ZeroFox Report: Manufacturing Sector Top Target for Ransomware; Qilin Group Dominates with 295 Attacks in Q2 2026

Manufacturing Remains Ransomware's Top Target as Qilin Group Continues Year-Long Dominance

HIGH
July 9, 2026
July 27, 2026
m read
RansomwareThreat IntelligenceThreat Actor

Related Entities(initial)

Threat Actors

AkiraDragonForceQilinThe Gentlemen

Organizations

ZeroFox

Other

LockBit

Full Report(when first published)

Executive Summary

According to the Q2 2026 threat intelligence report from ZeroFox, the manufacturing industry remains the most heavily targeted sector by ransomware and digital extortion (R&DE) groups. The high potential for operational disruption makes manufacturers a lucrative target. The Qilin ransomware-as-a-service (RaaS) collective has solidified its dominance, marking a full year as the most prolific R&DE group worldwide. While the total number of observed incidents (1,885) represents a slight 8.5% decrease from the previous quarter, the year-over-year figures show a dramatic 50.7% increase, indicating a long-term growth trend. The report also notes a geographic shift, with targeting in Europe growing significantly, suggesting threat actors are diversifying their victim pool.

Threat Overview

The report from ZeroFox underscores a persistent and evolving threat landscape. The manufacturing sector's vulnerability stems from its reliance on interconnected IT and Operational Technology (OT) systems, where any downtime can lead to immediate and substantial financial losses. This gives attackers significant leverage in ransom negotiations.

The Qilin group, a Russian-language RaaS operation, has been exceptionally active. Specializing in double-extortion attacks—encrypting data (T1486) and exfiltrating it for public leakage if the ransom is not paid (T1657)—Qilin primarily targets high-value organizations in critical infrastructure sectors. In Q2 2026 alone, they were linked to 295 incidents.

The top five most active groups in Q2 2026 were:

  1. Qilin
  2. The Gentlemen
  3. DragonForce
  4. Akira
  5. LockBit

These five groups alone accounted for 49.5% of all global R&DE attacks, highlighting a consolidation of power among a few highly effective operations.

Technical Analysis

Ransomware groups like Qilin typically employ a multi-stage attack chain. Initial access is often gained through phishing emails (T1566), exploitation of public-facing applications (T1190), or stolen credentials purchased from initial access brokers. Once inside, they perform reconnaissance (T1087, T1082), escalate privileges (T1068), and move laterally across the network (T1021) to identify high-value data and systems. Before deploying the ransomware payload, they exfiltrate sensitive data to their own servers (T1567) to use as leverage in their double-extortion tactics. Finally, they execute the ransomware to encrypt files across the network (T1486) and inhibit system recovery by deleting backups or volume shadow copies (T1490).

Impact Assessment

The impact of these attacks on the manufacturing sector is devastating. Production lines halt, supply chains are disrupted, and financial losses mount rapidly. The double-extortion model adds the long-term risk of data leakage, which can expose intellectual property, trade secrets, employee PII, and customer data, leading to regulatory fines, lawsuits, and loss of competitive advantage. The increasing focus on Europe, which saw a 66.6% year-over-year increase in incidents, indicates that no region is safe and that these groups are actively seeking new, less-prepared targets. While North America remains the most targeted region, its declining share suggests that defenses may be improving, forcing attackers to look elsewhere.

IOCs — Directly from Articles

The report is a high-level trend analysis and does not provide specific, actionable IOCs.

Cyber Observables — Hunting Hints

Security teams can hunt for generic ransomware precursor activity:

Type
Command Line Pattern
Value
vssadmin.exe delete shadows /all /quiet
Description
Command used to delete Volume Shadow Copies to prevent system restore. A major red flag.
Type
Process Name
Value
powershell.exe, wmic.exe, psexec.exe
Description
Frequent tools used for lateral movement and remote execution by ransomware operators. Monitor for anomalous usage.
Type
Network Traffic Pattern
Value
Large outbound data transfer to unknown cloud storage
Description
A common sign of data exfiltration before encryption. Monitor for large uploads to services like Mega, Dropbox, or unknown IP addresses.
Type
Log Source
Value
Security Event Log (Event ID 4624)
Description
Monitor for a high volume of successful logons (Logon Type 3 for network) from a single account to many different hosts in a short period, indicating lateral movement.

Detection & Response

  • Behavioral Analysis: Deploy EDR and XDR solutions that use behavioral analysis to detect ransomware activities, such as rapid file encryption, deletion of shadow copies, or disabling of security tools. This is more effective than signature-based detection against modern, polymorphic ransomware. D3FEND's D3-PA: Process Analysis is key.
  • Decoy Files: Place decoy files and user accounts (honeypots/honeytokens) on file shares. Any interaction with these decoys should trigger a high-priority alert, as it indicates an attacker is performing reconnaissance. This aligns with D3-DO: Decoy Object.
  • Network Segmentation Monitoring: Monitor traffic crossing network segments. An alert on a workstation from the IT network attempting to communicate with a server in the OT/ICS network on an unusual port could be an early sign of lateral movement.

Mitigation

  • Offline Backups: Maintain immutable, offline, and frequently tested backups. This is the most critical defense against ransomware, as it ensures you can restore operations without paying the ransom. This is the core of D3-FR: File Restoration.
  • Network Segmentation: Segment IT and OT networks to prevent a ransomware infection in the corporate environment from spreading to critical industrial control systems. This is a core tenant of D3-NI: Network Isolation.
  • Patch Management: Aggressively patch internet-facing systems and applications to close the initial access vectors commonly exploited by ransomware groups. D3FEND's D3-SU: Software Update is fundamental.
  • User Training: Conduct regular phishing awareness training for employees, as social engineering remains a primary initial access vector.

Timeline of Events

1
June 30, 2026
End of Q2 2026, the period covered by the ZeroFox report.
2
July 9, 2026
ZeroFox publishes its Q2 2026 ransomware threat intelligence report.
3
July 9, 2026
This article was published

Article Updates

July 17, 2026

Severity increased

New NordStellar report reveals ransomware attacks surged 20% in H1 2026, totaling 5,257 incidents, with a 74% increase targeting large enterprises.

A NordStellar report indicates ransomware attacks rose 20% year-over-year in H1 2026, reaching 5,257 incidents. While Q2 2026 saw a slight 4% dip from Q1, the overall volume sets a new high baseline. Critically, attacks on large enterprises (over $1 billion revenue) surged by 74%, signaling a strategic shift by threat actors. Qilin and The Gentlemen remain highly active, confirming their continued dominance in the ransomware landscape.

July 27, 2026

Severity increased

Global ransomware attacks increased by 3% in Q2 2026, with a significant strategic pivot towards software supply chain compromises, amplifying systemic risk.

A new report from NCC Group for Q2 2026 indicates a 3% increase in global ransomware attacks, reaching 2,229 incidents. Critically, threat actors are strategically pivoting to target software supply chains, allowing a single breach to impact numerous downstream organizations. This represents a significant increase in systemic risk, as exemplified by the Trivy compromise and Cisco breach. The industrial sector remains the primary target, and the Qilin ransomware group continues its dominance, responsible for 301 attacks in the quarter, solidifying its position for the fifth consecutive quarter. New TTPs include T1195.001 for initial access via compromised software supply chains.

July 27, 2026

Severity increased

Q2 2026 ransomware attacks increased by 3%, with a critical new focus on software supply chain compromises, amplifying systemic risk.

A new report from NCC Group for Q2 2026 reveals a 3% increase in global ransomware attacks, reaching 2,229 incidents. The most significant development is the strategic pivot by threat actors towards compromising software supply chains (T1195.001), allowing a single breach to have a cascading impact on numerous downstream organizations. The industrial sector remains the primary target, and the Qilin group continues its dominance with 301 attacks. New hunting hints include monitoring git clone activity and CI/CD pipeline logs. Mitigation now emphasizes hardening development environments, maintaining Software Bill of Materials (SBOMs), and enhanced network segmentation for dev environments.

Timeline of Events

1
June 30, 2026

End of Q2 2026, the period covered by the ZeroFox report.

2
July 9, 2026

ZeroFox publishes its Q2 2026 ransomware threat intelligence report.

Sources & References(when first published)

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Critical InfrastructureManufacturingQilinRansomwareThreat IntelligenceZeroFox

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.