Ransomware Landscape in H1 2026: Statistics and Key Issues
2026-09-16 • S2W •
https://medium.com/s2wblog/ransomware-landscape-in-h1-2026-statistics-and-key-issues-f15683e233cd
S2W links two ransomware cases to Andariel within its H1 2026 landscape. Symantec evidence associated a U.S. healthcare intrusion using Medusa ransomware with the North Korea-backed group, although S2W tracks the activity separately as puNK-012 because the specific Lazarus sub-organization remains unconfirmed. ESET also observed TigerRAT at a South Korean engineering company before a Rook ransomware variant encrypted multiple endpoints. The cases show Andariel using ransomware as a final payload alongside its established espionage and intrusion activity.