Qilin, The Gentlemen, DragonForce, Akira, LockBit 5.0 and 84 other active groupshigh
Killing the antivirus is now the first move: what Q2 says about ransomware
On 27 July 2026 Halcyon published its Q2 2026 Ransomware Evolution Report. Claimed attacks fell 5.7% quarter on quarter — 1,988 across 101 countries, from 89 active groups — but the number that matters is a different one: shutting down endpoint detection tools before encryption starts is no longer a specialist capability, it is standard operating procedure. Some groups now build it directly into the attack chain. In parallel, DragonForce and Akira went from initial breach to ransomware deployment in under an hour. The figures come from attackers' public claims: read them as a trend, not as a census.
The minute you bought, and no longer have
Every investment in detection rests on a silent assumption: that between the moment an attacker does something anomalous and the moment encryption begins there is an interval. That interval is where all incident response lives: the alert that fires, the analyst who looks, the host that gets isolated.
Halcyon's quarterly report, published on 27 July 2026, describes an ecosystem that has learned to attack precisely that interval. The technique is called EDR-kill: disabling or blinding endpoint detection and response tooling before encryption starts. Until recently it was considered a specialist capability. Now, the analysts write, it is standard practice among leading groups — and some build it straight into the attack chain, as a planned step rather than an improvisation.
The quarter in numbers
The leaderboard by claims: Qilin 293, The Gentlemen 214, DragonForce 143, Akira 119, LockBit 5.0 102. DragonForce and LockBit 5.0 both picked up activity during the quarter; The Gentlemen overtook Qilin for the top spot in June. Among emerging — or returning — groups the report flags KryBit, Payload, PEAR and World Leaks.
The most targeted industry is manufacturing, at 19.8% of all extortion attacks, followed by construction, business services, retail and software. That is no surprise: these are environments where production downtime has an immediately calculable daily cost, which shortens the negotiation.
One figure deserves separate attention: in some attacks DragonForce and Akira moved from initial breach to ransomware deployment in under an hour. At that pace, the idea of a manual response starting the morning after a night-time alert no longer holds.
The Gentlemen: the group that studies other groups
The case Halcyon analyses in detail is The Gentlemen, recently emerged and quickly one of the most prolific threats. The interesting part is not the volume, it is the development method.
According to Halcyon's Ransomware Research Center, The Gentlemen's developers systematically reverse-engineer samples from other groups — Babuk, Qilin, LockBit 5.0, Medusa — to pick the strongest encryption routines, code obfuscation techniques and EDR evasion methods, and fold them into their own codebase.
Anyone who works in software will recognise the model: do not invent, integrate the best available. The defensive consequence is uncomfortable. A technique that works against one group does not stay confined to that group: it gets copied, and the window in which any defence is "new" shortens with every cycle.
Artificial intelligence, minus the marketing
The report devotes a section to AI, and it is worth reading precisely, because this is an area where exaggeration runs in both directions.
What the analysts describe is a shift from experimentation to operational use: malware disguised as AI productivity tools, AI-assisted victim negotiation, and what researchers believe to be the first agentic ransomware capable of autonomously conducting key stages of an intrusion. EvilAI is named specifically — LLM-developed, distributed as a fake AI productivity app, used to hand initial access to ransomware actors.
The report also flags something else: state-aligned actors disguising espionage campaigns as criminal ransomware operations. It is a rational choice — the noise of ordinary crime covers intelligence work well — and it makes attribution more fragile than the ransom note suggests.
The doors they come through
The vulnerabilities most exploited by ransomware groups during the quarter are, once again, in edge devices: Citrix NetScaler ADC and Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), FortiOS (CVE-2024-55591).
These are not new flaws. They are known flaws with patches available, on appliances that are by definition exposed to the internet and that frequently fall outside server patching cycles because "they are network gear". The perimeter is still the preferred entry point, and for exactly the same reason as two years ago.
- Initial accessAn unpatched edge device, or a purchased VPN credential.
- Before encryptionEDR-kill: detection is switched off or blinded.
- In some cases <1 hourFrom first breach to ransomware deployment.
- AfterwardsA claim on the leak site — which is also the only source of these numbers.
How to read these numbers properly
A clarification the report implies and that deserves to be said out loud: 1,988 are publicly claimed attacks, that is, attacks the groups posted on their own leak sites. It is not a census of attacks that happened.
Which means two things. Victims who pay quickly often never appear. And a 5.7% decline does not prove attacks are down: it may indicate a decline, but it may equally reflect a change in publication habits or in payment rates. Treating it as good news would be an optimistic reading of a figure that does not support one.
What changes for defenders
Halcyon's own specialists put it best: the democratisation of EDR-kill techniques and the generalisation of AI across the attack chain mean defenders can no longer assume traditional controls will buy them the time they need to respond.
In practice, three concrete shifts.
Treat EDR going dark as an incident, not a fault. An agent that stops reporting is not a maintenance ticket for Monday: in the attack model described here, it is the second-to-last step before encryption. You need an alarm on the absence of telemetry, not only on suspicious telemetry.
Move weight onto defences the attacker cannot reach from the endpoint. Immutable backups separated from the domain, logs shipped off-host in real time, segmentation that limits spread. These controls stay standing even after endpoint detection has been silenced.
Close the perimeter before anything else. The three most exploited CVEs of the quarter are on edge appliances with patches available. It is the least interesting part of this dossier, and it is still the part that decides most cases.
A note on sources: the numbers, rankings and qualitative assessments in this article come from Halcyon's quarterly report and its press coverage. They are single-vendor data, based on attackers' public claims: they describe an observed trend, not an absolute measure of the phenomenon.