~/f4n6 $ grep -r "IT threat evolution in Q2 2026. Non-mobile statistics" ./investigations/ --include="*.md"

IT threat evolution in Q2 2026. Non-mobile statistics

Jeff Davies 10 Aug 2026 7 min read

1. Executive summary

Q2 2026 saw sustained ransomware operational tempo against enterprise targets, with Qilin (no MITRE ATT&CK profile; attribution unconfirmed) accounting for 14.57% of all data-leak-site (DLS) victims and actively exploiting CVE-2026-50751 (CVSS 9.3 CRITICAL, CISA KEV) in Check Point Remote Access VPN as a zero-day. CISA confirmed active ransomware exploitation of CVE-2026-33825 (CVSS 7.8 HIGH, CISA KEV), a local privilege escalation flaw in Microsoft Defender ("BlueHammer"). Microsoft's Digital Crimes Unit disrupted a malware-signing-as-a-service (MSaaS) operation run by Fox Tempest (no MITRE ATT&CK profile; attribution unconfirmed) that had been signing payloads for Akira (MITRE G1024), BlackByte (MITRE G1043), Rhysida, INC, and Qilin. EMEA financial services with exposed Check Point VPNs or unpatched Microsoft Defender endpoints face immediate risk.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 24: digital operational resilience testing — general requirements CVE-2026-50751 (CVSS 9.3) is a critical, actively exploited authentication bypass in Check Point Remote Access VPN, a perimeter-exposed ICT asset. Clients must include this CVE in their resilience testing programme and verify remediation across all VPN gateways.
DORA Art. 19: reporting of major ICT-related incidents to competent authorities CVE-2026-50751 zero-day exploitation has already impacted "several dozen organizations," and Qilin has been definitively tied to at least one incident. If a client's Check Point VPN is compromised, the incident likely meets the major-incident threshold and triggers DORA Art. 19 reporting timelines.
NIS2 Art. 23: incident reporting obligations Active exploitation of two CISA KEV-listed vulnerabilities (CVE-2026-33825, CVE-2026-50751) in perimeter and endpoint security products represents a significant cyber threat requiring early warning and incident notification. NIS2 in-scope entities must assess exposure and report any resulting compromise under Art. 23 timelines.

3. Technical analysis & attack chain

This item covers multiple distinct threat vectors and actor operations observed in Q2 2026. The most urgent are detailed below.

3.1 CVE-2026-50751 — Check Point Remote Access VPN / Mobile Access (CVSS 9.3 CRITICAL, CISA KEV, EPSS 83%)

Vulnerability mechanism: CWE-287 (Improper Authentication). The flaw affects Check Point Remote Access VPN and Mobile Access. Attackers began exploiting it as a zero-day on May 7, 2026, with activity spiking in early June. Check Point linked exploitation to the Qilin ransomware group (no MITRE ATT&CK profile; attribution unconfirmed by Adverse Trace). At least one incident has been definitively tied to Qilin. Several dozen organizations were targeted.

Attack chain (confirmed steps)

  1. Attacker targets an internet-exposed Check Point Remote Access VPN or Mobile Access gateway.
  2. Exploits CVE-2026-50751 (improper authentication) to gain unauthenticated access — no valid credentials required.
  3. Achieves initial access to the internal network via the VPN tunnel.
  4. Qilin operators proceed to ransomware deployment (specific post-exploitation steps not detailed in source).

Related flaw: CVE-2026-50752 (CVSS 7.4 HIGH, not in CISA KEV, EPSS 5%) — CWE-295 (Improper Certificate Validation) — affects site-to-site VPN connections using the legacy IKEv1 key exchange protocol. This could enable MITM interception of VPN traffic but has not been linked to active exploitation.

3.2 CVE-2026-33825 — Microsoft Defender "BlueHammer" (CVSS 7.8 HIGH, CISA KEV, EPSS 7%)

Vulnerability mechanism: CWE-1220. Local privilege escalation in Microsoft Defender. CISA added it to KEV on April 22, 2026, noting ongoing ransomware exploitation. Microsoft released a fix on April 14, 2026. CISA did not attribute the attacks to specific threat groups. No further technical details on the exploitation chain were disclosed.

3.3 Microsoft MSaaS disruption — Fox Tempest

Microsoft's Digital Crimes Unit shut down a malware-signing-as-a-service operation attributed to Fox Tempest (no MITRE ATT&CK profile; attribution unconfirmed). The operation abused the Microsoft Artifact Signing platform to generate digital signature certificates for malicious software. Signed malware was observed in campaigns by:

  • Ransomware groups: Rhysida (no MITRE profile; unconfirmed), Akira (MITRE G1024), INC (no MITRE profile; unconfirmed), Qilin (no MITRE profile; unconfirmed), BlackByte (MITRE G1043).
  • Loaders/stealers: Oyster loader, Lumma stealer, Vidar stealer.

Microsoft seized the MSaaS platform domain, revoked all associated certificates, and disabled related accounts. A lawsuit was filed against Fox Tempest. The revocation means endpoint security products should now flag previously-signed payloads with revoked certificates.

3.4 PayoutsKing QEMU-based evasion

Researchers assess with high confidence that PayoutsKing (no MITRE ATT&CK profile; attribution unconfirmed) is deploying hidden Alpine Linux-based virtual machines on compromised hosts using the legitimate QEMU emulator. The VM functions as a backdoor managed via a reverse SSH tunnel to attacker C2 infrastructure. Inside the VM, operators deploy credential theft tools. This technique exploits the visibility gap in security solutions that cannot inspect virtualized environments. Single-sourced; verify before enforcement.

3.5 Ransomware landscape statistics

  • Top DLS actors by victim share: Qilin 14.57%, Akira 7.80%, DragonForce 6.88%.
  • New ransomware families detected: 4. New modifications: 2,538.
  • Unique users protected from ransomware: 71,860. Peak month: April (31,206 targeted users).
  • Top ransomware families by detection share: Trojan-Ransom.Win32.Gen (28.02%), WannaCry/Trojan-Ransom.Win32.Wanna (7.14%), Trojan-Ransom.Win32.Crypren (6.27%).

3.6 Other notable threats

  • GlassWorm stealer (April, Aikido researchers): Distributed via malicious IDE extensions on Open VSX Registry. Second-stage implant exfiltrated crypto wallet data, environment variables, and secrets; installed a RAT. Propagated by installing a secondary malicious extension across all IDE environments on the host.
  • npm supply chain compromise (May, Socket researchers): art-template package compromised, injecting Coruna exploit kit into built web applications. Coruna targets iOS devices.
  • FlutterShell backdoor (June, Unit 42): macOS backdoor built with Flutter framework. Uses WebView to load malicious JavaScript; registers bridge functions for arbitrary payload execution. Passed Apple notarization. Analyzed samples functioned as adware but architecture supports sophisticated payloads.
  • IoT honeypots: Mirai variants dominate; Prometei botnet activity increased. SSH attacks rose slightly. Top SSH attack sources: Netherlands (21.18%), Germany (16.73%), United States (6.76%). Telnet attack sources: Pakistan (36.60%), China (35.62%).

4. Mitigation & containment

P1 — within 24 hours

  1. Check Point VPN (CVE-2026-50751, CVSS 9.3, KEV): Identify all Check Point Remote Access VPN and Mobile Access gateways. Apply the vendor fix immediately. If no fix is available, restrict VPN access to known IP ranges or disable internet exposure. Monitor VPN authentication logs for anomalous sessions from unexpected IPs. This is the highest-priority item — EPSS 83% and confirmed Qilin exploitation.
  2. Microsoft Defender (CVE-2026-33825, CVSS 7.8, KEV): Verify the April 14, 2026 Microsoft fix is deployed across all endpoints. Check for systems with delayed update rings. EDR should alert on any privilege escalation events originating from Microsoft Defender processes.
  3. Certificate revocation (Fox Tempest MSaaS): Ensure endpoint security products are enforcing certificate revocation checks. Block any executables signed with certificates revoked by Microsoft's Digital Crimes Unit. Query EDR for historically signed-but-now-revoked binaries.

P2 — within 72 hours

  1. Check Point IKEv1 (CVE-2026-50752, CVSS 7.4): Identify site-to-site VPN connections using IKEv1. Migrate to IKEv2 where possible. If IKEv1 must remain, restrict peer IPs and monitor for MITM indicators.
  2. QEMU visibility (PayoutsKing): Audit endpoints for unexpected QEMU processes. Deploy EDR rules to flag qemu-system-* executions from non-standard paths or by non-admin users. Assess whether endpoint security solutions have visibility into nested VM environments. Single-sourced threat; calibrate response accordingly.
  3. IDE extension audit (GlassWorm): Audit developer workstations for unrecognised VS Code / Open VSX extensions. Remove any extensions not in the approved list.

P3 — within 7 days

  1. npm dependency review (art-template/Coruna): Audit CI/CD pipelines and package-lock.json files for compromised versions of art-template. Pin to known-good versions. Review web applications built with affected versions for Coruna exploit kit injection.
  2. macOS endpoint review (FlutterShell): Review macOS endpoint telemetry for Flutter-based applications using WebView with JavaScript bridge functions. Validate notarization blocklist updates from Apple.
  3. IoT exposure: Ensure all internet-facing IoT devices use non-default credentials. Disable Telnet where possible. Restrict SSH to key-based auth.

5. Indicators of compromise

No atomic indicators of compromise (IPs, domains, hashes, URLs) are present in the source material.

Behavioural indicators

Behaviour Where to observe Confidence
Unauthenticated access to Check Point Remote Access VPN / Mobile Access VPN gateway authentication logs; SIEM High — confirmed zero-day exploitation
Privilege escalation originating from Microsoft Defender process context EDR process telemetry; Windows Event Logs Medium — KEV-confirmed, mechanism details not disclosed
QEMU emulator process executing from non-standard path on a compromised host EDR process monitoring; endpoint inventory Medium — single-sourced (Kaspersky assessment)
Reverse SSH tunnel from Alpine Linux VM to external C2 Network egress monitoring; firewall logs Medium — single-sourced
Malicious IDE extension installing secondary extension across all IDE environments IDE extension logs; developer workstation EDR Medium — single-sourced (Aikido researchers)
Flutter-based macOS application loading malicious JavaScript via WebView with registered bridge functions macOS endpoint telemetry; network proxy logs Medium — single-sourced (Unit 42)
Executables signed with now-revoked Microsoft Artifact Signing certificates EDR certificate validation logs; PKI tooling High — Microsoft confirmed revocation

6. Detection

Insufficient indicators to author detection rules. The source material describes behaviours and tool names (QEMU, Flutter WebView, IDE extensions) but does not provide specific strings, file paths, mutex names, command-line flags, or registry keys that are artefacts of the malicious files themselves. Authoring YARA or Sigma rules from the product names or CVE identifiers would detect reporting about the threats, not the threats.

CVE assessment

3 referenced CVEs — 2 actively exploited (CISA KEV), 1 critical (CVSS ≥ 9.0)

CVE CVSS Exploited EPSS Summary
CVE-2026-50751 9.3 Critical ⚠ KEV 2026-06-08 83% A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unau…
CVE-2026-33825 7.8 High ⚠ KEV 2026-04-22 7% Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-50752 7.4 High 5% A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker posit…

Threat actor context

Akira · G1024 · aka GOLD SAHARA, PUNK SPIDER, Howling Scorpius

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. …

BlackByte · G1043 · aka Hecamede

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. …

No MITRE ATT&CK profile for: Fox Tempest, Rhysida, INC, Qilin, PayoutsKing.

7. Sources

  • Kaspersky Securelist, "IT threat evolution in Q2 2026. Non-mobile statistics," https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/, 2026-08-10

8. Adverse Trace position

The Q2 2026 landscape presents two immediately actionable KEV-listed vulnerabilities — CVE-2026-50751 (CVSS 9.3, EPSS 83%) in Check Point VPN and CVE-2026-33825 (CVSS 7.8) in Microsoft Defender — both confirmed in ransomware exploitation. EMEA financial services with exposed Check Point VPNs are at acute risk given Qilin's confirmed exploitation and the group's position as the top DLS actor this quarter (14.57%). The Fox Tempest MSaaS disruption is significant but defensive benefit depends on certificate revocation enforcement at the endpoint. The PayoutsKing QEMU evasion technique and the supply-chain compromises (art-template/npm, GlassWorm/Open VSX) are lower-volume but relevant for clients with developer populations or weak VM visibility. We are prioritising client outreach on Check Point VPN exposure and Microsoft Defender patch status, and will distribute IOCs as they emerge from follow-on reporting. Attribution of Fox Tempest, PayoutsKing, Rhysida, INC, and Qilin remains unconfirmed by MITRE ATT&CK profiling — treat actor naming as operational, not definitive.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies