Reporting and research published in mid-January 2026 highlights continued high ransomware activity and rapid evolution in initial-access and evasion tradecraft. A Symantec/Carbon Black Threat Hunter Team study cited by Help Net Security reports ransomware actors claimed 4,737 attacks in 2025, with only brief slowdowns after major disruptions; the abrupt April 2025 shutdown of RansomHub was followed by affiliates quickly shifting to other operations, while LockBit failed to recover after late-2024 law-enforcement action. The same reporting notes a broader shift toward extortion models that don’t rely on encryption, emphasizing data theft and coercion as groups diversify pressure tactics.
Multiple technical reports describe how attackers are improving delivery and resilience. BleepingComputer says Gootloader now uses heavily malformed ZIP files—concatenating 500–1,000 ZIP archives and manipulating ZIP structures (e.g., truncated EOCD)—to crash or defeat common analysis tools while still extracting via Windows’ default utility, supporting its role as an initial-access vector often preceding ransomware. The Register reports DeadLock ransomware uses Polygon smart contracts to frequently rotate proxy infrastructure for victim communications (via an HTML wrapper pointing victims to the Session messenger), complicating blocking and takedown efforts; Group-IB notes DeadLock also departs from typical double-extortion by lacking a public data-leak site and instead threatening underground data sales. Separately, Microsoft-observed phishing described by KnowBe4 shows threat actors exploiting email routing/spoofing misconfigurations to make phishing appear internal (often leveraging Tycoon2FA), while ReliaQuest’s trend report and a separate write-up on CastleLoader describe human-driven initial access (spearphishing/drive-by) and social-engineering lures such as ClickFix being used to stage loaders and follow-on payloads—underscoring that access-broker and loader ecosystems continue to feed ransomware and broader intrusion activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
Symantec and Carbon Black said a new ransomware strain called Warlock was observed exploiting a SharePoint zero-day. The report noted tooling overlaps with prior Chinese espionage activity, suggesting convergence between extortion and espionage tradecraft.
The same January 2026 study reported that LockBit failed to recover after late-2024 law enforcement action and that RansomHub had disappeared, while Akira and Qilin emerged as leading claimants. It also highlighted the growth of encryptionless extortion and continued use of social engineering against cloud and identity systems.
A study published in January 2026 said claimed ransomware attacks reached 4,737 in 2025, while total extortion incidents rose to 6,182, up 23% from 2024. The report concluded that ransomware activity kept growing despite takedowns and ecosystem disruption.
Microsoft publicly reported that attackers were increasingly exploiting email authentication and routing misconfigurations to impersonate organizations' own domains in phishing campaigns. The company warned that successful compromise could lead to credential theft, BEC, partner targeting, and financial loss.
Expel released technical detection guidance for the new Gootloader ZIP technique, including a YARA rule based on distinctive ZIP header and EOCD characteristics. The guidance also recommended changing the default JScript handler and restricting wscript.exe and cscript.exe for downloaded content.
By January 2026, Expel reported that Gootloader operators had adopted a new delivery method using malformed archives made from hundreds to 1,000 concatenated ZIP files. The technique was built to unpack with Windows' native ZIP support while breaking or crashing many analysis and security tools.
Researchers described CastleLoader's infection chain as an Inno Setup installer using AutoIt and a suspended jsc.exe process to perform process-hollowing-like injection. The malware used APIs such as VirtualAllocEx, WriteProcessMemory, SetThreadContext, and ResumeThread to execute payloads in memory while minimizing disk artifacts.
Analysis published in January 2026 said CastleLoader had been used as an initial access mechanism in coordinated campaigns against federal agencies, IT firms, logistics companies, and essential infrastructure providers across North America and Europe. One campaign was reported to have affected about 460 organizations.
ReliaQuest published findings on attacker behavior from September to November 2025, highlighting trust exploitation, reduced infostealer volume after Lumma takedowns, and continued ransomware success through exploitation of known but unremediated vulnerabilities. The report also noted a 57% increase in victims in the professional, scientific, and technical services sector.
Group-IB reported that DeadLock was using Polygon smart contracts to obscure and rapidly rotate command-and-control or proxy infrastructure, complicating defender blocking efforts. The disclosure also noted that many operational details, including initial access, remained unclear.
From September 1 through November 30, 2025, ReliaQuest observed attackers increasingly relying on social engineering, legitimate tools, and code-signing rather than zero-days. BaoLoader dominated incidents, while ClickFix and Maverick also rose, reflecting a broader move toward human-driven initial access and command obfuscation.
Group-IB first observed the DeadLock ransomware operation in July 2025. The group appeared to favor an encryption-only model and used Session-based victim communications rather than a traditional public leak site.
Microsoft observed a surge beginning in May 2025 of threat actors abusing mail-routing and spoofing misconfigurations to send phishing emails that appeared to come from inside targeted organizations. The campaigns used lures such as voicemail, HR, shared document, and password notices, often tied to PhaaS tooling including Tycoon2FA.
In April 2025, the shutdown of RansomHub caused a short-lived dip in ransomware activity, but affiliates quickly moved to other operations and activity rebounded within weeks. The disruption did not prevent 2025 from reaching record claimed attack volumes.
CastleLoader, a multi-stage malware loader later assessed as a serious threat to U.S. government and critical infrastructure organizations, was first identified in early 2025. It was designed for stealthy in-memory payload delivery and evasion of conventional detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceblog.knowbe4.com
Open sourcecybersecuritynews.com
Open sourcereliaquest.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.