State of ransomware in 2026
2026-05-12T08:51:53Z•43da6dfebdcdfc9e1f24194cd38c1be6b471f1a9abd10feb3479407155fdfb64
ABCDoorAmazon SESBECC2 frameworksCVE-2025-68670EDR-killersFakeWalletOceanLotusPhantomRPCPyPI supply-chainRPC privilege escalationSilver FoxValleyRATZiChatBotcrypto stealerdata-leak extortionexploitsiOSindustrial/OT threatsphishingpre-auth RCEransomwarevulnerability statisticsxrdp
What happened
Kaspersky Securelist roundup (May 2026) highlights evolving ransomware trends (rise of EDR-killers and a shift from encryption to data-leak extortion), a disclosed pre-auth RCE in xrdp (CVE-2025-68670), and quarterly vulnerability/exploit statistics including C2 usage in APTs. Additional notable findings: OceanLotus used malicious PyPI wheels to deliver ZiChatBot, a new Amazon SES-based phishing/BEC technique, Silver Fox campaigns deploying ValleyRAT and the ABCDoor backdoor, a Windows RPC privilege-escalation technique dubbed PhantomRPC, iOS FakeWallet crypto stealers in the App Store, and an
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 43da6dfebdcdfc9e1f24194cd38c1be6b471f1a9abd10feb3479407155fdfb64
- Enrichment time
- 2026-05-12T08:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.