VYPR
breachPublished Aug 10, 2026· 1 source

Ransomware Groups Leverage Disrupted Signing Service, Exploit Windows and VPN Flaws in Q2 2026

Microsoft's takedown of a malware-signing service and active exploitation of critical vulnerabilities in Windows and VPN products marked a turbulent Q2 2026 for ransomware operations.

In the second quarter of 2026, the cybersecurity landscape was significantly shaped by the disruption of a key enabler for ransomware groups and the active exploitation of critical vulnerabilities. Microsoft's Digital Crimes Unit successfully dismantled a malware-signing-as-a-service (MSaaS) operation run by the threat group Fox Tempest. This illicit service had been abusing the Microsoft Artifact Signing platform to generate digital certificates for malicious software, enabling ransomware gangs like Rhysida, Akira, INC, Qilin, and BlackByte, as well as infostealer operators, to distribute their malware with seemingly legitimate signatures.

Microsoft's decisive action involved seizing the MSaaS platform's domain, revoking associated certificates, and disabling related accounts, alongside filing a lawsuit against Fox Tempest. This move aimed to cripple the ability of numerous threat actors to distribute their payloads effectively. However, the threat landscape remained dynamic, with attackers quickly adapting and exploiting existing vulnerabilities.

Adding to the pressure on defenders, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed the active exploitation of CVE-2026-33825, a local privilege escalation flaw within Microsoft Defender. This vulnerability, dubbed BlueHammer, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog due to its use in ongoing ransomware attacks. Despite Microsoft releasing a patch in early April, unpatched systems continued to be targeted, highlighting the persistent risk posed by unmitigated vulnerabilities.

The attack surface for VPNs also proved vulnerable, with Check Point linking zero-day exploitation of CVE-2026-50751 to the Qilin ransomware group. This critical flaw affected Check Point Remote Access VPN and Mobile Access products, with exploitation beginning in early May and escalating significantly in June. While several organizations were targeted, at least one incident was definitively attributed to Qilin, underscoring the group's aggressive posture.

Qilin ransomware notably reclaimed the top spot among prolific ransomware gangs in Q2 2026, accounting for approximately 14.57% of all victims listed on threat actors' data leak sites (DLS). This resurgence, following a second-place finish in the previous quarter, was accompanied by the Akira ransomware (7.80%) and the DragonForce RaaS group (6.88%) rounding out the top three. Overall, Kaspersky products detected 2,538 new ransomware variants and blocked over 71,000 users from ransomware attacks during the quarter.

Beyond direct exploitation, the report also highlighted novel evasion techniques. Researchers observed the PayoutsKing group leveraging the legitimate QEMU emulator to deploy hidden Alpine Linux-based virtual machines on compromised hosts. This method allows attackers to conceal their malicious activities within virtualized environments, evading detection by security solutions that often lack visibility into such setups. The virtual machines were configured as backdoors, managed via reverse SSH tunnels.

The statistics from Kaspersky indicate a continued stabilization in the number of new ransomware variants after previous spikes. However, the active exploitation of critical vulnerabilities and the disruption of essential services for threat actors demonstrate the ongoing cat-and-mouse game between defenders and attackers. The resilience and adaptability of ransomware groups, as evidenced by Qilin's rise, remain a significant concern for organizations worldwide.

Synthesized by Vypr AI