Bg Shape
Image

Six Ransomware Groups That Emerged in 2026

Smarttech247 Research Team
Insights and Intelligence
Published:
September 4, 2026

Key takeaways

  • There's no single fix here. Krybit and Insomnia get in through stolen credentials, no fixed vector. Deadlock and Payload disable your defences before they encrypt anything. Settra and AiLock just try to look legitimate once they're in.
  • Four of the six lean on identity. Krybit, Settra, Insomnia, and Payload (via credential-stuffing risk) all depend on looking like a valid user, not on malware a signature can catch.
  • Two of these groups never encrypt anything. Settra and Insomnia are pure data theft. Your backups won't save you from either.

Krybit

Krybit showed up as a ransomware-as-a-service operation in late March 2026. It leases encryption builders covering Windows, Linux, VMware ESXi, and NAS devices out to affiliates, stages 10 to 250GB of stolen data per victim, then demands $40,000 to $100,000 in ransom.

What actually got Krybit noticed wasn't the ransomware itself. It was a fight. In April 2026, a rival group called 0APT breached Krybit's admin panel, exposing two operators, five affiliates, and twenty live negotiations. Krybit hit back within a day and defaced 0APT's own leak site. Good story, but it didn't slow anything down: Krybit had logged more than 50 victims by the end of its first full quarter, with claimed targets concentrated in business services, manufacturing, education, and technology.

Here's the thing about Krybit: it doesn't care how it gets in. No single entry vector is consistently tied to the group, phishing, exploited services, stolen credentials, exposed RDP, whatever works. Once it's in, it deletes shadow copies and uses process injection to stay ahead of detection. Education stands out among its victims. Universities run huge, scattered device estates with staff and students travelling constantly. That's a lot of surface area for an opportunist like Krybit to work with.

What stops it:

You can't out-patch a group that doesn't care which door it uses. Block phishing and it comes through RDP. Lock down RDP and it comes through a stolen credential. Defending one vector still leaves three open.

RCSI ran into this exact problem, and built its Smarttech247 partnership to solve it. We deployed IBM QRadar SIEM to pull millions of daily events, network flows, Windows systems, and cloud feeds into a single view across its four-campus estate.

That's what actually matters against Krybit: you stop caring which door they used, because you're watching what happens next regardless. Attackers exploit human behaviour through phishing and social engineering, which makes identity the most critical attack surface in education, even with strong tooling already in place.

Deadlock

Deadlock's been around longer than you'd think. It first showed up in July 2025, disappeared from public leak sites for eleven months, then came back in June 2026 with 75 named victims in a single month, before it exploits a vulnerable driver to disable your endpoint security tools outright, wiping out the telemetry your team would normally catch it with. That's how it landed near the top of the leaderboard almost overnight.

What makes Deadlock interesting is its infrastructure. Most groups rely on domains or IPs you can block. Deadlock doesn't: its command and control loads from a public blockchain, so operators rotate addresses invisibly. Microsoft's threat intel team has tracked Deadlock deployments by affiliates linked to Lynx and INC, so there's likely shared tooling or overlapping affiliates rather than one clean operation.

Victims cluster in professional services, manufacturing, and technology, across roughly 40 countries, over half in Europe. Manufacturing gets hit hardest for an obvious reason: a stopped production line bleeds money by the hour, and that urgency is exactly the leverage an attacker wants.

What stops it:

Deadlock needs two things to go its way: disabling your tools before anyone notices, and infrastructure nobody can block. Trivium Packaging built its Smarttech247 partnership to take both away:

  • Detection mapped to MITRE ATT&CK use cases, not static indicator lists, so it never depended on Deadlock having a blockable IP
  • Pre-authorised response, so analysts isolate a compromised system the second a high-confidence attack fires, not after someone signs off

Against a group that's built to disable your defences fast, that speed is what actually matters.

Payload

Payload showed up on 17 February 2026. Its Windows binary was compiled that day, and the first victim hit its leak site within hours. It's built on Babuk's leaked 2021 source code, but swaps Babuk's original cipher for Curve25519 and ChaCha20, and runs against both Windows and Linux/VMware ESXi from the same codebase.

Here's the part that actually matters: it's not the encryption that makes Payload dangerous, it's what it does right before. Reverse-engineering found the malware wipes Windows event logs, patches ETW to blind security monitoring, deletes shadow copies, and kills your backup and security-tool services, all before it locks a single file. It's built to erase evidence of itself faster than any analyst could react.

By late April 2026, Payload had logged more than 30 claims across a dozen-plus countries, mostly in manufacturing, business services, and healthcare, and it's growing more than 50 percent quarter on quarter. Despite the Babuk roots, nobody's confirmed a link to any other named group. This looks like an independent operation running on borrowed code.

What stops it:

Payload's whole advantage is speed of erasing evidence. By the time a compromised host's own logs would normally show something wrong, they're already gone. So you can't rely on the host to tell you it's under attack.

Dairygold had a version of this problem long before Payload existed. Its Windows estate, ICS, and SCADA systems all had good tools, but they sat on disconnected platforms with no way to correlate what any of them were seeing. We extended IBM QRadar with BigFix, pulling endpoint and OT telemetry into one correlated view, with actionable intelligence flowing within three months.

That's the actual answer to Payload: visibility that lives above the host doesn't go dark when Payload wipes a single machine's logs. A threat built to erase its own tracks gets nothing if your detection was never relying on those tracks in the first place.

Settra

Settra might not encrypt anything at all, and that alone makes it unusual for 2026. It emerged in June 2026 as what researchers call a data broker: no encryptor tied to Settra has ever been publicly analysed, and the group's own leak site doesn't confirm an encryption capability. This looks like an exfiltration-first operation that pressures victims with stolen data and public exposure, not locked files.

Where Settra is consistent is how it gets in. MOXFIVE's own incident casework has Settra gaining access through compromised VPN credentials, then moving through victim environments using legitimate admin and red-team tools instead of custom malware, a deliberate choice that lets the activity blend into normal network traffic instead of tripping a signature-based alert.

Victims don't cluster around one sector. Construction, business services, industrial manufacturing, and e-commerce, spread across five countries. Settra tends to post victims in batches, which suggests it's working from a bulk credential feed rather than hand-operating each intrusion.

What stops it:

Settra's whole approach depends on looking normal. Valid credentials plus legitimate tools means no malware signature to catch and no obviously malicious login to flag.

That's exactly the gap CluneTech closed. Before working with us, CluneTech's team was investigating 1,200 to 1,400 security offences a month. We filtered that down to roughly 30 a month. What's left isn't noise, it's the small number of events that actually warrant a look, including the kind of legitimate-looking, credential-based activity Settra depends on to stay unnoticed.

Attackers with valid credentials can move laterally in under an hour without triggering traditional alerts, because the behaviour looks like a normal user, not a break-in. Catching that takes behavioural analysis, not malware scanning, which is exactly the layer Settra is built to slip past.

AiLock

AiLock first showed up in early 2025 and came back into focus hard in March 2026, marketing itself openly as "AI-assisted" ransomware, with suspected ties to the Russian state-linked group APT28 (Fancy Bear). If that link's ever confirmed, it points to motives well beyond money. It's a RaaS operation, running a hybrid ChaCha20 and NTRUEncrypt encryption scheme with double extortion.

It's aggressive by design. AiLock tags locked files with a .AiLock extension, swaps your desktop wallpaper for a robot skull, and gives you 72 hours to respond and up to five days to pay before it leaks your data and destroys recovery tools, on top of threatening to report the breach to regulators or hand your stolen data straight to your competitors.

The "AI-assisted" label doesn't hold up under any real scrutiny. No published technical analysis has ever pinned down what that component actually does, and by early June 2026 AiLock had racked up 38 claimed victims since its March relaunch, with the APT28 link still unconfirmed.

Insomnia

Insomnia is the odd one out here. It's ransomware in name only. The group showed up in October 2025 as a data-theft-only operation with no encryptor, no negotiation portal, and no affiliate program. It steals patient files, tax documents, driver's licences, and just publishes them for free. No lock screen, no ransom to pay. By late April 2026, it had logged over 30 claims, nine in ten in the US, roughly a third to half tied to healthcare.

Its whole approach is built to stay quiet. Researchers say Insomnia uses stolen and infostealer-sourced credentials plus authentication bypass flaws, then rides legitimate infrastructure to move laterally, optimising for speed and low visibility instead of the loud disruption that actually gets a SOC's attention.

What stops it:

Insomnia's edge is that healthcare data almost never lives where you'd expect. Healthcare organisations have sensitive data spread across shared drives, legacy systems, and collaboration platforms with weak governance, which creates a fragmented attack surface way bigger than the core clinical systems. Stolen credentials get an attacker in. Once they're in, ungoverned data sitting outside anyone's watch is easy to find and even easier to take.

The fix here isn't encryption-focused, because Insomnia never encrypts anything. It's about actually knowing where your sensitive data sits. Find your high-value data first, improve classification, cut what you don't need, and layer in continuous controls incrementally, a realistic approach if you're a smaller provider without an enterprise security budget, which describes most of Insomnia's victims.

Read Our Latest Blogs

Blog Image
8 SOC Platform Requirements for 24/7 Threat Monitoring

Evaluating a threat detection and response platform? Here are the 8 requirements for 24/7 monitoring, threat intelligence, and automated response.

Blog Image
Six Ransomware Groups That Emerged in 2026

67 new ransomware groups emerged in 2026, but only six are worth your attention. See how each operates, who they target, and what actually stops them.

Blog Image
VMware vCentre Backdoor, LiteLLM Supply Chain Attack & Azure Entra ID Targeted

China-backed APT exploits VMware vCentre, LiteLLM supply chain attack hits 2,500 pipelines, and Azure Entra ID targeted with stolen credentials.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Six Ransomware Groups That Emerged in 2026

Ransomware and Malware
Threat Actors and Campaigns
Identity and Access
Incident Response and Recovery
Smarttech247 Research Team
Insights and Intelligence
September 4, 2026

Key takeaways

  • There's no single fix here. Krybit and Insomnia get in through stolen credentials, no fixed vector. Deadlock and Payload disable your defences before they encrypt anything. Settra and AiLock just try to look legitimate once they're in.
  • Four of the six lean on identity. Krybit, Settra, Insomnia, and Payload (via credential-stuffing risk) all depend on looking like a valid user, not on malware a signature can catch.
  • Two of these groups never encrypt anything. Settra and Insomnia are pure data theft. Your backups won't save you from either.

Krybit

Krybit showed up as a ransomware-as-a-service operation in late March 2026. It leases encryption builders covering Windows, Linux, VMware ESXi, and NAS devices out to affiliates, stages 10 to 250GB of stolen data per victim, then demands $40,000 to $100,000 in ransom.

What actually got Krybit noticed wasn't the ransomware itself. It was a fight. In April 2026, a rival group called 0APT breached Krybit's admin panel, exposing two operators, five affiliates, and twenty live negotiations. Krybit hit back within a day and defaced 0APT's own leak site. Good story, but it didn't slow anything down: Krybit had logged more than 50 victims by the end of its first full quarter, with claimed targets concentrated in business services, manufacturing, education, and technology.

Here's the thing about Krybit: it doesn't care how it gets in. No single entry vector is consistently tied to the group, phishing, exploited services, stolen credentials, exposed RDP, whatever works. Once it's in, it deletes shadow copies and uses process injection to stay ahead of detection. Education stands out among its victims. Universities run huge, scattered device estates with staff and students travelling constantly. That's a lot of surface area for an opportunist like Krybit to work with.

What stops it:

You can't out-patch a group that doesn't care which door it uses. Block phishing and it comes through RDP. Lock down RDP and it comes through a stolen credential. Defending one vector still leaves three open.

RCSI ran into this exact problem, and built its Smarttech247 partnership to solve it. We deployed IBM QRadar SIEM to pull millions of daily events, network flows, Windows systems, and cloud feeds into a single view across its four-campus estate.

That's what actually matters against Krybit: you stop caring which door they used, because you're watching what happens next regardless. Attackers exploit human behaviour through phishing and social engineering, which makes identity the most critical attack surface in education, even with strong tooling already in place.

Deadlock

Deadlock's been around longer than you'd think. It first showed up in July 2025, disappeared from public leak sites for eleven months, then came back in June 2026 with 75 named victims in a single month, before it exploits a vulnerable driver to disable your endpoint security tools outright, wiping out the telemetry your team would normally catch it with. That's how it landed near the top of the leaderboard almost overnight.

What makes Deadlock interesting is its infrastructure. Most groups rely on domains or IPs you can block. Deadlock doesn't: its command and control loads from a public blockchain, so operators rotate addresses invisibly. Microsoft's threat intel team has tracked Deadlock deployments by affiliates linked to Lynx and INC, so there's likely shared tooling or overlapping affiliates rather than one clean operation.

Victims cluster in professional services, manufacturing, and technology, across roughly 40 countries, over half in Europe. Manufacturing gets hit hardest for an obvious reason: a stopped production line bleeds money by the hour, and that urgency is exactly the leverage an attacker wants.

What stops it:

Deadlock needs two things to go its way: disabling your tools before anyone notices, and infrastructure nobody can block. Trivium Packaging built its Smarttech247 partnership to take both away:

  • Detection mapped to MITRE ATT&CK use cases, not static indicator lists, so it never depended on Deadlock having a blockable IP
  • Pre-authorised response, so analysts isolate a compromised system the second a high-confidence attack fires, not after someone signs off

Against a group that's built to disable your defences fast, that speed is what actually matters.

Payload

Payload showed up on 17 February 2026. Its Windows binary was compiled that day, and the first victim hit its leak site within hours. It's built on Babuk's leaked 2021 source code, but swaps Babuk's original cipher for Curve25519 and ChaCha20, and runs against both Windows and Linux/VMware ESXi from the same codebase.

Here's the part that actually matters: it's not the encryption that makes Payload dangerous, it's what it does right before. Reverse-engineering found the malware wipes Windows event logs, patches ETW to blind security monitoring, deletes shadow copies, and kills your backup and security-tool services, all before it locks a single file. It's built to erase evidence of itself faster than any analyst could react.

By late April 2026, Payload had logged more than 30 claims across a dozen-plus countries, mostly in manufacturing, business services, and healthcare, and it's growing more than 50 percent quarter on quarter. Despite the Babuk roots, nobody's confirmed a link to any other named group. This looks like an independent operation running on borrowed code.

What stops it:

Payload's whole advantage is speed of erasing evidence. By the time a compromised host's own logs would normally show something wrong, they're already gone. So you can't rely on the host to tell you it's under attack.

Dairygold had a version of this problem long before Payload existed. Its Windows estate, ICS, and SCADA systems all had good tools, but they sat on disconnected platforms with no way to correlate what any of them were seeing. We extended IBM QRadar with BigFix, pulling endpoint and OT telemetry into one correlated view, with actionable intelligence flowing within three months.

That's the actual answer to Payload: visibility that lives above the host doesn't go dark when Payload wipes a single machine's logs. A threat built to erase its own tracks gets nothing if your detection was never relying on those tracks in the first place.

Settra

Settra might not encrypt anything at all, and that alone makes it unusual for 2026. It emerged in June 2026 as what researchers call a data broker: no encryptor tied to Settra has ever been publicly analysed, and the group's own leak site doesn't confirm an encryption capability. This looks like an exfiltration-first operation that pressures victims with stolen data and public exposure, not locked files.

Where Settra is consistent is how it gets in. MOXFIVE's own incident casework has Settra gaining access through compromised VPN credentials, then moving through victim environments using legitimate admin and red-team tools instead of custom malware, a deliberate choice that lets the activity blend into normal network traffic instead of tripping a signature-based alert.

Victims don't cluster around one sector. Construction, business services, industrial manufacturing, and e-commerce, spread across five countries. Settra tends to post victims in batches, which suggests it's working from a bulk credential feed rather than hand-operating each intrusion.

What stops it:

Settra's whole approach depends on looking normal. Valid credentials plus legitimate tools means no malware signature to catch and no obviously malicious login to flag.

That's exactly the gap CluneTech closed. Before working with us, CluneTech's team was investigating 1,200 to 1,400 security offences a month. We filtered that down to roughly 30 a month. What's left isn't noise, it's the small number of events that actually warrant a look, including the kind of legitimate-looking, credential-based activity Settra depends on to stay unnoticed.

Attackers with valid credentials can move laterally in under an hour without triggering traditional alerts, because the behaviour looks like a normal user, not a break-in. Catching that takes behavioural analysis, not malware scanning, which is exactly the layer Settra is built to slip past.

AiLock

AiLock first showed up in early 2025 and came back into focus hard in March 2026, marketing itself openly as "AI-assisted" ransomware, with suspected ties to the Russian state-linked group APT28 (Fancy Bear). If that link's ever confirmed, it points to motives well beyond money. It's a RaaS operation, running a hybrid ChaCha20 and NTRUEncrypt encryption scheme with double extortion.

It's aggressive by design. AiLock tags locked files with a .AiLock extension, swaps your desktop wallpaper for a robot skull, and gives you 72 hours to respond and up to five days to pay before it leaks your data and destroys recovery tools, on top of threatening to report the breach to regulators or hand your stolen data straight to your competitors.

The "AI-assisted" label doesn't hold up under any real scrutiny. No published technical analysis has ever pinned down what that component actually does, and by early June 2026 AiLock had racked up 38 claimed victims since its March relaunch, with the APT28 link still unconfirmed.

Insomnia

Insomnia is the odd one out here. It's ransomware in name only. The group showed up in October 2025 as a data-theft-only operation with no encryptor, no negotiation portal, and no affiliate program. It steals patient files, tax documents, driver's licences, and just publishes them for free. No lock screen, no ransom to pay. By late April 2026, it had logged over 30 claims, nine in ten in the US, roughly a third to half tied to healthcare.

Its whole approach is built to stay quiet. Researchers say Insomnia uses stolen and infostealer-sourced credentials plus authentication bypass flaws, then rides legitimate infrastructure to move laterally, optimising for speed and low visibility instead of the loud disruption that actually gets a SOC's attention.

What stops it:

Insomnia's edge is that healthcare data almost never lives where you'd expect. Healthcare organisations have sensitive data spread across shared drives, legacy systems, and collaboration platforms with weak governance, which creates a fragmented attack surface way bigger than the core clinical systems. Stolen credentials get an attacker in. Once they're in, ungoverned data sitting outside anyone's watch is easy to find and even easier to take.

The fix here isn't encryption-focused, because Insomnia never encrypts anything. It's about actually knowing where your sensitive data sits. Find your high-value data first, improve classification, cut what you don't need, and layer in continuous controls incrementally, a realistic approach if you're a smaller provider without an enterprise security budget, which describes most of Insomnia's victims.

Smarttech247 Research Team

Insights and Intelligence

Our content team turns real-world cybersecurity operations into clear, practical insight. We work directly with service delivery, threat intelligence, and incident response teams to ensure accuracy and credibility. We focus on resilience over fear, explaining how organisations reduce risk, detect threats faster, and recover confidently.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365