State of ransomware in 2026

2026-05-12T08:51:53Z43da6dfebdcdfc9e1f24194cd38c1be6b471f1a9abd10feb3479407155fdfb64
ABCDoorAmazon SESBECC2 frameworksCVE-2025-68670EDR-killersFakeWalletOceanLotusPhantomRPCPyPI supply-chainRPC privilege escalationSilver FoxValleyRATZiChatBotcrypto stealerdata-leak extortionexploitsiOSindustrial/OT threatsphishingpre-auth RCEransomwarevulnerability statisticsxrdp

What happened

Kaspersky Securelist roundup (May 2026) highlights evolving ransomware trends (rise of EDR-killers and a shift from encryption to data-leak extortion), a disclosed pre-auth RCE in xrdp (CVE-2025-68670), and quarterly vulnerability/exploit statistics including C2 usage in APTs. Additional notable findings: OceanLotus used malicious PyPI wheels to deliver ZiChatBot, a new Amazon SES-based phishing/BEC technique, Silver Fox campaigns deploying ValleyRAT and the ABCDoor backdoor, a Windows RPC privilege-escalation technique dubbed PhantomRPC, iOS FakeWallet crypto stealers in the App Store, and an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
43da6dfebdcdfc9e1f24194cd38c1be6b471f1a9abd10feb3479407155fdfb64
Enrichment time
2026-05-12T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · State of ransomware in 2026 · Baitaphish