Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month

2026-04-10T14:52:26Zcd70f6477b719cd3549321d24b020c427eb8275861b84438055a3c97c1f0f428
AI agentsAkiraAtomic StealerBitcoin DepotBitter APTChromeClickFixDevice Bound Session CredentialsDragonforceGeminiGoogle API keysNinja FormsQilinSTX RATScript Editor bypassUNC6783WordPress RCE (file upload) update 3.3.27 recommended (critical)cryptocurrency theftextortionfinance sectorhack-for-hireinfostealermacOSnon-human identities (NHI)ransomware

What happened

Infosecurity Magazine roundup (Apr 2026) highlights concentrated ransomware activity—Qilin, Akira and Dragonforce accounted for 40% of March incidents—alongside multiple active malware campaigns and high-impact breaches. Key technical developments include Chrome’s Device Bound Session Credentials to block infostealers, a new STX RAT targeting finance, Venom/Storm infostealers and Venom phishing/stealer MaaS, npm/GitHub supply-chain abuse (axios, GitHub-based C2), and macOS ClickFix variations targeting Script Editor. Several exploited/critical flaws and defensive actions are reported: Ninja •

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
cd70f6477b719cd3549321d24b020c427eb8275861b84438055a3c97c1f0f428
Enrichment time
2026-04-10T14:52:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.