What Ransomware Actually Exploits
Most vulnerability lists rank what could be exploited. CISA's Known Exploited Vulnerabilities catalog carries a quieter and harder-won field: a flag marking the entries known to have been used in ransomware campaigns. That flag is the closest thing there is to a public census of the flaws the extortion economy actually pays for, and this page is our graph read through it — each flagged flaw joined to the groups we tie to it, the payloads at the end of the chain, and what we have written about the conversion.
In our synced copy of the catalog, 352 of 1,685 KEV entries — 20.9% — carry the ransomware flag, and 77 of those 352 are tied to at least one named group by an actor-to-CVE link (all figures measured 2026-08-29). The links reach 54 distinct groups, and their split is the most instructive number on the page: 29 are groups we track as APTs and 25 are ransomware crews. The flag says ransomware; the graph says more than half the named hands on these flaws belong to state-aligned operations — DPRK units deploying ransomware for revenue, espionage sets sharing a doorway with affiliates.
Concentration runs the other way too. Medusa alone holds links to 21 of the 77 actor-tied flaws — more than a quarter of the entire linked set — while the most crew-crowded single entry is a FortiOS authentication bypass with four different crews on it. That shape is what no filter here can express: /cve can already isolate KEV or sort by severity, but it cannot say which flaw is a one-crew tool, which is a lobby everyone walks through, and which carries CISA's flag with no named hand at all. The Cleo flaws anchor a documented mass-extortion wave and hold zero actor links in our graph; that gap is published on this page rather than papered over.
One shelf over, Exploited Edge Devices groups a related set of flaws by where the broken device sits in a network. This page groups by who converts the flaw and into what, and reading the two against each other is the point: the perimeter recurs here not because we selected for it, but because it is where the conversion economy keeps finding the doors unlocked.
- Curated entries: 32
- Incidents attributed in the last 90 days: 610
- Members in the CISA KEV catalog: 12
- 82 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Financial Theft (T1657) 4/5 here · 19/194 tracked
- Disable or Modify Tools (T1685) 4/5 here · 40/194 tracked
- Remote System Discovery (T1018) 4/5 here · 43/194 tracked
- Valid Accounts (T1078) 4/5 here · 55/194 tracked
- Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) 3/5 here · 29/194 tracked
- Data Encrypted for Impact (T1486) 3/5 here · 31/194 tracked
- External Remote Services (T1133) 3/5 here · 33/194 tracked
- Remote Services: Remote Desktop Protocol (T1021.001) 3/5 here · 40/194 tracked
- Process Discovery (T1057) 3/5 here · 43/194 tracked
- System Network Configuration Discovery (T1016) 3/5 here · 45/194 tracked
Shared tooling
- Rclone 4/9 here · 31/255 tracked
- PsExec 5/9 here · 64/255 tracked
- Mimikatz 5/9 here · 73/255 tracked
- BlackCat 2/9 here · 3/255 tracked
- ngrok 2/9 here · 11/255 tracked
- AdFind 2/9 here · 15/255 tracked
- LaZagne 2/9 here · 15/255 tracked
- Impacket 2/9 here · 24/255 tracked
- Cobalt Strike 2/9 here · 68/255 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- Cl0p 236 of 725 claims in the week of 2025-02-24 · 32.6% of lifetime output · 644 days after its debut
- The Gentlemen 68 of 629 claims in the week of 2026-06-15 · 10.8% of lifetime output · 91 days after its debut
- RansomHub 62 of 843 claims in the week of 2024-06-03 · 7.4% of lifetime output · 119 days after its debut
- Akira 43 of 1,441 claims in the week of 2025-01-27 · 3% of lifetime output · 385 days after its debut
- Play Ransomware 25 of 946 claims in the week of 2024-06-10 · 2.6% of lifetime output · 378 days after its debut
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Medusa Ransomware 372 incidents — Ransomware · Unknown — 2026-02-14 — The densest actor in the layer: 21 of the 74 actor-linked ransomware-flagged KEV entries carry a Medusa edge (measured 2026-08-16) — print servers, Exchange, Ivanti, SimpleHelp, GoAnywhere, ScreenConnect. Breadth as strategy.
- Play Ransomware 946 incidents — Ransomware · Unknown — 2026-09-10 — Five ransomware-flagged KEV links spanning FortiOS, Exchange and a Windows CLFS flaw — exploit sourcing that kept pace with the patch cycle for years.
- Cl0p 725 incidents — Ransomware · Russia — 2026-09-10 — The economy's mass-exploitation specialist. Two edges in this layer — MOVEit, and the PTC Windchill flaw whose August 2026 campaign ReliaQuest attributes to the group — against waves documented elsewhere on this site; see Mass-Victim Weeks for the shape its exploitation leaves in the leak-site record.
- Akira 1,441 incidents — Ransomware · Unknown — 2026-09-10 — Cisco ASA and Veeam Backup — the two links that bracket an intrusion: the way in, and the backups that would have made extortion survivable. Among the highest-volume filers in our incident log.
- RansomHub 843 incidents — Ransomware · Unknown — 2025-03-31 — Zerologon and PAN-OS chained in a sub-14-hour attack in the reporting we hold — the compressed flaw-to-ransom timeline this economy sells.
- Gunra 34 incidents — Ransomware · Unknown — 2026-09-04 — On the FortiOS authentication bypass alongside three other crews, and the subject of an FBI/CISA advisory in our coverage this month for attacks on hospitals.
- The Gentlemen 629 incidents — Ransomware · Unknown — 2026-09-09 — Two links, both recent-vintage flaws. A crew recruiting affiliates on rare 90% payouts needs a reliable doorway to hand them; our graph shows which ones.
- NightSpire 257 incidents — Ransomware · Unknown — 2026-09-11 — Its FortiOS kill chain is the best-documented single conversion in our own reporting — the article below walks the whole chain.
- Scattered Spider 1 incident — Ransomware · Unknown — 2023-09-11 — The counterexample to 'crews buy zero-days': a 2015 driver flaw, brought along rather than found, exploited to kill EDR rather than to enter.
- Andariel 0 incidents — APT · North Korea — DPRK. Log4Shell, PaperCut, Confluence, TeamCity, ActiveMQ — five ransomware-flagged links from a state unit deploying ransomware for revenue. The row where this page meets How North Korea Earns.
Vulnerabilities
KEV marks a vulnerability CISA records as exploited in the wild.
- CVE-2024-55591 KEV · ransomware — CVSS 9.8 · EPSS 98.3% · KEV added 2025-01-14 — FortiOS/FortiProxy authentication bypass — the most crew-crowded flaw in our graph. Four different ransomware crews (Everest, Gunra, NightSpire, The Gentlemen) hold links to it, which reads less like a tool and more like a shared doorway.
- CVE-2020-12812 KEV · ransomware — CVSS 9.8 · EPSS 49.3% · KEV added 2021-11-03 — FortiOS SSL VPN improper authentication — the previous generation of the same doorway, linked to Hive and Play. Same vendor, same class of failure, four years earlier.
- CVE-2025-5777 KEV · ransomware — CVSS 9.3 · EPSS 100.0% · KEV added 2025-07-10 — CitrixBleed 2. Anubis and DragonForce on one side, Salt Typhoon on the other — the clearest single-CVE convergence of extortion crews and a state actor in our graph.
- CVE-2025-55182 KEV · ransomware — CVSS 10 · EPSS 99.8% · KEV added 2025-12-05 — React Server Components RCE, CVSS 10.0 — the newest software class here, a web framework rather than an appliance, already carrying four actor links: three crews and a China-nexus set.
- CVE-2023-27350 KEV · ransomware — CVSS 9.8 · EPSS 100.0% · KEV added 2023-04-21 — PaperCut print server. Medusa on one link, Andariel on the other — a ransomware crew and a DPRK unit monetising the same flaw. The flag and the state actor sit on one row.
- CVE-2020-1472 KEV · ransomware — CVSS 5.5 · EPSS 99.4% · KEV added 2021-11-03 — Zerologon. Not an entry flaw — a domain-takeover escalation, linked to Conti and to RansomHub, crews from two different generations of the economy. Conversion is not only about getting in.
- CVE-2022-41082 KEV · ransomware — CVSS 8 · EPSS 100.0% · KEV added 2022-09-30 — ProxyNotShell. Exchange as an intrusion surface long outlived its patch cycle; Medusa and Play both hold links.
- CVE-2024-3400 KEV · ransomware — CVSS 10 · EPSS 100.0% · KEV added 2024-04-12 — PAN-OS GlobalProtect command injection — RansomHub beside RedNovember, an espionage-tracked set, on the same flaw.
- CVE-2023-34362 KEV · ransomware — CVSS 9.8 · EPSS 99.9% · KEV added 2023-06-02 — MOVEit. The most consequential ransomware-flagged CVE of its year, and in our graph it is a single edge: Cl0p. A reminder that link count measures our coverage, not impact.
- CVE-2015-2291 KEV · ransomware — CVSS 7.8 · EPSS 9.0% · KEV added 2023-02-10 — An Intel diagnostics driver flaw from 2015 with the lowest EPSS score in this set (0.09, measured 2026-08-16). Scattered Spider brings the vulnerable driver along to blind EDR mid-intrusion — exploited severity is not catalog severity.
- CVE-2024-50623 KEV · ransomware — CVSS 9.8 · EPSS 98.6% · KEV added 2024-12-13 — Cleo Harmony/VLTrader/LexiCom. Ransomware-flagged by CISA and tied by public reporting to a documented Cl0p mass-extortion wave — yet it holds zero actor links in our graph. Included as the honest measure of where our link layer ends.
- CVE-2026-12569 KEV · ransomware — CVSS 9.3 · EPSS 40.6% · KEV added 2026-06-25 — PTC Windchill and FlexPLM. Ransomware-flagged in KEV, added 2026-06-25 with a three-day due date, and the subject of an August 2026 mass-extortion campaign ReliaQuest attributes to Cl0p as 'highly likely' — a custom web shell that steals data with no additional tooling. Unlike Cleo, the wave sits in our own table: 45 Cl0p leak-site claims stamped 2026-08-12.
Malware and tooling
- Clop 2 groups — Malware — The payload at the end of the managed-file-transfer chains — what the MOVEit conversion was for.
- Medusa Ransomware 1 group — Malware — The encryptor behind the widest exploitation portfolio in this layer.
- Akira 1 group — Malware — Deployed after ASA and Veeam exploitation in the chains our links record.
- DEWMODE 2 groups — Malware — The web shell dropped on Accellion FTA appliances in the 2021 Cl0p-linked wave — the earliest fully documented flaw-to-extortion chain in this set. All four FTA CVEs still carry the ransomware flag.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Exploit Public-Facing Application 49 groups — initial-access — Exploit Public-Facing Application — the entry half of the conversion story, and the technique most rows on this page instantiate.
- Exploitation for Privilege Escalation 24 groups — privilege-escalation — Exploitation for Privilege Escalation — the other half. Zerologon and the driver flaw on this page are conversions that happen after the door.
Further reading
- NightSpire Kill Chain: How a FortiOS Zero-Day Became Ransomware's Favorite Front Door Ransomware — 2026-02-01 — The complete conversion, step by step: how one FortiOS flaw became a ransomware front door.
- Access broker exploits Citrix bug to plant DragonForce ransomware Ransomware — 2026-07-10 — The division of labour: an access broker exploits, a crew encrypts — CitrixBleed 2 as a market, not just a flaw.
- FBI and CISA warn of Gunra ransomware hitting hospitals Ransomware — 2026-08-10 — The advisory layer catching up with the graph: FBI and CISA on Gunra's exploitation of the same FortiOS bypass.
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants Ransomware — 2026-02-16 — Two flaws from this page — PAN-OS and Zerologon — chained into a sub-14-hour intrusion.
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Tuboaços da Amazônia Ltda. 2026-09-11 · NightSpire
- DiamondLease 2026-09-11 · NightSpire
- Ozel & Ozel Laws Office 2026-09-11 · NightSpire
- Perimetral Oriental de Bogotá S.A.S. 2026-09-11 · NightSpire
- Eagle Construction 2026-09-10 · Akira
- George Cameron Nash 2026-09-10 · Akira
- Sys-kool 2026-09-10 · Play Ransomware
- HENRYPRATT.COM 2026-09-10 · Cl0p
- Grunthal Welding & Supplies 2026-09-10 · Play Ransomware
- AK Stamping 2026-09-10 · Akira
- HARLEY-DAVIDSON.COM 2026-09-10 · Cl0p
- PharmaEssentia Corporation 2026-09-09 · The Gentlemen
- Air Canada 2026-09-09 · The Gentlemen
- Kyodo USA 2026-09-09 · Akira
- Brentwood Country Club 2026-09-08 · Akira
- GT Distributors 2026-09-08 · Play Ransomware
- CreateASoft 2026-09-08 · Akira
- Red Star Oil 2026-09-08 · Play Ransomware
- Brent Electric 2026-09-08 · Akira
- Hollard Insurance Group 2026-09-07 · The Gentlemen
Our coverage
The 12 most recent of 82 briefings that mention a member of this collection.
- More ransomware crews, but far fewer victims each 2026-09-13
- Ransomware crew says it stole 51,409 Air Canada files 2026-09-10
- North Korea's hacking machine is bigger than Lazarus 2026-09-07
- LockBit leads a four-fold jump in Dutch leak-site listings 2026-09-05
- Settra quietly became one of the busiest extortion crews 2026-09-04
- Exploited bugs up 34% as attackers beat the patch cycle 2026-09-03
- Leak sites turn on Southeast Asia's listed companies 2026-09-03
- Gentlemen ransomware encrypts within two days of break-in 2026-09-01
- New ransomware crew Za Woo opens with 10 German victims 2026-08-30
- Qilin retakes the ransomware top spot from The Gentlemen 2026-08-30
- Ransomware crews turn on Chile after months of quiet 2026-08-29
- Hackers exploit PaperCut zero-day to take over servers 2026-08-28
How this list was chosen. Membership rule: the CVEs are hand-picked from the ransomware-flagged KEV entries our actor-to-CVE layer links most densely, weighted toward rosters that mix crews with state actors — the raw link-count leader, with five links and every one an espionage set, is deliberately absent for that reason — plus MOVEit as a single-link impact reminder and one deliberate zero-link counterexample; the actors are the groups holding the most such links; malware and techniques appear only where the chain is documented in the ATT&CK catalogue or our own cited reporting. Denominators are ours, not CISA's — every count runs over our synced cves table. The link layer itself is thin and mostly machine-made: 107 actor-CVE edges touch ransomware-flagged entries, 96 of them medium-confidence and the largest share extracted by an LLM from our own published articles (measured 2026-08-29), so read every link as inherited from cited reporting, not independently established. The kev_ransomware flag is likewise CISA's determination, repeated here rather than re-verified — and it is conservative in both directions: absence of an actor link measures our coverage, not a flaw's innocence (the Cleo entries are the proof), and the flag itself lags the reporting. Five CVEs and three crews on this page also appear on Exploited Edge Devices; that page asks where the device sits, this one asks whose hands are on the flaw, and the recurrence of the perimeter across both is a shared finding, not duplication. Muddled Libra is deliberately absent: its two CVE links are identical to Scattered Spider's, the same activity cluster under a different vendor name. show_incidents is ON because most members are crews actively filing leak-site claims — but we hold no incident-to-CVE table, so no victim below is tied to any flaw above, and every leak-site claim is a claim, not a confirmed breach.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.