September 15, 2026
From the Disk to the Flows: Ransomware Infrastructure Analysis
Since April 2025, Team Cymru has worked with a digital forensics and incident response (DFIR) company on more than 20 ransomware investigations, predominantly impacting small-to-medium-sized enterprises located in the United Kingdom. For each investigation, our trusted partner shared live indicators of compromise (IOCs) they uncovered from manual host-based forensic analysis as the incidents were ongoing to provide Team Cymru with the best opportunity to analyze and track the operators in our global netflow data and internet telemetry.
Using all of the IOCs provided by our trusted partner, Team Cymru analyzed the IP address attributes and NetFlow communications. This led us to identify useful trends in hosting, services used, protocols, and software leveraged by multiple ransomware gangs.
The reason these IOCs are particularly valuable is that Team Cymru can then build detection rules and tags for detecting ransomware infrastructure to help our community of defenders prevent attacks.
Ransomware Gangs Tracked
Our trusted partner can respond to up to 50 ransomware incidents per year from a range of ransomware gangs. For this research, Team Cymru analyzed the infrastructure used by Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, and Lynx over the course of one year, from April 2025 to April 2026.

Data Exfiltration Technique Trends
Before encrypting the systems of a victim, most ransomware gangs will steal the data beforehand to extort the victim into paying the ransom for not only the decryption keys but also to prevent the release of the stolen data publicly via their Tor data leak sites. Through forensic analysis, our trusted partner tracked and identified multiple techniques utilized by the ransomware gangs they encountered across various engagements. The diagram below (see Figure 2) shows the distribution of techniques across the various ransomware gangs. Tools such as Rclone and FileZilla are some of the most commonly used for data exfiltration used by a wide variety of gangs, as shown in the Ransomware Tool Matrix here.

Notably, Akira has the highest variety of techniques, overlapping with techniques utilized by other gangs. This could be due to a number of factors. One hypothesis is that, as Akira is one of the most active threats with the highest number of victims posted to their Tor data leak site, this variety of techniques could be an indicator that highlights their experience as operators to change their approach based on the breadth of target environments they are able to infiltrate. Another hypothesis could be that Akira has numerous operators working for them who prefer their own techniques that they are used to using to achieve their objectives.
IP Tag Classification Trends
Analysis of the IP Tag classification by Team Cymru also yielded interesting results (see Figure 3 below). Across 10 of the IP addresses used for data exfiltration by four of the ransomware gangs, Team Cymru already had Tags developed that identified them all as a potential concern, which, if observed in any type of outbound data transfer activity, would be a cause for concern.

Explanation of the following proprietary Tags developed by Team Cymru’s Threat Detection Team:
● Risknet: Risky networks are tagged with the "risknet" tag. This tag is used to identify IP addresses belonging to hosting providers that have been associated with an elevated level of suspicious and/or malicious behavior such as scanning, exploitation, brute-forcing, and malware hosting.
● Socks Proxy: A standard internet protocol that exchanges network packets between a client and server through a proxy server, routing traffic through a specified IP address to mask the origin. These IPs are often associated with suspicious traffic from our experience.
● AnyDesk: a proprietary remote desktop application that provides platform-independent remote access to personal computers and other devices.
Detailed Ransomware Infrastructure Trends
Using the IP addresses provided by our trusted partner, we are able to identify infrastructure tactics, techniques, and procedures (TTPs) and trends utilized by the various ransomware gangs across multiple engagements.
Akira Infrastructure
Analysis of network IOCs from six Akira ransomware incidents between June and December 2025 revealed a consistent operational reliance on virtual private server (VPS) infrastructure across a diverse set of autonomous systems (AS) to facilitate intrusion, command and control (C2), and data exfiltration activities.
● In Incident 1 (December 2025), the Akira operator leveraged infrastructure within AS14061 to host a Go Simple Tunnel (GOST) SOCKS5 proxy chain configuration.
● Incident 2 (October 2025) saw the use of AS213250 to host Rclone SFTP nodes, consistent with Akira's well-documented preference for Rclone as a data exfiltration utility.
● Incident 3 (June 2025) demonstrated a more diversified infrastructure footprint, with Cobalt Strike beaconing observed to AS42624, AnyDesk being abused for C2 purposes via AS63018, and an additional Rclone FTP exfiltration node identified within AS19318.
● In Incident 4 (July 2025), the Akira operator utilized AS62240 for SSH-based access and AS64236 to host a FileZilla configuration, again indicative of staging for exfiltration.
● Incident 5 (October 2025) involved Akira using Rclone SFTP nodes within AS14315 alongside two separate VPS providers, AS55286 and AS16276, used to facilitate initial access via exploitation of SonicWall appliances, aligning with broader industry reporting of Akira affiliates targeting SonicWall SSL VPN devices throughout 2025.
● Across multiple incidents, our trusted partner has also observed Akira operators using the hostname “kali” for their VPS servers to connect remotely into target environments.
Collectively, these observations underscore Akira's continued tradecraft of distributing operational infrastructure across multiple, often low-reputation, hosting providers to complicate attribution and disrupt defensive blocking efforts, while maintaining a consistent tooling profile centered on Rclone, Cobalt Strike, and legitimate remote access utilities such as AnyDesk.
DragonForce Infrastructure
Analysis of three DragonForce ransomware incidents between April 2025 and February 2026 highlights a consistent operational pattern centered on the abuse of Remote Desktop Protocol (RDP) for both initial access and lateral movement, supplemented by the use of commodity offensive tooling and anonymizing infrastructure.
● In Incident 1 (April 2025), the DragonForce affiliate leveraged infrastructure within AS57509 to facilitate RDP access, established a Cobalt Strike command and control (C2) channel over AS209132, which doubled as an FTP server for ingressing additional tooling, and deployed a dedicated proxy node within AS59395 to tunnel operator traffic.
● Incident 2 (August 2025), a DragonForce affiliate utilized multiple RDP access nodes observed alongside an RDP session routed over the Tor network, as well as separate infrastructure used to stage and deliver a Cobalt Strike Beacon payload.
● Incident 2 (August 2025) a DragonForce affiliate used multiple RDP access nodes observed across AS33535 and AS36352, an RDP session routed over the Tor network via AS205100, as well as a host on AS9009 to stage and deliver a Cobalt Strike Beacon payload.
● Incident 3 (February 2026) saw continued reliance on RDP by a DragonForce affiliate, with a host within AS57523 observed conducting RDP brute-force activity in addition to multiple successful RDP access events sourced from AS6661 and AS58061, suggesting the DragonForce affiliate either failed to obtain valid credentials from infostealer logs and opted for opportunistic credential guessing against exposed endpoints with Port 3389 open.
Overall, these observations underscore DragonForce affiliates' continued reliance on RDP as a primary intrusion and persistence vector, complezalt Strike as the C2 framework of choice, and a growing willingness to incorporate anonymizing services such as Tor to obscure operator origin. These TTPs reinforce the importance of restricting external RDP exposure, enforcing multi-factor authentication, and monitoring for anomalous RDP authentication patterns and Tor exit-node traffic within enterprise environments.
Clop Infrastructure
Our trusted partner also encountered a Clop data theft extortion incident in December 2025. Clop is historically well-known for the mass exploitation of managed file transfer (MFT) platforms as a primary tactic. In this instance, the DFIR team encountered the targeting of a Gladinet CentreStack File Transfer Service system. From analysis of available logs, exploitation traffic originated from five IP addresses, with two notably attributable to commercial VPN services, including Cloudflare's WARP consumer VPN and Private Internet Access (PIA). The remaining three exploitation source IPs were hosted on AS396073, AS51852, and AS50049.
The pattern of multiple, closed groups highlights the importance of monitoring and threat hunting for anomalous outbound data flows from MFT appliances, and robust patch management over reliance on static ASN- or IP-based reputation blocking.
INC Ransom, LockBit, Qilin, Lynx, and MedusaLocker Infrastructure
Analysis of five different ransomware incidents observed between October 2025 and March 2026 reveals a broadly consistent set of operational patterns centered on the abuse of legitimate remote administration utilities, data exfiltration tooling, and commercially leased VPS infrastructure distributed across numerous autonomous systems (AS).
● In Incident 1 (October 2025), an INC Ransom affiliate leveraged infrastructure within AS208137 to facilitate data exfiltration via Rclone.
● Incident 2 (December 2025) involved the leaked version of LockBit3 for an intrusion in which the operator abused SimpleHelp, a legitimate remote monitoring and management (RMM) platform, via infrastructure hosted within AS9009.
● Incident 3 (December 2025) was attributed to Qilin, with AS14956 observed hosting both SFTP-based exfiltration infrastructure and OpenSSH activity, suggesting a single staging node was used to support multiple post-compromise objectives.
● Incident 4 (February 2026) involved the Lynx ransomware group obtaining initial access through a Fortinet FortiGate appliance, with infrastructure within AS16276 facilitating Rclone-based exfiltration alongside the use of the 1VPN service to obscure the source of the operator’s traffic.
● Incident 5 (March 2026) saw a MedusaLocker affiliate distribute operations across a wider infrastructure footprint, with RDP access nodes observed within AS56694 and AS49505, SSH/SFTP-based exfiltration infrastructure within AS50340, and AS62212 hosting a Chisel implant chained with a Cloudflare Worker to establish a reverse SOCKS proxy, which is a notably more sophisticated persistence and tunnelling configuration designed to blend egress traffic with legitimate Cloudflare-fronted services.
These all of these observations underscore a cross-group convergence in tradecraft, with Rclone and FileZilla being used by multiple gangs, RDP and SSH continuing to serve as primary remote access vectors, increased abuse of legitimate RMM platforms, commercial VPN services, and Cloudflare’s services such Workers and Warp VPN to obfuscate operator activity.
The breadth of autonomous systems leveraged across these incidents further reinforces the limitations of static IP- or ASN-based blocking and highlights the importance of behavior-based detection of exfiltration tooling, RMM abuse, and anomalous tunneling activity within enterprise environments.
Conclusion
From our year-long collaboration with our trusted partner, we learned a lot about the typical infrastructure choices and preferences of multiple ransomware gangs. The IOCs shared helped build and improve our detection rules and IP tagging systems. As a result, Team Cymru's focus on tracking Risknet ranges, Socks Proxies, and AnyDesk Servers will evidently support the early detection and prevention of ransomware attacks.
Akira had the highest variety of techniques, but all TTPs overlapped with other gangs. Therefore, by focusing on Akira, defenders can gain an advantage over other groups using similar tactics. Analysis of all the TTPs across investigations led to interesting findings. This included a notable lack of any custom-coded malware for lateral movement or command-and-control (C2). There was also a constant use of dual-use tools, such as AnyDesk, Rclone, and FileZilla. These signed, legitimate tools are regularly abused by dozens of ransomware gangs.
Further, most of the attackers leveraged network-based attacks, such as exploiting SonicWall SSL-VPNs vulnerabilities, brute-forcing exposed RDP ports, as well as using stolen credentials to access Fortinet Fortigate devices. Offensive security tools (OSTs) such as Cobalt Strike, a staple for cybercriminals for years, also continued to remain a common thread among several gangs. Traffic obfuscation services such as VPN Nodes and Tor Nodes are also to be expected during these incidents, highlighting the importance of being able to detect and mitigate attacks by having the context to be able to identify such services.
About The Lack of Indicators of Compromise
Due to the sensitive nature of sharing IOCs of very specific investigations involving our partner’s customers, we decided not to share the specific IOCs publicly. However, approved researchers, authorities, and officials may contact us for more information on specific ransomware groups. Please use the following form to connect with us and learn more about Team Cymru: https://www.team-cymru.com/contact-us
Relevant Scout Queries
Customers with Team Cymru Scout™ can use the following set of queries to identify infrastructure matching the behavior of the ransomware gangs highlighted in this blog. These queries are examples of how customers can search inside Team Cymru’s NetFlow data for IP addresses that match these behaviors. The results can be used for either alerting or threat hunting. Further research and vetting may be required before permanently blocking them.



