Ransomware Groups Elevate EDR Evasion Tactics Amidst Declining Attack Volumes
Ransomware groups are increasingly adopting sophisticated techniques to disable Endpoint Detection and Response (EDR) tools, making attacks harder to detect and mitigate, according to Halcyon's latest report.

Ransomware operations are increasingly standardizing the practice of disabling Endpoint Detection and Response (EDR) solutions before initiating encryption, a tactic once considered a specialized capability but now a common procedure across the threat landscape. Halcyon's Q2 2026 Ransomware Evolution Report highlights this trend, noting that it significantly reduces the window of opportunity for defenders to detect and contain attacks.
This sophisticated evasion is not merely an afterthought; some leading ransomware groups are now integrating EDR or antivirus shutdown directly into their attack chains. The Gentlemen, a recently emerged and prolific ransomware threat, exemplifies this, with researchers observing its developers systematically reverse-engineering samples from other prominent groups like Babuk, Qilin, LockBit 5.0, and Medusa. Their goal is to incorporate the most effective encryption routines, code-obfuscation techniques, and EDR evasion methods into their own arsenal.
Despite a reported 5.7% quarter-on-quarter decrease in publicly claimed ransomware attacks during Q2 2026, the underlying tactics employed by the remaining threat actors have grown substantially more advanced. Halcyon's analysis identified 1988 claimed attacks from 89 active groups across 101 countries. This decline in volume, coupled with increased sophistication, signals a strategic shift towards faster, more automated, and stealthier operations that are harder for security tools to identify and thwart.
The report from Halcyon identified Qilin as the most active group with 293 attack claims, followed closely by The Gentlemen with 214 claims. DragonForce and LockBit 5.0 also showed increased activity, while The Gentlemen notably surpassed Qilin in attack volume by June. The report also flagged emerging or returning groups such as KryBit, Payload, PEAR, and World Leaks, indicating a dynamic and evolving threat environment.
Manufacturing emerged as the most heavily targeted industry in Q2 2026, accounting for 19.8% of all cyber extortion attacks. Other significantly impacted sectors included construction, business services, retail, and software. The report also pointed to the continued exploitation of vulnerabilities in enterprise edge devices, citing specific examples like Citrix NetScaler ADC and Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet’s FortiOS (CVE-2024-55591) as common entry points for ransomware operations.
Furthermore, the operationalization of Artificial Intelligence (AI) by ransomware groups is accelerating. Threat actors are leveraging AI throughout the attack chain, from malware disguised as AI productivity tools to AI-assisted victim negotiations. Halcyon analysts noted the emergence of what they believe to be the first agentic ransomware, capable of autonomously executing key stages of an intrusion. Examples include EvilAI, an LLM-developed tool masquerading as fake AI-productivity apps to provide initial access to ransomware actors.
Ross Asquith, solutions engineering director for Europe at Halcyon, emphasized that the widespread adoption of EDR-kill techniques and the integration of AI into attack chains are making ransomware operations "faster, more automated and far more effective at neutralizing the security tools organizations rely on." This evolving threat landscape necessitates a shift in defensive strategies towards cyber resilience, moving away from the assumption that traditional security controls alone will provide sufficient response time.
Finally, the report shed light on the growing use of ransomware to support state-sponsored objectives. Evidence suggests that Iran-linked actors are increasingly disguising espionage campaigns as criminal ransomware operations, blurring the lines between cybercrime and nation-state cyber warfare.