< Back to situation

[REVISION HISTORY]

AI-driven ransomware surge and evolving global threats

Updated 11 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-16 17:21 UTC → 2026-08-26 16:24 UTC · added removed

The ransomware landscape is undergoing a structural shift, characterized by an increase in active criminal groups and the integration of AI. The number of active groups rose from 71 to 93 in the second quarter of 2026. While the top 10 groups now account for a smaller share of victims (57.6%), total victims recorded on leak sites reached 2,139, a 33% year-over-year increase. Notably, the group ‘The Gentlemen’ saw 62% growth, with evidence suggesting AI coding assistants allow small teams to develop management panels in just days. Meanwhile, ransom payment rates have hit a multi-year low of approximately 23%. Qilin remains a prolific operator, but ‘The Gentlemen’ briefly overtook them in June. New technical threats are emerging, such as the DeadLock ransomware and the Aeternum botnet, both of which utilize the Polygon blockchain to create resilient command-and-control mechanisms that evade conventional takedowns. Specific threats continue to target critical infrastructure. The Gunra ransomware-as-a-service operation, also known as ‘Golden Community,’ has prompted a joint advisory from the FBI, CISA, NSA, and South Korea’s National Police Agency. Gunra, a Conti-derived operation, exploits Fortinet firewall and VPN vulnerabilities to target healthcare, financial, and government sectors. The group utilizes a double-extortion model, often demanding ransoms exceeding $10 million. Technical analysis revealed that Gunra can subvert multi-factor authentication by modifying virtual desktop infrastructure files through techniques such as session hijacking. This aligns with a broader trend in the Americas, where attackers are increasingly weaponizing edge infrastructure from providers like Ivanti, Cisco, and Palo Alto Networks to maximize pressure through high-leverage data exfiltration. Recent developments highlight the growing impact of AI, with 89% of surveyed financial providers reporting an increase in AI-driven attacks. These include automated phishing and ‘counter incident response’ tactics, where attackers delete logs to thwart security teams.

Versions

  1. 2026-08-26 16:24 UTC AI-driven ransomware surge and evolving global threats
  2. 2026-08-16 17:21 UTC AI-driven ransomware surge and evolving global threats
  3. 2026-08-15 00:06 UTC AI-driven ransomware surge and evolving global threats
  4. 2026-08-14 00:02 UTC AI-driven ransomware surge and evolving global threats
  5. 2026-08-13 14:32 UTC AI-driven ransomware surge and evolving global threats
  6. 2026-08-12 04:15 UTC AI-driven ransomware surge and evolving global threats
  7. 2026-08-12 00:34 UTC AI-driven ransomware surge and evolving global threats
  8. 2026-08-11 12:50 UTC AI-driven ransomware surge and evolving global threats
  9. 2026-08-11 08:53 UTC AI-driven ransomware surge and evolving global threats
  10. 2026-08-10 19:18 UTC AI-driven ransomware surge and evolving global threats
  11. 2026-08-01 14:47 UTC AI‑enhanced ransomware surge and policy response
  12. 2026-07-29 05:17 UTC AI‑enhanced ransomware surge and policy response

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.