Qilin, formerly Agenda, was the most prolific ransomware-as-a-service of H1 2026 with 641 claimed victims, including the Asahi brewery attack.
Jesse William McGraw
The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.
A 2026 OSINT methodology for pivoting from one malicious IP to a whole adversary cluster using favicon hashes, JARM fingerprints, and certificate transparency.
Initial Access Brokers (IABs) are the middlemen of the modern ransomware economy — specialists who break into corporate networks and resell that access to ransomware operators. We break down the marketplaces, the pricing tiers, the dominant brokers of 2026, and how to disrupt the chain.
Remote Desktop Protocol remains the single most-abused initial-access vector for ransomware operators in 2026. We break down the current attack patterns — credential stuffing, broker-sold access, BlueKeep-era CVE echoes, and weaponised RDS misconfigurations — and the controls that actually move the needle.
Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.
Through 2024 and 2025 a quiet rebalancing happened: password-phishing fell, session-cookie theft via infostealers surged, and “we have MFA” stopped meaning what defenders thought it meant. A 2026 field guide to the technique and the controls that actually answer it.
A 2026 attribution playbook for ransomware investigations — combining TTP fingerprinting against MITRE ATT&CK, ransom-note artifact analysis, leak-site monitoring, and the open-source intelligence pivots that hold up under scrutiny.
A 2026 practitioner walkthrough of Active Directory hardening against the lateral-movement, credential-theft, and persistence techniques that modern ransomware operators rely on — Tier 0 isolation, DSRM rotation, PRT theft mitigation, and AD audit baselines.
A 2026 self-doxxing tutorial — run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.