feb 2026). OFAC listed wallet addresses across Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin and SolanaMedium-High
OFAC, 14 to 15 July 2026Central Bank of Iran designation updated with four additional cryptocurrency addressesUse of cryptocurrency to sidestep sanctions, fund the regime and funnel assets to regional partners including HezbollahThe four wallets received $165 million in stablecoins; $131 million frozen immediately by Tether. Cumulative Tether freezes against OFAC-identified CBI addresses now approach $475 millionHigh
OFAC, 20 July 2026Russia-related designations updatesNot enumerated on the retrieved recent-actions indexNo reliable dataNo reliable data
DOJ, indictment unsealed 14 to 15 July 2026Alexander Volosovik (43), Kirill Zatolokin (34), Yulia Pankova (29); Media Land LLC and ML.Cloud LLC, St. PetersburgConspiracy to commit and aid and abet computer fraud, wire fraud conspiracy, wire fraud, money laundering conspiracy; deliberate shielding of customers from law enforcement demands and takedowns$62 million in proceeds from attacks on dozens of US businesses across more than 20 states. Indictment returned under seal 5 December 2024, Case 1:24-CR-001161, N.D. Ohio, unsealed 14 July 2026 under Operation Riptide. Rewards for Justice offering up to $10 millionMedium

Three observations. First, the 13 July package is the EU's largest-ever cyber sanctions round and, per High Representative Kaja Kallas, its biggest round of individual designations since the 2022 full-scale invasion. Second, it confirms a deliberate shift from designating operators to designating the enabler tier: VPN providers, malware-as-a-service developers, bulletproof hosting, and cryptor developers were all named in a single coordinated action. Third, the 1VPNS designation follows a repeatable and fast evidentiary model, building on on-chain payment traces from named ransomware operators to the enabler rather than on victim-impact attribution, which is substantially slower to assemble. CONFIRMED.

Financial Flow Observations

Infrastructure Hosting Patterns

SECTION 7 - LAW ENFORCEMENT AND REGULATORY ACTIONS

New Actions This Month

OperationLead AgenciesDateOutcomeImpact
Stokes extradition (Scattered Spider)US DOJ, Northern District of Illinois, with Finland1 July 2026Peter Stokes extradited from Finland and detained pending trial. Approximately $8 million extortion attempt across 100-plus intrusions. In US custodyMedium-High
Tri-lateral cyber sanctions packageEU Council, UK FCDO, US Treasury OFAC13 July 202637 designations across three jurisdictions (EU 9 individuals plus 4 entities; UK 24; OFAC 3). Stern named for the first time; LummaC2 developers, Media Land, GRU Unit 29155, CARR and Z-Pentest designated. EU's largest-ever cyber package. No arrestsHigh
Martino sentencing (BlackCat / ALPHV)US DOJ Criminal Division10 July 202670 months' imprisonment for a serving ransomware negotiator who sold client negotiation strategy and insurance limits to BlackCat across five victim cases. $10 million in assets seized. Restitution hearing set for 17 SeptemberMedium
NetNut / Popa disruptionGoogle GTIG, FBI, IRS, Lumen Technologies, Shadowserver Foundation2 to 3 July 2026At least 2 million infected devices cut off; netnut.com, proxyjet.io and divinetworks.com seized; C2 accounts and services on Google infrastructure disabled; SDK flagged in Play Protect. No arrests reportedHigh
INTERPOL Operation First Light 2026INTERPOL, 97 countries and territoriesOperation 15 Jan to 30 Apr 2026; results announced 9 July 20265,811 arrests; $293 million intercepted; 31,014 bank accounts blocked; 15,606 suspects identified; 142,000-plus victims identified; 152,808 cases analysedMedium
OFAC designation of 1VPNSUS Treasury OFAC, coordinated with UK FCDO13 July 2026Three designations (one entity, two individuals); all US-jurisdiction property and interests frozen; follows the May 2026 Operation Saffron takedown of the 1VPNS websiteMedium-High
Media Land / ML.Cloud indictmentUS DOJ; State Department Rewards for JusticeUnsealed 14 to 15 July 2026Three Russian nationals and two companies charged; $62 million in proceeds alleged; up to $10 million reward offered. No arrests; all defendants in RussiaMedium
Operation Olympus Blade (Kratos / Sneaky2FA)Germany BKA and ZIT with US authorities and Indonesian police; Trend Micro intelligence support20 July 2026More than 200 servers shut down; platform fully offline; developer and technical administrator arrested in Indonesia; 1,800-plus subscriber base disruptedMedium-High

Impact rationales. The Stokes extradition is scored Medium-High because it is a completed transfer into custody of a named individual, the outcome this series most often lacks, though it reaches an English-speaking Scattered Spider subject rather than a Russia-based operator. The tri-lateral package is scored High because it names the ecosystem's most financially significant identified operator for the first time and simultaneously covers four enabler categories across three jurisdictions, which closes the forum-shopping gaps that single-jurisdiction designations leave open. NetNut is scored High because the anonymization layer is cross-cutting: 316 distinct threat clusters were observed using it in a single week, spanning criminal and espionage actors. Olympus Blade is scored Medium-High as the only July action combining infrastructure removal with the arrest of a principal. The 1VPNS designation is scored Medium-High because it establishes a repeatable evidentiary model and reaches a Ukrainian subject in a cooperating jurisdiction. The Martino sentencing is scored Medium: it is a custodial result with $10 million recovered, but it addresses an insider failure mode rather than reducing adversary capacity. The Media Land indictment is scored Medium on its own because it carries no custodial or infrastructure-seizure component, though in combination with the EU designation of the same individual one day earlier its practical effect is greater. First Light is scored Medium for ransomware specifically because its focus was social engineering fraud and associated laundering, though its impact on the broader fraud ecosystem is High.

Reconstitution Status Tracker

Prior-cycle actions updated at 30, 90 and 180-day intervals. Status options: Fully Reconstituted, Partially Reconstituted, Not Reconstituted, Pending, No Data.

OperationAction DateTargetAction Type30-Day90-Day180-Day
RAMP forum seizure28 Jan 2026RAMP forumSeizedDarkDarkNot Reconstituted (184 days; suspected admin publicly declined to rebuild)
LeakBase seizureMar 2026LeakBaseSeizedNot ReconstitutedNot ReconstitutedPending (~150 days)
BKA REvil warrants6 Apr 2026REvil / GandCrab operatorsWarrantsNo arrestNo arrestPending (~117 days)
Stark / Dutch FIOD18 to 27 May 2026Stark BPH~800 servers seizedPartially Reconstituted (successor claim remains unverified)Pending (~70 days)Pending
Operation Saffron19 to 20 May 20261vpns anonymization33 servers seizedNot ReconstitutedNot Reconstituted (~73 days); reinforced by the 13 July OFAC designationPending
AudiA6 takedown10 Jun 2026Laundering serviceSeized; 2 arrestsNot ReconstitutedPending (~52 days)Pending
Operation Endgame (StealC / Amadey / SocGholish)15 to 24 Jun 2026Stealer and loader infrastructure326 servers, 142 domainsNo confirmed C2 re-emergence in retrieved sources (~45 days)PendingPending
NetNut / Popa disruption2 to 3 Jul 2026Residential proxy, 2M devicesDomains seized, C2 disabledPending (~29 days)PendingPending
Media Land indictment14 Jul 2026BPH providerIndictment onlyPending (~18 days); no infrastructure seizure componentPendingPending
Operation Olympus Blade20 Jul 2026Kratos PhaaS200+ servers; 1 arrestPending (~12 days)PendingPending
Lumma Stealer takedownMay 2025Lumma C2 (2,300 domains)SeizedPastPastFully Reconstituted

Cumulative Impact Assessment

Short-term disruption (1 to 30 days): High. Six enablement layers were removed, degraded or designated inside nineteen days: anonymization, phishing-as-a-service, VPN concealment, cryptor services, malware-as-a-service and bulletproof hosting. The measurable capacity removed is substantial and specific: at least 2 million proxy nodes serving 316 observed threat clusters, a PhaaS platform running roughly 15,000 campaigns per month for 1,800 subscribers, a VPN service with traced payments from three named ransomware operators, and $131 million in stablecoins frozen at the issuer within a day of designation. Thirty-seven designations landed across three jurisdictions on a single day, plus one custodial sentence and one arrest.

Custodial outcomes. July produced two, which is unusual for this series and revises the standing assessment that enforcement reaches infrastructure but not people. Peter Stokes was extradited from Finland into US custody on 1 July. Angelo Martino was sentenced to 70 months on 10 July with $10 million in assets recovered. A third, the Kratos developer, was arrested in Indonesia on 20 July. Set against that, every Russia-based principal named during the month remains beyond reach.

Structural ecosystem impact (90-plus days): Medium-High, revised upward from the prior cycle. Two factors raise the score. First, the tri-lateral coordination closes jurisdictional gaps that single-authority designations leave open, and naming Stern removes the pseudonymity that has protected the Trickbot syndicate's most senior figure for a decade. Second, the Iran Central Bank action proves that issuer-level stablecoin freezing converts designation into immediate asset denial at nine-figure scale, which no infrastructure seizure in this series has achieved. Three factors hold it below High. Reconstitution history remains unfavourable, with Lumma fully reconstituted and now assessed to lead 2026 distribution even as its developers are designated, which shows designation alone does not remove capability. Mandiant's on-record assessment that disrupting one proxy service converts competitors into resellers means the NetNut action displaces capacity rather than removing it. And every Russia-based principal named in July, Kovalev, Volosovik, Zatolokin, Pankova, Voronin, Gordienko and Bashev, remains beyond custodial reach. The actions with the highest probability of durable structural results are the two that reach cooperating or domestic jurisdictions: the 1VPNS designation of a Ukrainian administrator, and the Martino sentencing. ANALYST INFERENCE, medium confidence.

SECTION 8 - VULNERABILITY EXPLOITATION MATRIX

CVEs with confirmed exploitation during the reporting period, cross-referenced against the CISA KEV catalog. All cisa.gov fetches returned empty bodies during collection (see Section 13); KEV facts are corroborated through Security Affairs, The Hacker News and Help Net Security.

CVEProductCVSSExploitation MethodThreat ActorScale / VolumeCISA KEVKEV Date
CVE-2026-45659Microsoft SharePoint Server8.8Deserialization of untrusted data to RCE; authenticated attacker with Site Member rightsJuly activity not attributed. Storm-2603 (Warlock) known for SharePoint exploitation since mid-2025Not quantifiedYes1 Jul 2026; due 4 Jul
CVE-2026-48282Adobe ColdFusion10.0Path traversal to unauthenticated arbitrary code executionNot attributed. First exploitation from 103.207.14[.]220Exploited under 2 hours after public disclosureYes7 Jul 2026; due 10 Jul
CVE-2026-56290Joomlack Page Builder CK10.0Improper access control to web shell installationNot attributedLive web shell on a production Joomla site within hours of the 27 Jun fixYes7 Jul 2026; due 10 Jul
CVE-2026-48908JoomShaper SP Page Builder10.0Unrestricted file upload to PHP execution and admin account creationNot attributedNot quantifiedYes7 Jul 2026; due 10 Jul
CVE-2026-55255Langflow6.1 CISA / 9.9 SysdigAuthorization bypass via user-controlled key; chained with CVE-2026-33017 for RCEFinancially motivated cluster, botnet or cryptojacking orientedExploitation 22 to 25 Jun; first active exploitation 25 JunYes7 Jul 2026; due 10 Jul
CVE-2026-16232Check Point Security Mgmt / Multi-DomainCritical auth bypassUnauthenticated login-token retrieval, then SmartConsole login with full admin rights and policy modificationNot attributed. Check Point published attacker IPsA handful of customers confirmed affected and notifiedYesDue 25 Jul 2026
CVE-2025-3248Langflow9.8Missing authentication on the code validation endpoint; unauthenticated Python executionJADEPUFFER (agentic ransomware)One documented operation; 600+ payloads; 1,342 config items encryptedYesMay 2025

Lag analysis. The reporting period contains both extremes of the KEV-to-exploitation interval. CVE-2025-3248 was KEV-listed in May 2025 and used as the entry point for the first documented agentic ransomware operation disclosed on 1 July 2026, a gap of roughly fourteen months. CVE-2026-48282 inverts it entirely, with exploitation beginning under two hours after public disclosure. Sysdig's assessment explains why both are now dangerous simultaneously: agentic tooling makes spraying the entire historical vulnerability catalogue effectively free, so the long tail of unpatched systems becomes more exposed over time rather than less. The operational implication is that KEV age is no longer a useful triage input for exposed internet-facing assets.

SECTION 9 - SUPPLY CHAIN AND THIRD-PARTY COMPROMISE

ShinyHunters OAuth and Identity Abuse (SaaS supply chain)

JADEPUFFER (AI orchestration platform as supply-chain entry)

Trend Assessment

Supply chain attacks as a percentage of total incidents: no reliable July figure is available, and none was published in the retrieved reporting. What is verifiable is a structural characterisation rather than a percentage. Black Kite's April 2025 to March 2026 dataset finds that third-party services including SaaS platforms, ERP systems, CRM applications, OAuth tokens, remote access tools and connected business software have become common attack paths, and that organizations with strong internal controls remain exposed through them. The July evidence supports a specific refinement of that finding: the two documented supply-chain vectors this month, OAuth token abuse and AI orchestration compromise, both bypass the vulnerability model entirely. Neither the ShinyHunters Abbott intrusion nor the Langflow credential harvest depended on exploiting the trusted platform. They depended on the trust relationship itself, and on credentials stored in an adjacent service. Patching does not close either path. CREDIBLE REPORTING with an explicit quantification gap.

SECTION 10 - ECOSYSTEM CONTROL NODE ANALYSIS

Top Control Nodes Table

RankNodeTypeEstimated Ecosystem ReachDependenciesSPOF?Disruption Difficulty
1Stablecoin issuance and crypto cashout layerCrypto Laundry$820M in on-chain ransomware payments in 2025. Demonstrated chokepoint: Tether froze $131M within a day of the 14 to 15 July CBI designation, with cumulative freezes near $475M. ConfirmedA single dominant issuer's compliance function; exchange on and off-ramps; correspondent bankingYes for USDT-denominated flowsMedium, revised down. Issuer cooperation is proven and fast
1bVictim-side negotiation and incident response layerOtherCoveware Q2: average payment $1.88M across a shrinking payer population. Martino case: one negotiator compromised five victim cases and $10M in assets recovered. ConfirmedProfessional licensing, insurer panels, employer vetting at IR firmsNoLow. Domestic, regulated, and reachable by subpoena
2Infostealer-to-IAB credential pipelineIAB MarketAverage access price collapsed to $439 from $1,427 on log oversupply; IAB inflow spikes precede payment spikes by ~30 days. Estimate, high confidenceMaaS operators, Telegram distribution channels, ClickFix delivery clustersNoExtreme (fully decentralized)
3Residential proxy and anonymization layerBPH / OtherNetNut alone at 2M+ devices with 316 distinct threat clusters observed in one June week. Confirmed for NetNut, estimate for the layerConsumer device supply chain, SDK distribution, reseller whitelabeling agreementsNo (reseller mesh)High (reconstitutes by substitution)
4The Gentlemen RaaSRaaS Platform18.3% of leak-site posts in the final week of July; 238 Q2 victims; 94 June victims. Confirmed per trackerAffiliate pool; 90/10 split economics; leak-site infrastructurePartialMedium (operator identity previously exposed)
5Qilin RaaSRaaS Platform14% of all Q2 2026 victims (301); 41 healthcare-provider claims in H1. Confirmed per sourceSame affiliate pool; RAMP dispute resolution no longer existsPartialHigh (no acting jurisdiction)
6Phishing-as-a-service (Kratos successor market)Stealer / PhaaS ServiceKratos: 1,800+ subscribers and ~15,000 campaigns per month prior to the 20 July takedown. ConfirmedAiTM kit development talent, Telegram sales channels, domain supplyPartialMedium (twice disrupted, twice rebranded)
7Bulletproof hosting (Media Land / ML.Cloud tier)BPH Provider$62M in charged US losses; LockBit, BlackSuit and Play named as tenants. ConfirmedUpstream transit carriers, RIR resources, corporate formation agentsNoHigh (Russian jurisdiction)
8Enterprise edge and management planeOtherSix KEV additions in July across ColdFusion, SharePoint, Check Point, Langflow and two Joomla builders. ConfirmedVendor patch cadence; exposure of management interfaces to the internetNoLow (defender-side remediable)
9DarkForums and private Telegram (post-RAMP forum layer)ForumRAMP and BreachForums both non-operational; migration concentrated on DarkForums and Telegram. Credible reportingHosting, administrator OPSEC, reputation escrowPartialMedium (RAMP precedent shows durable denial is achievable)
10Agentic attack toolingOtherOne documented end-to-end agentic ransomware operation with 600+ payloads. Confirmed, single caseLLM API access, or stolen compute via LLMjackingNoExtreme (dual-use, commercially available)

Cascade Failure Analysis

Node 2, infostealer-to-IAB credential pipeline. What breaks downstream: the credential supply that sets affiliate operating cost. The measurable effect of this node functioning well is that corporate access now averages $439 against $1,427 three years ago, a 69 percent reduction in the entry cost of a ransomware operation. Remove it and affiliate unit economics invert immediately, because the 58-to-1 return ratio between ransomware payments and IAB spend collapses when access has to be earned rather than bought. Realistic reconstitution timeline: weeks. Lumma reconstituted within weeks of a takedown that removed 2,300 domains and now leads 2026 distribution. Enforcement mechanism that could realistically work: none in single-strike form. The only demonstrated approach is repeated coordinated action on the Operation Endgame model, treating each strike as one increment of sustained cost rather than a terminal event. Chainalysis's finding that IAB inflow spikes lead payment spikes by 30 days also means this node offers the ecosystem's best early-warning telemetry, which is an intelligence value independent of any disruption value.

Node 3, residential proxy and anonymization layer. What breaks downstream: attribution resistance for every actor category simultaneously. In a single week, 316 distinct threat clusters spanning criminal and espionage operations routed through one provider. Remove it and password-spray campaigns, victim-environment access and operator infrastructure management all lose their residential-IP cover at once. Realistic reconstitution timeline: 30 to 60 days, and by substitution rather than rebuild. Mandiant states directly that disrupting one proxy service prompts operators to buy replacement capacity from competitors, converting those competitors into resellers, because the industry is built on mutual capacity trading. Enforcement mechanism that could realistically work: simultaneous rather than sequential action against the reseller and whitelabel tier. Taking the largest provider offline while its whitelabel partners remain operational transfers customers instead of denying capacity.

Nodes 4 and 5 treated jointly, the RaaS affiliate labour market. What breaks downstream: nothing durable, and that is the finding. The number one position changed hands in June because a former Qilin affiliate offered a 90/10 split after a payout dispute, not because of superior tooling. Halcyon assesses roughly half the names on any given month's top-15 list were absent the month before. Removing either platform displaces its affiliates into the competing platform within weeks, which is precisely what the June transition demonstrated in reverse. Realistic reconstitution timeline: weeks, and it is not reconstitution, it is migration. Enforcement mechanism that could realistically work: nothing targeting the platforms. The mechanism that would work targets affiliate expected value directly, meaning the payment layer, which is Node 1 and the subject of Section 11.

Structural Vulnerability Summary

The single most critical structural weakness in the current ecosystem is the payment layer, and July produced the first direct proof of it. Every other node reconstitutes by substitution: proxies by reseller transfer within 30 to 60 days, stealers within weeks, RaaS platforms by affiliate migration in the same cycle they are disrupted, bulletproof hosting by re-registration under Russian jurisdiction. LummaC2 makes the point sharply, remaining operational and assessed as a 2026 distribution leader on the same day its named developers were designated by the EU. The payment layer does not substitute, because it is the only node that must interface with the regulated financial system to convert extortion into value, and on 14 to 15 July Tether froze $131 million within a day of an OFAC designation, taking cumulative freezes against those addresses to nearly $475 million. No infrastructure seizure in this reporting series has produced comparable denial on comparable timescales. Coveware's Q2 data shows the layer is already under strain from the other direction: the payment rate is at a record low, exfiltration-only extortion converts at 15 percent, and the ecosystem's revenue now flows through a shrinking population of transactions averaging $1.88 million. That concentration is a vulnerability, not a strength, because a small number of large traceable payments is a far more tractable enforcement surface than a large number of small ones. The Martino case exposes the adjacent weakness: the professional layer advising victims through those transactions is domestic, licensed and reachable, and it has now been shown to be corruptible. The ecosystem is most brittle where extorted value converts to spendable funds, and least brittle at the infrastructure and platform layers where the majority of July's operational effort was directed.

SECTION 11 - STRATEGIC LEVERAGE ASSESSMENT

Financial Pressure

TARGET Ransom payment intermediation: negotiation firms, incident response providers, cyber insurers and exchange off-ramps servicing extortion proceeds above $1 million.

CONDITION Coveware Q2 2026 records a record-low overall payment rate with average payments at $1.88 million, up 176 percent quarter over quarter, and a median of $150,000. The revenue of the entire ecosystem now passes through a small, countable population of large transactions. On 10 July a serving negotiator at a US incident response firm was sentenced to 70 months for selling client insurance limits and negotiation strategy to BlackCat across five victim cases, with $10 million in assets seized.

THRESHOLD THRESHOLD MET twice over. The divergence between a rising average and a falling median confirms revenue concentration into a tractable number of transactions, and the Martino conviction confirms the intermediation layer is already penetrated.

ACTION Impose a mandatory 72-hour on-chain destination reporting requirement on any single extortion payment above $1 million, applied at the negotiation and payment-facilitation layer rather than the victim. Pair it with a licensing and background-vetting regime for ransomware negotiators, and require disclosure to the victim of any prior contact between the negotiator and the threat actor.

WINDOW Two to three quarters, before operators adapt by fragmenting demands below the reporting threshold.

PRIORITY Critical

TARGET Dominant stablecoin issuer compliance channel, and the upstream counterparties feeding designated addresses.

CONDITION Tether froze $131 million within a day of the 14 to 15 July Central Bank of Iran designation update, with cumulative freezes against those addresses approaching $475 million. Chainalysis identified the upstream counterparties for the newly designated wallets as an institutional liquidity provider and an Asia-based payment processor.

THRESHOLD THRESHOLD MET. Issuer-level freezing has been executed at nine-figure scale within a 24-hour window and the upstream counterparties are already identified on-chain.

ACTION Extend the same designate-then-freeze sequence to ransomware-attributed wallet clusters rather than reserving it for state-nexus targets, and designate the identified institutional liquidity provider and Asia-based payment processor to close the funding path rather than only the destination.

WINDOW Open now. Narrows as illicit flows migrate to issuers with weaker compliance functions or to non-custodial rails.

PRIORITY Critical

TARGET On-chain payment traces from named ransomware operators to enabler services, replicating the 1VPNS evidentiary model.

CONDITION TRM Labs traced Anubis payments in December 2025 and March 2026, a Qilin payment of $120 in January 2026 and a Sinobi payment of $58 in February 2026 directly to 1VPNS, and those traces underpinned the 13 July designation.

THRESHOLD THRESHOLD MET. The model has been executed once and the evidentiary pathway is proven; the trigger for each subsequent action is the existence of an operator-to-enabler payment trace, not the assembly of victim-impact evidence.

ACTION Designate the next three enabler services for which operator payment traces already exist, building each action on payment evidence rather than victim harm, which shortens the evidentiary timeline by quarters.

WINDOW Open now; narrows as enablers migrate to Monero and non-custodial rails.

PRIORITY High

Infrastructure Pressure

TARGET NetNut whitelabel resellers and capacity-trading partners.

CONDITION GTIG notes NetNut operated a robust reseller program allowing whitelabeling of its network, and Mandiant states that disrupting one proxy service prompts operators to purchase replacement capacity from competitors, turning those competitors into resellers.

THRESHOLD First confirmed migration of identified NetNut customers to a named competing proxy brand.

ACTION Identify the top five NetNut whitelabel resellers now and seize their domains and disable their control infrastructure in a single simultaneous action timed to the migration, rather than sequentially as each surfaces.

WINDOW 30 to 60 days from the 2 to 3 July action, which is the observed substitution interval for this layer.

PRIORITY High

TARGET The successor adversary-in-the-middle phishing kit to Kratos, and the Telegram sales channels that carried it.

CONDITION Kratos was itself a rebrand of Sneaky2FA, which had operated since October 2024, and the takedown follows the March 2026 disruption of Tycoon 2FA. The AiTM PhaaS category has now rebranded or been disrupted twice inside eighteen months while retaining its subscriber base.

THRESHOLD First advertisement of a new AiTM kit on the Telegram channels that previously carried Kratos.

ACTION Seize the Telegram sales channels and subscriber records at first advertisement rather than waiting for infrastructure maturity. The 1,800-subscriber base, not the 200 servers, is the reconstitution asset.

WINDOW 60 to 90 days, based on the Sneaky2FA to Kratos rebrand interval.

PRIORITY High

TARGET Internet-exposed AI orchestration platforms, specifically Langflow and Alibaba Nacos instances.

CONDITION JADEPUFFER used CVE-2025-3248, KEV-listed since May 2025. CVE-2026-55255 and CVE-2026-33017 were exploited between 22 and 25 June. These hosts routinely hold LLM provider API keys and cloud credentials and are frequently deployed without network controls. Nacos ships an unchanged default JWT signing key publicly documented since 2020.

THRESHOLD THRESHOLD MET. Two Langflow CVEs are KEV-listed, one has a documented end-to-end ransomware outcome, and the Nacos default key is a known unremediated condition.

ACTION Extend binding KEV remediation to AI orchestration platforms as a named asset class, and run a Shadowserver-model notification sweep of internet-exposed Langflow and Nacos instances with direct victim notification.

WINDOW Immediate. Agentic tooling makes spraying the historical CVE catalogue effectively free, so exposure converts to compromise faster each cycle rather than decaying.

PRIORITY Critical

Jurisdictional Pressure

TARGET Dmytro Rashevskyi, Ukrainian national, administrator of 1VPNS.

CONDITION OFAC designated Rashevskyi on 13 July. Unlike the Russia-based principals in the Media Land indictment, he is in a jurisdiction with a demonstrated record of cybercrime cooperation, including the July 2025 action against the XSS administrator. His co-designee Silayev is Belarusian.

THRESHOLD THRESHOLD MET. A cooperating-jurisdiction nexus exists and the designation is already in force.

ACTION Convert the designation into a Ukrainian criminal referral with a request for arrest and device seizure, prioritising recovery of 1VPNS subscriber records, which would identify by name the ransomware groups that purchased concealment.

WINDOW 90 days before the subject relocates to a non-cooperating jurisdiction; the designation itself creates the relocation incentive.

PRIORITY Critical

TARGET Alexander Volosovik, Kirill Zatolokin and Yulia Pankova, and the corporate entities Media Land LLC and ML.Cloud LLC.

CONDITION Volosovik is now subject to three separate actions in eight months: OFAC designation November 2025, EU designation 13 July 2026, DOJ indictment unsealed 14 July 2026, alleging $62 million in proceeds with a Rewards for Justice offer of up to $10 million. Media Land has served LockBit, EvilCorp and BlackBasta since 2016. All three defendants reside in St. Petersburg and extradition from Russia is not realistically available.

THRESHOLD THRESHOLD MET for the non-custodial elements. Triple designation across two jurisdictions plus a standing reward is the trigger for travel interdiction and corporate measures.

ACTION Circulate provisional arrest requests to third countries with US diplomatic agreements that these defendants have previously travelled to, and place both corporate entities on procurement and payment-processor deny lists across Five Eyes and EU jurisdictions to force successor registration into the open. Task the upstream transit carriers serving Media Land prefixes with termination notices citing the EU designation, which reaches European carriers that the US designation alone did not.

WINDOW Indefinite for arrest; 30 to 90 days for the corporate deny-list and carrier-notice action before successor entities are registered under new names.

PRIORITY High

TARGET Third-country interdiction coverage for CIS-national cybercrime subjects.

CONDITION The Russian MFA has published its own list of jurisdictions where it assesses US detention capability as effective and has advised citizens to avoid them: much of Europe and Latin America, plus Australia, Canada, Armenia, Israel, the Maldives, South Korea, Singapore, Thailand, Fiji, Sri Lanka, Liberia and Morocco. The Stokes extradition from Finland on 1 July demonstrates the mechanism completing. Read in reverse, the advisory is the adversary enumerating for its own criminal diaspora exactly where interdiction works.

THRESHOLD THRESHOLD MET. The list is published and one extradition completed inside the reporting month.

ACTION Prioritise provisional arrest request coverage across the named jurisdictions, and open liaison with jurisdictions conspicuously absent from the list before subjects relocate to them. Armenia's inclusion despite CSTO membership and Serbia's absence are the two most actionable anomalies.

WINDOW Open now. Degrades as subjects redistribute toward unlisted jurisdictions, which the advisory itself will accelerate.

PRIORITY High

TARGET Vitaly Nikolayevich Kovalev, alias Stern.

CONDITION EU-designated 13 July as senior administrator of the Trickbot and Conti syndicate, with wallets receiving more than $300 million as a personal cut. First public attribution of the Stern moniker to Kovalev by a sanctioning body, following BKA identification in 2025 and OFAC and OFSI designations in February 2023. Chainalysis Reactor maps his transactions across Ryuk, Conti, Diavol, Karakurt, Royal, 3am, Quantum and Bitpaymer.

THRESHOLD THRESHOLD MET. Public moniker-to-name attribution is the trigger, and it has now occurred across three jurisdictions.

ACTION Publish the wallet clusters underpinning the $300 million figure to enable exchange-level screening, and use the cross-strain transaction map to designate the downstream affiliates and service providers he paid, converting one designation into a network action against the 19-member sanctioned Trickbot cohort's remaining unsanctioned counterparties.

WINDOW 12 to 24 months. Historical wallet clusters do not decay, so this window is unusually long, but attribution value falls once the cohort migrates to new infrastructure.

PRIORITY High

Coming Month Focus (Top 3)

1. Apply the designate-then-freeze sequence proven against the Central Bank of Iran to ransomware-attributed wallet clusters, starting with the Stern clusters published in the 13 July EU designation. Expected outcome: nine-figure asset denial on a 24-hour timeline, replicating the $131 million Tether freeze, against a target set where the wallet attribution is already complete and public. This is the highest expected-value action available because it requires no new investigation and no foreign cooperation.

2. Pursue Rashevskyi through a Ukrainian criminal referral and seek seizure of 1VPNS subscriber records. Expected outcome: the first custodial result against a named ransomware enabler in this reporting series, and a subscriber list identifying the ransomware operations that purchased concealment, converting a single designation into a multi-target evidentiary base.

3. Pre-position the simultaneous NetNut reseller and whitelabel takedown inside the 30-to-60-day substitution window. Expected outcome: denial of replacement proxy capacity rather than transfer of it, producing the first measurable net reduction in available anonymization supply rather than a redistribution among providers.

SECTION 12 - UNCONFIRMED SIGNALS AND HORIZON INDICATORS

[UNCONFIRMED REPORTING] AsyncAPI npm organization compromise, 14 July 2026. Five package versions across four package names were reportedly republished within roughly ninety minutes, each carrying the same injected loader, with an actor identifying as TeamPCP claiming credit. The Microsoft Threat Intelligence primary post was not retrieved during collection and no downstream install count is available.

Confirm via: retrieval of the Microsoft Security Blog post and an npm advisory carrying affected-version download counts.

[UNCONFIRMED REPORTING] A malicious jscrambler npm package, version 8.14.0, reportedly reached the registry on 11 July carrying a preinstall hook that dropped a Rust infostealer on Windows, macOS and Linux, targeting cloud credentials and CI tokens.

Confirm via: an npm security advisory or a vendor writeup with affected-version download figures.

[UNCONFIRMED REPORTING] Q2 2026 initial-access telemetry placing phishing at 65 percent of intrusions. The figure surfaced in collection but the primary quarterly dataset was not retrievable, so it is excluded from the Section 4 ranking.

Confirm via: a retrievable ReliaQuest or LevelBlue Q2 2026 dataset with methodology.

[RESOLVED, RE-DATED] The Spanish arrest of an individual linked to CARR, Z-Pentest and NoName057(16) is substantively confirmed but is a July disclosure of a March 2026 action, not a July arrest. The investigation opened in August 2025 on an FBI tip; the arrest took place in Palencia in March 2026; reporting appeared 7 July 2026. The suspect allegedly provided logistical and operational support to a Ukrainian hacker operating for CARR and attempted to facilitate that hacker's escape to Russia via Poland and Belarus. Charges include membership of and collaboration with a terrorist organisation. The case sits under Operation Riptide. Significance is higher than first assessed: the EU designated both CARR and Z-Pentest on 13 July, pairing designation with custody against the same network inside one quarter.

Status: CREDIBLE REPORTING. Corroborated across five named outlets at search level; primary not yet fetched. Verification pending next cycle.

[UNCONFIRMED REPORTING] Medtronic reportedly notified 3.8 million individuals following a ShinyHunters breach. Headline-level verification only. If accurate, this materially raises the assessed downstream impact of the ShinyHunters identity-abuse campaign described in Section 9.

Confirm via: an HHS OCR breach portal entry with the affected-individual count.

[ANALYST INFERENCE] The final-week volume surge (240 posts, up 40.4 percent) may reflect three new entrants front-loading their leak sites to attract affiliates rather than a genuine rise in compromises. Global Secret Group, Booba Team and Exfilsquad accounted for 54 of the 240 posts, or 22.5 percent, on their debut week.

Refute via: August post volume from the same three groups. A debut spike that decays within one month is an affiliate-recruitment signal; one that sustains indicates real capacity.

[ANALYST INFERENCE] The 15 percent exfiltration-only payment rate indicates the encryption-free extortion model has reached a monetization ceiling. If confirmed, expect partial reversion to encryption among volume-oriented groups while extortion-only consolidates among actors targeting verticals with heavy regulatory exposure.

Confirm or refute via: the Coveware Q3 2026 exfiltration-only payment rate and Unit 42's updated encryption-use percentage. A Q3 figure below 15 percent confirms; above 20 percent refutes.

[ANALYST INFERENCE] Early warning for August: expect a second documented agentic ransomware operation, and expect StealC or Amadey command-and-control re-emergence at the 60-to-90-day mark from the June Operation Endgame action, which falls between mid-August and late September.

Confirm via: new C2 telemetry attributed to those families on fresh infrastructure, and vendor disclosure of a second LLM-driven end-to-end intrusion chain. Sysdig has already published a JADEPUFFER follow-on describing ransomware built to destroy AI models, which suggests the case count is already moving.

[ANALYST INFERENCE] Qilin's 44.7 percent week-over-week decline at month-end may mark a durable position change rather than cadence variance. The group held the top position for five consecutive quarters and lost it in June on affiliate economics, and the RAMP forum that once arbitrated its affiliate disputes no longer exists.

Confirm via: August and September monthly counts. Two further consecutive months below The Gentlemen confirms a structural shift; recovery within one month indicates variance.

SECTION 13 - ANALYTIC CAVEATS AND COLLECTION GAPS

Sources Blocked or Dropped During Verification

Data Unavailable or Unreliable This Cycle

Known Inflation and Deflation Biases in Victim Count Data

Competing Explanations for Major Observed Trends

Sections Omitted

No sections were omitted. All thirteen standing sections met the minimum data threshold, with explicit no-reliable-data notation applied wherever July-specific figures were unavailable rather than substituting hedged language.

Publication note: this is the published edition of the July 2026 cycle. It carries the full analytic content, figures, confidence labels and source list, together with a supplementary pass dated 2 August 2026 covering the Stokes extradition, the full 13 July designee roster including the Rybar tranche, and the Aeza pretrial-detention datapoint.

SOURCES

Every URL below was retrieved by direct fetch during verification. URLs that failed retrieval are listed in Section 13 and appear nowhere in the report body.

Ransomware Tracking Platforms

RansomLook - open ransomware intelligence, live post and group statistics - https://www.ransomlook.io

Ransomware.live - 2026 statistics, active groups and new-group registry - https://www.ransomware.live/stats/2026

Comparitech - Healthcare Ransomware Roundup, H1 2026 - https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/

Government and Law Enforcement

US Treasury - Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans, 13 July 2026 - https://home.treasury.gov/news/press-releases/sb0559

OFAC - Recent Actions index - https://ofac.treasury.gov/recent-actions

TechCrunch - US charges Russian bulletproof web hosts over cyberattacks that netted $62M, 15 July 2026 - https://techcrunch.com/2026/07/15/us-charges-russian-bulletproof-web-hosts-over-cyberattacks-that-netted-62m-from-cybercrime-victims/

Security Affairs - INTERPOL Operation First Light nets 5,811 arrests and seizes $293 million, 9 July 2026 - https://securityaffairs.com/195056/security/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million.html

Security Affairs - Former ransomware negotiator sentenced to 70 months for secretly helping the BlackCat gang, 10 July 2026 - https://securityaffairs.com/195081/cyber-crime/former-ransomware-negotiator-sentenced-to-70-months-in-prison-for-secretly-helping-blackcat-gang.html

Vendor Threat Intelligence

Sysdig - JADEPUFFER: Agentic ransomware for automated database extortion, 1 July 2026 - https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

Trend Micro - Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, 22 July 2026 - https://www.trendmicro.com/en_us/research/26/g/kratos-takedown.html

Halcyon - Why The Gentlemen Beat Qilin: A Lesson in Ransomware Affiliate Economics, 14 July 2026 - https://www.halcyon.ai/blog/why-the-gentlemen-beat-qilin-a-lesson-in-ransomware-affiliate-economics

GuidePoint Security - Ransomware Insights from Q2 2026 (GRIT Q2 2026 Report), 9 July 2026 - https://www.guidepointsecurity.com/blog/ransomware-insights-q2-2026/

Cybersecurity News

The Hacker News - SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation, 2 July 2026 - https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html

The Hacker News - ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files, 17 July 2026 - https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html

Security Affairs - CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow and JoomShaper SP Page Builder flaws to KEV, 8 July 2026 - https://securityaffairs.com/194927/hacking/u-s-cisa-adds-adobe-coldfusion-joomlack-page-builder-langflow-and-joomshaper-sp-page-builder-flaws-to-its-known-exploited-vulnerabilities-catalog.html

Help Net Security - Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232), 23 July 2026 - https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/

Help Net Security - Ransomware in 2026: More groups, more victims, no slowdown (Black Kite 2026 Ransomware Report), 24 July 2026 - https://www.helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report/

BleepingComputer - NetNut proxy network disrupted, 2 million infected devices cut off, 3 July 2026 - https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/

SWK Technologies - Cybersecurity News Recap July 2026 - https://www.swktech.com/swk-cybersecurity-news-recap-july-2026/

Financial Intelligence

Coveware by Veeam - Ransomware Payment Trends Q2 2026, 30 July 2026 - https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html

Chainalysis - Crypto Ransomware: 2026 Crypto Crime Report - https://www.chainalysis.com/blog/crypto-ransomware-2026/

Chainalysis - Stern, likely most prolific ransomware operator ever, sanctioned by EU, 14 July 2026 - https://www.chainalysis.com/blog/cyber-sanctions-trickbot-administrator-july-2026/

Chainalysis - OFAC sanctions Iran Central Bank crypto wallets, freezing $131 million in stablecoins, 15 July 2026 - https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins/

Help Net Security - EU and UK blacklist Russia's cyber operators over efforts to destabilize Europe, 13 July 2026 - https://www.helpnetsecurity.com/2026/07/13/eu-uk-russia-cyber-activity-sanctions/

Infrastructure Intelligence

BleepingComputer - NetNut disruption, Google GTIG, FBI, Lumen and Shadowserver coordination detail - https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/

Chainalysis - infrastructure convergence between criminal and state-linked actors; bulletproof hosting and residential proxy analysis - https://www.chainalysis.com/blog/crypto-ransomware-2026/

END OF REPORT