Ransomware Tactics Evolve: EDR-Kill Becomes Standard as AI and Speed Reshape Attacks
A new report from Halcyon reveals a sharp escalation in ransomware sophistication, with attackers increasingly disabling endpoint detection and response (EDR) tools a tactic once reserved for advanced groups now standard across the ecosystem. Published on July 27, the Q2 2026 Ransomware Evolution Report highlights how ransomware operations are becoming faster, more automated, and harder to detect, despite a 5.7% quarterly decline in publicly claimed attacks.
Key Trends in Q2 2026
During the quarter, 89 active ransomware groups executed 1,988 attacks across 101 countries. While overall attack volume dipped, tactics grew more aggressive. Leading groups Qilin (293 attacks), The Gentlemen (214), DragonForce (143), Akira (119), and LockBit 5.0 (102) prioritized speed, with some achieving initial breach to encryption in under an hour. The Gentlemen, a rising threat, has rapidly refined its arsenal by reverse-engineering techniques from groups like Babuk, Qilin, and Medusa, incorporating their strongest encryption and evasion methods.
Targeted Sectors and Exploited Vulnerabilities
Manufacturing bore the brunt of attacks (19.8%), followed by construction, business services, retail, and software. Ransomware groups exploited critical flaws in enterprise edge devices, including Citrix NetScaler ADC/Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet FortiOS (CVE-2024-55591). Emerging groups like KryBit, Payload, PEAR, and World Leaks also reemerged, signaling a broadening threat landscape.
AI’s Role in Ransomware Operations
AI is no longer experimental for ransomware actors. Halcyon observed its integration across the attack chain, from malware disguised as AI productivity tools (e.g., EvilAI) to AI-assisted negotiations and even agentic ransomware capable of autonomous intrusion stages. The shift underscores how threat actors are leveraging automation to outpace defenses.
State-Linked Ransomware and EDR Evasion
The report also noted growing evidence of Iran-linked actors disguising espionage as ransomware operations, blurring the line between criminal and state-sponsored activity. Meanwhile, the democratization of EDR-kill techniques now a staple among top groups has slashed defenders’ response windows, forcing a reevaluation of traditional security controls.
Halcyon’s findings paint a stark picture: ransomware is evolving into a more adaptive, AI-driven threat, with attackers systematically dismantling defenses before encryption even begins.
Source: https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
SonicWall cybersecurity rating report: https://www.rankiteo.com/company/sonicwall
Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet
"id": "SONFOR1785147921",
"linkid": "sonicwall, fortinet",
"type": "Vulnerability",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing', 'type': 'Sector'},
{'industry': 'Construction', 'type': 'Sector'},
{'industry': 'Business Services', 'type': 'Sector'},
{'industry': 'Retail', 'type': 'Sector'},
{'industry': 'Software', 'type': 'Sector'}],
'attack_vector': ['Exploited vulnerabilities in enterprise edge devices',
'AI-assisted malware (e.g., EvilAI)'],
'data_breach': {'data_encryption': 'Yes'},
'date_detected': '2026-07-27',
'date_publicly_disclosed': '2026-07-27',
'description': 'A new report from Halcyon reveals a sharp escalation in '
'ransomware sophistication, with attackers increasingly '
'disabling endpoint detection and response (EDR) tools—a '
'tactic once reserved for advanced groups now standard across '
'the ecosystem. The report highlights how ransomware '
'operations are becoming faster, more automated, and harder to '
'detect, despite a 5.7% quarterly decline in publicly claimed '
'attacks.',
'lessons_learned': 'Ransomware operations are becoming faster, more '
'automated, and harder to detect due to AI integration and '
"EDR-kill techniques. Defenders' response windows have "
'shrunk, necessitating a reevaluation of traditional '
'security controls.',
'motivation': ['Financial gain', 'Espionage (state-linked actors)'],
'post_incident_analysis': {'root_causes': ['Exploited vulnerabilities in '
'enterprise edge devices',
'AI-assisted malware',
'EDR-kill techniques']},
'ransomware': {'data_encryption': 'Yes',
'ransomware_strain': ['Qilin',
'The Gentlemen',
'DragonForce',
'Akira',
'LockBit 5.0',
'Babuk',
'Medusa']},
'references': [{'date_accessed': '2026-07-27',
'source': 'Halcyon Q2 2026 Ransomware Evolution Report'}],
'threat_actor': ['Qilin',
'The Gentlemen',
'DragonForce',
'Akira',
'LockBit 5.0',
'KryBit',
'Payload',
'PEAR',
'World Leaks',
'Iran-linked actors'],
'title': 'Ransomware Tactics Evolve: EDR-Kill Becomes Standard as AI and '
'Speed Reshape Attacks',
'type': 'Ransomware',
'vulnerability_exploited': ['CVE-2025-5777 (Citrix NetScaler ADC/Gateway)',
'CVE-2024-40766 (SonicWall SSL VPN)',
'CVE-2024-55591 (Fortinet FortiOS)']}