A report from cybersecurity firm NordStellar indicates a persistent and growing ransomware threat landscape, with a 20% year-over-year increase in attacks during the first half of 2026. Researchers documented 5,257 ransomware incidents between January and June 2026. Although the second quarter experienced a minor 4% decrease compared to the first, the overall volume establishes a new and alarmingly high baseline. The report highlights intense activity from ransomware groups Qilin and The Gentlemen. A particularly concerning trend is a 74% quarterly increase in attacks targeting large enterprises, suggesting that major corporations are increasingly in the crosshairs of sophisticated ransomware operations.
While small and medium-sized businesses (SMBs) remain the primary targets, the report identifies a significant strategic shift towards more lucrative, large enterprise targets.
The high volume of attacks is driven by the Ransomware-as-a-Service (RaaS) model, which lowers the barrier to entry for less skilled affiliates. The TTPs used by these groups are well-established:
T1566 - Phishing), exploitation of public-facing applications (T1190 - Exploit Public-Facing Application), and the use of stolen credentials, particularly for remote access services like RDP and VPNs (T1078 - Valid Accounts).T1486 - Data Encrypted for Impact) and exfiltrating data to their leak sites.This is a trend report and does not contain specific IOCs.
To detect activity from prevalent groups like Qilin, defenders can hunt for:
file_nameREADME.txtcommand_line_patternreg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender"process_nameadfind.exeservice_namePsExecNew analysis reveals an intense rivalry between Qilin and The Gentlemen ransomware groups is fueling the previously reported surge in attacks, with U.S. SMBs being primary targets.
Patching vulnerabilities remains a key defense against the initial access methods used by many ransomware groups.
Mapped D3FEND Techniques:
Segmenting networks can contain a ransomware infection and prevent it from spreading to critical assets.
Mapped D3FEND Techniques:
Protecting privileged accounts makes it harder for attackers to move laterally and deploy ransomware widely.
Mapped D3FEND Techniques:
The NordStellar report's finding of a 74% surge in attacks on large enterprises highlights the need for robust internal controls like D3-NI (Network Isolation). Large, flat networks are a primary enabler of widespread ransomware impact. Enterprises must implement a microsegmentation strategy to contain breaches. This involves creating small, isolated network zones around critical applications and data stores. For example, a company's financial database should be in its own segment, with firewall rules that only allow connections from specific application servers on specific ports. An attacker who compromises a user workstation should have no network path to this critical server. This containment strategy limits the 'blast radius' of an attack, preventing a single compromised endpoint from leading to a full-blown enterprise-wide encryption event. It directly counters the lateral movement phase of a ransomware attack.
To gain early warning of an active intrusion by groups like Qilin or The Gentlemen, organizations should deploy D3-DO (Decoy Objects). This involves placing fake but attractive-looking files and credentials (honeypot data) in various locations on the network, such as user workstations and file shares. These could be files named passwords.xlsx or fake AWS access keys. Any interaction with these decoy objects—a file being opened, a credential being used—is a high-fidelity indicator of malicious activity, as no legitimate user should ever touch them. When an alert is triggered, the security team knows an attacker is in the reconnaissance or lateral movement phase and can immediately initiate incident response to evict the attacker before they can deploy ransomware. This proactive hunting technique provides an essential early warning system that is difficult for attackers to bypass.
Start of H1 2026, the period analyzed in the NordStellar report.
End of H1 2026, during which 5,257 ransomware incidents were recorded.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.