Ransomware Leverage is Growing by the Terabyte: Takeaways from ThreatLabz 2026 Ransomware Report

From the source: Zscaler ThreatLabz

Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in.The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and…

Read the full story on Zscaler ThreatLabz
Originally published by Zscaler ThreatLabz on 30 Sept 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from Zscaler

Recent updates from Zscaler, so you can tell whether this is a one-off or part of a pattern.

All Zscaler news →
Security

2CLoader: A New Malware Loader Delivering Vidar and Remus

In August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information stealers including Vidar and Remus in addition to XWorm RAT. 2CLoader has the ability to perform a wide range of anti-analysis and evasion techniques, including indirect system calls, anti-analysis checks, and installing…

Zscaler·via Zscaler ThreatLabz
SecurityWhy it matters

Threat Actors Use Google Ads To Target Ledger Users

In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…

Zscaler·via Zscaler ThreatLabz
Security

Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation

Vidar is an information stealer that was first observed in 2018. Across its iterations, Vidar has continued to improve its string obfuscation to make detection and analysis more difficult by changing deobfuscation algorithms, constants, and primitives. From May through early September 2026, Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from basic XOR to ChaCha20,…

Zscaler·via Zscaler ThreatLabz

More in Security

What other companies in Security are doing. The category page shows who’s active, side by side.

Compare companies in Security →
Security

Using AI to chart a course for our post-quantum migration

We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far.

Cloudflare·via Cloudflare Blog
SecurityVideo

Streamline: custom video pipelines with Cloudflare Stream and Workers

Streamline demonstrates how to build long-running, continuous video processing pipelines by pairing Cloudflare Workers and Durable Objects with a containerized media engine.

Cloudflare·via Cloudflare Blog
Security

Introducing Web Search API via AI Gateway

Cloudflare AI Gateway now supports native web search API integration in partnership with Ceramic.ai, Exa, and Linkup. Developers can now inject real-time web context into model inference calls via AI Gateway, REST APIs, or Workers bindings.

Cloudflare·via Cloudflare Blog
Security

Updates on our pledge to make Cloudflare features accessible to everyone

A year after pledging to eliminate two-tier product access, Cloudflare has expanded Logpush, multi-account governance, and higher platform limits to all accounts. Here is an update on our progress, how we dogfood these tools internally, and what is coming next.

Cloudflare·via Cloudflare Blog