Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Attacks Surge as Qilin Targets Vulnerabilities

A brightly-lit office workspace with a computer workstation and blank screens.

"Kaspersky products blocked nearly 400 million attacks that originated with various online resources." That striking total frames an active quarter: Q2 2026 saw widespread, diverse malicious activity ranging from large-scale web exploitation to targeted ransomware operations and novel VM-based evasion techniques.

Scope and headline statistics: web, file, and local detections

Kaspersky’s telemetry shows 399,312,961 attacks blocked worldwide in Q2 2026. Web Anti‑Virus responded to 52,850,592 unique URLs, and File Anti‑Virus detected 16,986,351 malicious or potentially unwanted objects on endpoints and removable media. On average, 4.54% of users’ computers worldwide encountered at least one web-based Malware attack during the quarter, while Malware local threats were detected at least once on 10.93% of users’ computers. Kaspersky recorded 71,860 unique users targeted by ransomware and 213,003 unique users targeted by miner programs in this period.

Microsoft disrupts an illicit malware-signing-as-a-service run by Fox Tempest

Microsoft’s Digital Crimes Unit dismantled an MSaaS operation run by a group identified as Fox Tempest. The illicit service abused the Microsoft Artifact Signing platform to generate signing certificates for malware, and signed samples were observed in campaigns linked to ransomware groups Rhysida, Akira, INC, Qilin, and BlackByte, as well as by operators of the Oyster loader and the Lumma and Vidar infostealers. To disrupt the operation Microsoft seized the domain used by the platform, revoked associated certificates, disabled related accounts, and filed a lawsuit against Fox Tempest.

Qilin, zero-days, and the ransomware picture

Qilin reclaimed the top position among ransomware groups by share of victims listed on data leak sites, accounting for 14.57% of listings; the Akira RaaS and DragonForce group followed with 7.80% and 6.88% respectively. Kaspersky detected four new ransomware families and 2,538 new ransomware modifications in Q2, and reported that 15% of all ransomware victims whose data was published on threat actors’ data leak sites (DLS) were attacked by Qilin.

Two active vulnerability developments amplified ransomware risk. On April 22, CISA added CVE‑2026‑33825 — a local privilege escalation in Microsoft Defender — to its Known Exploited Vulnerabilities catalog, noting ongoing exploitation in ransomware attacks; Microsoft had released a patch on April 14 but unpatched systems remained vulnerable. Separately, Check Point linked zero‑day exploitation of CVE‑2026‑50751 in its Remote Access VPN and Mobile Access to activity by Qilin, with exploitation beginning May 7 and spiking sharply in early June. Check Point also disclosed CVE‑2026‑50752, a related certificate‑validation flaw affecting IKEv1 site‑to‑site VPNs.

Notably, researchers reported that the PayoutsKing group is employing the legitimate QEMU emulator to spin up hidden Alpine Linux‑based virtual machines on compromised hosts. These embedded VMs host credential theft tools and are controlled via reverse SSH tunnels — a technique intended to exploit limited security visibility inside virtualized environments.

Miners, macOS supply‑chain compromises, and IoT botnets

Cryptomining activity surged: Kaspersky detected 6,067 new miner variants in Q2 and found miner programs on the machines of 213,003 unique users. On macOS, incidents included GlassWorm stealer campaigns delivered via malicious IDE extensions on the Open VSX Registry that installed a second-stage implant and a RAT; a supply‑chain compromise of the npm package art‑template that injected the Coruna exploit kit (targeting iOS); and discovery of FlutterShell, a new macOS backdoor built on Flutter that leverages WebView and — in analyzed samples — passed Apple notarization.

IoT honeypots continued to show familiar botnet dominance: Mirai variants remained the leading threat delivered to IoT devices, and activity by Prometei increased. SSH‑based attacks were led by sources in the Netherlands (21.18%), Germany (16.73%), and the United States (6.76%). Telnet‑based attacks shifted toward Pakistan (36.60%) and China (35.62%), with the Russian Federation at 8.75%.

How enterprise security teams, policymakers, and end users will respond

  • Enterprise security teams: Will need to prioritize patch management for CVE‑2026‑33825 and CVE‑2026‑50751, review VPN and IKEv1 deployments for CVE‑2026‑50752 exposure, and investigate detection gaps for nested or VM‑based implants such as those deployed with QEMU.
  • Policymakers and regulators: CISA’s KEV update and Microsoft’s takedown show active law‑and‑policy interventions; regulators will track whether certificate revocations and legal action reduce malware distribution via signed binaries and whether KEV listings prompt measurable patch uptake.
  • End users and smaller operators: Face the bulk of web‑borne and local threats — with web Malware affecting 4.54% of users on average and local detections hitting nearly 11% — and should assume their devices could encounter mining, adware, or supply‑chain risks such as malicious package or extension updates.

Q2 2026 folded law‑enforcement style interventions and rapid exploitation of new flaws into an already crowded threat landscape: takedowns and certificate revocations intersected with zero‑day weaponization and inventive evasion techniques. The quarter’s telemetry underlines that defenders must contend simultaneously with high‑volume web and local threats, persistent ransomware operations such as Qilin, and supply‑chain and VM‑based stealth methods that blunt conventional detection.

Source: https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/