Ransomware Landscape in H1 2026: Statistics and Key Issues

2026-09-16 S2W

https://medium.com/s2wblog/ransomware-landscape-in-h1-2026-statistics-and-key-issues-f15683e233cd

Thumbnail for Ransomware Landscape in H1 2026: Statistics and Key Issues

S2W links two ransomware cases to Andariel within its H1 2026 landscape. Symantec evidence associated a U.S. healthcare intrusion using Medusa ransomware with the North Korea-backed group, although S2W tracks the activity separately as puNK-012 because the specific Lazarus sub-organization remains unconfirmed. ESET also observed TigerRAT at a South Korean engineering company before a Rook ransomware variant encrypted multiple endpoints. The cases show Andariel using ransomware as a final payload alongside its established espionage and intrusion activity.

Related Actors

First seen: Jul 2017
Last seen: Sep 2026

Related Reports

« Back