State of ransomware in 2026

2026-05-13T20:51:58Zfe0e43165e1717b5cc142c766ab45c4a6b9c957a4efe129f0282d661d1c6c565
abcdooramazon-sesbeccrypto-stealercve-2025-68670data-leakedr-killersfakewalletindustrial-threatsiosoceanlotusphantomrpcphishingpre-auth-rceprivilege-escalationpypiransomwarerpcsilver-foxsupply-chainvalleyratvulnerabilities-reportxrdpzichatbot

What happened

Kaspersky Securelist (May 2026) roundup covering multiple active threats and research: a state-of-ransomware report (rise of EDR-killers and shift from encryption to data-leaks); discovery and coordinated patch of CVE-2025-68670 (pre-auth RCE in xrdp); a new Windows RPC privilege-escalation technique dubbed PhantomRPC; APT activity including OceanLotus distributing ZiChatBot via malicious PyPI wheels and Silver Fox using tax-notification lures to deliver ValleyRAT and the new ABCDoor backdoor; phishing campaigns abusing Amazon SES for BEC/evasion; FakeWallet iOS crypto-stealer apps in the App

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
fe0e43165e1717b5cc142c766ab45c4a6b9c957a4efe129f0282d661d1c6c565
Enrichment time
2026-05-13T20:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · State of ransomware in 2026 · Baitaphish