What Ransomware Actually Exploits

Most vulnerability lists rank what could be exploited. CISA's Known Exploited Vulnerabilities catalog carries a quieter and harder-won field: a flag marking the entries known to have been used in ransomware campaigns. That flag is the closest thing there is to a public census of the flaws the extortion economy actually pays for, and this page is our graph read through it — each flagged flaw joined to the groups we tie to it, the payloads at the end of the chain, and what we have written about the conversion.

In our synced copy of the catalog, 352 of 1,685 KEV entries — 20.9% — carry the ransomware flag, and 77 of those 352 are tied to at least one named group by an actor-to-CVE link (all figures measured 2026-08-29). The links reach 54 distinct groups, and their split is the most instructive number on the page: 29 are groups we track as APTs and 25 are ransomware crews. The flag says ransomware; the graph says more than half the named hands on these flaws belong to state-aligned operations — DPRK units deploying ransomware for revenue, espionage sets sharing a doorway with affiliates.

Concentration runs the other way too. Medusa alone holds links to 21 of the 77 actor-tied flaws — more than a quarter of the entire linked set — while the most crew-crowded single entry is a FortiOS authentication bypass with four different crews on it. That shape is what no filter here can express: /cve can already isolate KEV or sort by severity, but it cannot say which flaw is a one-crew tool, which is a lobby everyone walks through, and which carries CISA's flag with no named hand at all. The Cleo flaws anchor a documented mass-extortion wave and hold zero actor links in our graph; that gap is published on this page rather than papered over.

One shelf over, Exploited Edge Devices groups a related set of flaws by where the broken device sits in a network. This page groups by who converts the flaw and into what, and reading the two against each other is the point: the perimeter recurs here not because we selected for it, but because it is where the conversion economy keeps finding the doors unlocked.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Peak weeks

The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Vulnerabilities

KEV marks a vulnerability CISA records as exploited in the wild.

Malware and tooling

Defining tradecraft

Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.

Further reading

Recent activity

The most recent incidents in our log attributed to the groups above, from the last twelve months.

Our coverage

The 12 most recent of 85 briefings that mention a member of this collection.

How this list was chosen. Membership rule: the CVEs are hand-picked from the ransomware-flagged KEV entries our actor-to-CVE layer links most densely, weighted toward rosters that mix crews with state actors — the raw link-count leader, with five links and every one an espionage set, is deliberately absent for that reason — plus MOVEit as a single-link impact reminder and one deliberate zero-link counterexample; the actors are the groups holding the most such links; malware and techniques appear only where the chain is documented in the ATT&CK catalogue or our own cited reporting. Denominators are ours, not CISA's — every count runs over our synced cves table. The link layer itself is thin and mostly machine-made: 107 actor-CVE edges touch ransomware-flagged entries, 96 of them medium-confidence and the largest share extracted by an LLM from our own published articles (measured 2026-08-29), so read every link as inherited from cited reporting, not independently established. The kev_ransomware flag is likewise CISA's determination, repeated here rather than re-verified — and it is conservative in both directions: absence of an actor link measures our coverage, not a flaw's innocence (the Cleo entries are the proof), and the flag itself lags the reporting. Five CVEs and three crews on this page also appear on Exploited Edge Devices; that page asks where the device sits, this one asks whose hands are on the flaw, and the recurrence of the perimeter across both is a shared finding, not duplication. Muddled Libra is deliberately absent: its two CVE links are identical to Scattered Spider's, the same activity cluster under a different vendor name. show_incidents is ON because most members are crews actively filing leak-site claims — but we hold no incident-to-CVE table, so no victim below is tied to any flaw above, and every leak-site claim is a claim, not a confirmed breach.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions