“Shutting down endpoint detection and response (EDR) tools before encryption begins has become standard operating procedure across the ransomware ecosystem,” researchers at Halcyon warned in their Q2 2026 Ransomware Evolution Report, published 27 July — a finding rooted in analysis of 1,988 publicly claimed attacks over the quarter.
EDR-kill techniques go mainstream
Halcyon’s analysis shows what was once a specialist capability — disabling EDR or antivirus before encryption — has become routine across leading ransomware groups. The report states some groups now include an EDR or antivirus shutdown as an explicit step in their attack chain, a development Halcyon frames as shortening defenders’ available response time and reducing opportunities for detection and containment.
“The ransomware ecosystem is becoming faster, more automated and far more effective at neutralizing the security tools organizations rely on,” Ross Asquith, solutions engineering director for Europe at Halcyon, told the authors of the report, summarizing the practical consequence of EDR-kill’s diffusion.
The Gentlemen: borrowing the best (and the nastiest)
Halcyon singled out a recently emerged actor known as The Gentlemen as both prolific and methodical. The company’s Ransomware Research Center reported that The Gentlemen’s developers “are systematically reverse-engineering samples from other groups, such as Babuk, Qilin, LockBit 5.0 and Medusa, to select the strongest encryption routines, code-obfuscation techniques and EDR evasion methods to incorporate into their own codebase.”
That hybridization helps explain the group’s rapid rise: Halcyon attributed 214 attack claims to The Gentlemen in Q2 2026, and noted the group overtook Qilin for the top spot in June.
AI in the attack chain: EvilAI and agentic ransomware
Halcyon documents a clear operational shift: AI is moving from experimentation into active use across ransomware operations. “Threat actors increasingly leveraged AI throughout the attack chain, from malware disguised as AI productivity tools to AI-assisted victim negotiations and the emergence of what researchers believe to be the first agentic ransomware capable of autonomously conducting key stages of an intrusion,” the Halcyon analysts wrote.
The report cites instances of an LLM-developed tool named EvilAI being disguised as a fake AI-productivity app, while actually providing initial access to operators. Halcyon’s framing ties AI’s generalization in ransomware directly to increased automation and speed in campaigns.
Rapid deployment and exploited edge vulnerabilities (CVE-2025-5777, CVE-2024-40766, CVE-2024-55591)
Across 1,988 claimed attacks from 89 groups targeting 101 countries, Halcyon found attackers exploiting a set of enterprise edge vulnerabilities to gain initial access. Notable CVEs named in the report include Citrix NetScaler ADC and Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766) and Fortinet’s FortiOS (CVE-2024-55591).
The report also records operational speed: groups such as DragonForce and Akira in some incidents moved from initial breach to ransomware deployment in under an hour, a tempo that compounds the impact of EDR-kill and automated tooling.
Qilin, DragonForce, Akira, LockBit 5.0 — who was most active
Although the overall number of claimed attacks fell 5.7% quarter-on-quarter, Halcyon identified concentrated activity among leading groups. The counts for Q2 2026 were Qilin (293 attack claims), The Gentlemen (214), DragonForce (143), Akira (119) and LockBit 5.0 (102). The report also names several emerging or returning groups — KryBit, Payload, PEAR and World Leaks — adding to the field’s churn.
Sectoral targeting skewed toward manufacturing, which accounted for 19.8% of all reported cyber extortion attacks in the quarter, followed by construction, business services, retail and software.
What this means for technologists, policymakers, and procurement leaders
- Technologists and security teams: expect faster, automated attacks that explicitly target EDR and AV. Halcyon’s analysis and Ross Asquith’s warning about neutralizing security tools suggest defenders cannot rely solely on traditional controls to buy time for response.
- Policymakers and regulators: the report’s naming of exploited CVEs — CVE-2025-5777, CVE-2024-40766 and CVE-2024-55591 — and the observation that Iran-linked actors are disguising espionage as criminal ransomware activity point to overlapping criminal and state objectives that will shape regulatory and attribution conversations.
- Enterprise procurement and owners in manufacturing and construction: the sector-level numbers and the rapid “initial breach to deployment” timings reported for DragonForce and Akira underline the need to reassess vendor risk and patching priorities for exposed edge devices and gateways.
Halcyon’s Q2 portrait is stark: fewer total claims, but more sophisticated, faster and more automated campaigns that deliberately blunt defenders by targeting the very tools organizations depend on. The next practical question the report leaves in plain view is whether defenders will shift from assuming time to respond toward designing systems that accept — and survive — a faster, EDR-kill-capable adversary.




