الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

International Anti-Ransomware Day 2026: Ransomware Trends & Insights by Kaspersky

On International Anti-Ransomware Day, May 12, Kaspersky shares a report with an overview of ransomware trends that marked 2025 and insights into what the threat landscape holds in 2026. According to Kaspersky Security Network, in 2025 Latin America had the highest share of organizations with ransomware attacks detected (8.13%), followed by the Asia-Pacific region (7.89%), Africa (7.62%), Middle East (7.27%), the Commonwealth of Independent States (CIS, 5.91%) and Europe (3.82%). The report highlights the rise of “encryption-less” extortion attacks, the use of post-quantum cryptography by ransomware groups, and the persistent use of Telegram channels by cybercriminals to distribute compromised data sets and credentials.
Despite a slight decline in the overall share of organizations attacked by ransomware in 2025 compared to 2024, users remain at significant risk as attackers industrialize their operations, automate intrusion methods, and increasingly focus on stealing and leaking sensitive data rather than simply encrypting systems.
One of the trends in 2025 is the continued rise of endpoint detection and response (EDR) “killers” – tools specifically designed to disable endpoint security solutions before executing the malware itself. EDR killers have become a standard component of attacks, which means more deliberate and methodical intrusions.
Researchers also noted the emergence of ransomware families adopting post-quantum cryptography standards – this was predicted by Kaspersky previously. The development signals a concerning shift toward encryption methods that could resist future quantum computing decryption attempts.
The role of Initial Access Brokers (IABs) – cybercriminal intermediaries that sell pre-compromised corporate access through underground forums and messaging platforms – is growing. RDWeb portals (websites through which devices can be controlled remotely) are increasingly targeted as ransomware groups continue to industrialize attacks through “Access-as-a-Service” operations. As a result, the barrier to launching ransomware attacks declines.
Telegram channels and dark web forums continuously function as platforms for the distribution and for the sale of compromised data sets and accesses including those that were obtained as a result of ransomware attacks. A major underground forum, RAMP, which also functioned as a platform through which threat actors advertised their ransomware services and published service‑related updates, got seized by authorities in January 2026. Another underground forum, LeakBase, where malicious actors distributed exfiltrated and compromised data, was seized in March 2026. However, while law enforcement agencies are actively shutting down dark web platforms and ransomware data leak sites, similar portals may appear over time.
Active groups
Among the most active ransomware groups in 2025 based on data leak sites, Kaspersky identified Qilin as the dominant ransomware-as-a-service (RaaS) operator following RansomHub’s seizure of operations. Clop ranked as the second most active group, with Akira in the third place.
While several major ransomware groups stopped operation in 2025, new actors emerge. Looking at 2026, the Gentlemen is one of the most important new ransomware actors due to the group’s rapid growth, structured operations, and increasing focus on data-centric extortion. The group may include attackers formerly associated with other major ransomware operations. The Gentlemen exemplify a broader shift in the ransomware ecosystem away from chaotic, high-noise campaigns toward scalable, business-like extortion models focused primarily on stealing sensitive data and leveraging reputational and regulatory pressure rather than relying solely on disruptive file encryption.
“Ransomware has evolved into a highly organized ecosystem focused on monetizing stolen data, disabling defenses, and scaling attacks with business-like efficiency. Threat actors are quickly adapting, weaponizing legitimate tools, exploiting remote access infrastructure, and even adopting post-quantum cryptography years earlier than many expected. The purpose of Anti-Ransomware Day is to raise global awareness about the threats posed by ransomware and to promote best practices for prevention and response, and we urge all users to stay secure, set up layered defenses, invest in backups and boost cyberliteracy levels to counter attacks,” comments Fabio Assolini, Lead Security Researcher at Kaspersky GReAT.
On Anti-Ransomware Day and beyond, Kaspersky encourages organizations to follow these best practices to safeguard from ransomware:
• Enable ransomware protection for all endpoints. There is a free Kaspersky Anti-Ransomware Tool for Business that shields computers and servers from ransomware and other types of malware, prevents exploits and is compatible with already installed security solutions.
• Always keep software updated on all the devices you use to prevent attackers from exploiting vulnerabilities and infiltrating your network.
• Focus your defense strategy on detecting lateral movements and data exfiltration to the internet. Pay special attention to outgoing traffic to detect cybercriminals’ connections to your network. Set up offline backups that intruders cannot tamper with. Make sure you can access them quickly when needed or in an emergency.
• Companies from non-industrial sector can protect themselves by installing anti-APT and EDR solutions that enable capabilities for advanced threat discovery and detection, investigation and timely remediation of incidents. Organizations can also provide their SOC teams with access to the latest threat intelligence and regularly upskill them with professional training. All of the above is available within Kaspersky Next.

Related Posts:

Kaspersky unveils how the worst cyber incidents hit SMBs over the past year

Turkish Airlines Named Liverpool FC Main Partner from 2027/28 Season

The Investor 2026 to Tackle Egypt’s Industry and Real Estate Challenges

Tanmeyah Receives Gold Client Protection Certification from MicroFinanza Rating

Bloom Holding Launches Alhambra, the Vibrant Heart and Final Release of Bloom Living

GovAcademy’s Executive Director joins the summit’s opening sessions as Abu Dhabi’s approach to skills intelligence takes centre stage

Zerosploit MEA and Comforte Announce Strategic Data Security Partnership

Al Seer Marine Capitalises on Strong Tanker Values with Profitable Sale of VLCC

آخر الأخبار
Kaspersky unveils how the worst cyber incidents hit SMBs over the past year وزير الشباب والرياضة يبحث مع «Blue Ribbon» تطوير إدارة وتشغيل الأندية الرياضية كاسبرسكي: 86% من الشركات الصغيرة والمتوسطة تعرضت لهجمات سيبرانية «عوده للتطوير» تطرح كمبوند «كناري» في الحي 25 بالعبور الجديدة على مساحة 15 فدانا Turkish Airlines Named Liverpool FC Main Partner from 2027/28 Season الذهب يعاود الصعود في مصر.. عيار 21 يسجل 6300 جنيه الخطوط الجوية التركية شريك رئيسي لنادي ليفربول من موسم 2027/2028 تيلدا تتيح إرسال واستقبال الأموال عبر إنستاباي بدعم موديوباي وزارة الصحة تنظم اليوم العلمي لمناقشة المجلة العلمية لمركز المعلومات الدوائية ديبال تتصدر سوق السيارات الكهربائية ممتدة المدى في مصر.. 1,135 سيارة منذ بداية العام جي بي أوتو تطلق هافال V7 في مصر.. تصميم صندوقي جريء وقدرات متقدمة على الطرق الوعرة وخياران من أنظمة ... البنك العربي يوقع اتفاقية تمويل مع شركة إيديتا للصناعات الغذائية بقيمة 600 مليون جنيه مصري رئيس الوزراء يهنيء مزارعي مصر بمناسبة الاحتفال بالعيد الـ ٧٤ للفلاح «CACC» وأكاديمية مصر للطيران للتدريب توقعان بروتوكول تعاون لتطوير الكوادر البشرية بقطاع الشحن الجوي 50 عدّاءً إماراتيًا يحملون رسالة العطاء إلى بكين ضمن سباق زايد الخيري وماراثون هوايرو سور الصين العظ... إبسون تفتتح مقرها الإقليمي للشرق الأوسط وشمال إفريقيا في المملكة العربية السعودية وزير التخطيط يبحث دعم رواد الأعمال المصريين في الإمارات مؤتمر Money2020 Middle East يستعرض في الرياض جدول أعمال نسخة 2026 مع مشاركة قادة التقنية المالية وال... وزيرة الأسرة: الميثاق يجسد رؤية الإمارات الاستباقية في تعزيز استقرار وتماسك الأسرة تيك توك يحذف 15.5 مليون فيديو مخالف.. العراق ومصر في الصدارة