Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month
2026-04-10T14:52:26Z•cd70f6477b719cd3549321d24b020c427eb8275861b84438055a3c97c1f0f428
AI agentsAkiraAtomic StealerBitcoin DepotBitter APTChromeClickFixDevice Bound Session CredentialsDragonforceGeminiGoogle API keysNinja FormsQilinSTX RATScript Editor bypassUNC6783WordPress RCE (file upload) update 3.3.27 recommended (critical)cryptocurrency theftextortionfinance sectorhack-for-hireinfostealermacOSnon-human identities (NHI)ransomware
What happened
Infosecurity Magazine roundup (Apr 2026) highlights concentrated ransomware activity—Qilin, Akira and Dragonforce accounted for 40% of March incidents—alongside multiple active malware campaigns and high-impact breaches. Key technical developments include Chrome’s Device Bound Session Credentials to block infostealers, a new STX RAT targeting finance, Venom/Storm infostealers and Venom phishing/stealer MaaS, npm/GitHub supply-chain abuse (axios, GitHub-based C2), and macOS ClickFix variations targeting Script Editor. Several exploited/critical flaws and defensive actions are reported: Ninja •
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- cd70f6477b719cd3549321d24b020c427eb8275861b84438055a3c97c1f0f428
- Enrichment time
- 2026-04-10T14:52:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.