Ransomware Gangs Vie for Cyber Supremacy
A rivalry between major threat actors is escalating, with data showing a surge in attacks targeting small businesses and large enterprises.
A high-stakes power struggle between prominent cybercrime syndicates is altering the threat landscape, as two groups compete to secure their dominance in the digital underworld. Data indicates that this tactical competition is resulting in a sharp rise in incident volume, disproportionately impacting smaller organizational structures while simultaneously drawing larger corporations into the crosshairs.
The Leaders of the Malware Race
Analysis of threat actor activity during the second quarter of 2026 highlights two primary organizations driving the current surge in malicious operations. By monitoring more than 200 threat actor blogs, researchers identified 2,581 distinct ransomware incidents during this period. The data reveals that Qilin and The Gentlemen are significantly outpacing other groups in frequency, with DragonForce trailing behind as the third most active entity.
While Qilin remains the most prolific actor overall, its operational pace saw a slight decline compared to the previous quarter. In contrast, The Gentlemen have ramped up their efforts, recording a 39% increase in activity during the April to June timeframe.
Data on the 2026 Ransomware Landscape
- Total ransomware attacks in Q2 2026: 2,581
- Attacks attributed to Qilin: 299
- Attacks attributed to The Gentlemen: 284
- Attacks attributed to DragonForce: 147
- US-based SMBs affected: 769
- Percentage increase in attacks against $1 billion+ revenue enterprises: 74%
Escalating Risks for Smaller Businesses
Small and medium-sized businesses continue to bear the brunt of these campaigns. These organizations, typically characterized by having fewer than 200 employees and annual revenues under $25 million, recorded 769 incidents in the United States alone. Other regions, including Canada, Germany, and the UK, also reported significant attack counts, though at a lower volume than the US.
Security researchers suggest that these smaller targets remain attractive due to perceived deficiencies in their defensive infrastructure. By selecting organizations with less robust security postures, attackers can maximize their success rates.
Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack.
— Vakaris Noreika, cybersecurity expert at NordStellar
The Pivot Toward Corporate Targets
The landscape is shifting as major enterprises with revenues exceeding $1 billion are increasingly targeted. Data shows these high-value organizations experienced 40 incidents in Q2, up from 23 in the first quarter, representing a 74% increase. Experts view this trend as a byproduct of the ongoing rivalry between threat groups, where large-scale breaches are used to solidify a group's standing.
This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.
— Vakaris Noreika, cybersecurity expert at NordStellar
Implications for Security Postures
This escalating competition suggests that organizational size may no longer be a reliable indicator of risk. As rival gangs seek higher-profile targets to boost their reputations, both large enterprises and smaller firms face a more volatile environment. For businesses, this suggests that the threshold for what constitutes a "high-value" target is evolving. The focus on reputation-building within the cybercriminal community implies that defensive strategies must account for attackers motivated by status as much as direct financial gain, potentially leading to more aggressive exploitation tactics regardless of the victim's scale.
Continue Reading
Estée Lauder Breach Tied to Oracle Flaw
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.
LLM-Assisted Phishing Kits Scale Attacks
Researchers uncovered an exposed server revealing how attackers use AI to industrialize the creation of malware delivery campaigns.
Cruciferra Crypter Evolves Malware Tactics
A sophisticated crypter service is leveraging process ghosting and kernel-driver abuse to cloak various commodity malware strains.
Sources
- TechRadar Original source