Ransomware Groups Increasingly Deploy EDR Kill Techniques
ID: f145927f-8bdf-5e24-8030-4477cec772af
STIX ID: report--f145927f-8bdf-5e24-8030-4477cec772af
Feed Name: Infosecurity Magazine (News)
Halcyon’s Q2 2026 ransomware report documents 1,988 publicly claimed attacks by 89 active groups across 101 countries, noting increased sophistication: EDR/AV shutdowns ("EDR-kill") have become routine, attackers are operationalizing AI (including agentic ransomware and AI-disguised malware), some groups can move from breach to encryption in under an hour, and multiple enterprise edge vulnerabilities (e.g., CVE-2025-5777, CVE-2024-40766, CVE-2024-55591) were actively exploited; the report also flags growing evidence of ransomware being used to further state-aligned espionage objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
