Arctic Wolf A.I CyberSecurity Scoring
Arctic Wolf
Company Information
Website:https://arcticwolf.com
Employees number:3,314
Number of followers:151,921
NAICS:541514
Industry Type:Computer and Network Security
Homepage:arcticwolf.com
Arctic Wolf Risk Score (AI oriented)
Between 0 and 549
Arctic WolfComputer and Network Security
Updated:
27/08/2026
27/08/2026
518/1000
Critical
C
Arctic Wolf Global Score (TPRM)
xxxx
Arctic WolfComputer and Network Security
Score locked

Arctic WolfCritical
Current Score
518C (CRITICAL)
01000
5 incidents
-49.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
519
AUGUST 2026
516
JULY 2026
505
JUNE 2026
502
Vulnerability
01 Jun 2026 • Arctic Wolf
Citrix, Kontron, The Gentlemen RaaS Victims and Anubis Ransomware Victims: Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors
498
CRITICAL-4
CITGUIKONARC1783031139
Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors
Threat actors linked to the Anubis ransomware-as-a-service (RaaS) operation are actively exploiting CVE-2025-5777 (Citrix Bleed 2), a critical vulnerability in Citrix NetScaler ADC and Gateway, to gain initial access to victim networks. According to a report by Arctic Wolf, attackers leverage legitimate Remote Management and Monitoring (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment to blend in with normal IT activity while maintaining persistent control.
Anubis, a rebrand of the Sphinx ransomware, emerged in late 2024 and was formally announced on the RAMP underground forum in February 2025. Since then, the group has claimed 91 victims on its data leak site, with 11 reported in June 2026 alone. Targeted sectors include healthcare, business services, manufacturing, technology, and financial services, with over 50% of victims based in the U.S., followed by the U.K., Australia, France, and Canada.
The group employs aggressive tactics, including an irreversible data-wiping feature that reduces files to 0 KB regardless of ransom payment, increasing pressure on victims. Affiliates receive 80% of ransom payments, a lucrative incentive that has fueled the operation’s growth. Beyond Citrix Bleed 2, Anubis actors have also used stolen VPN credentials potentially sourced from initial access brokers, credential stuffing, or info-stealer malware to breach networks via Cisco AnyConnect VPNs, particularly through hosting providers like AS20473 (The Constant Company) and AS55286 (ServerMania).
Once inside, attackers move laterally using RDP and PsExec, deploy RMM tools for persistence, and exfiltrate data via Cloudflare Tunnels, S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. They also disable security defenses, including Windows Defender and Sophos, and manipulate logs to hinder forensic analysis. In some cases, the ransomware encryptor is deleted post-execution, further complicating detection.
### The Gentlemen RaaS and Zero-Day Exploits
Separately, Kaspersky detailed The Gentlemen RaaS, which exploits known vulnerabilities and weak credentials to deploy a Go-based backdoor for remote command execution. The malware collects system data, exfiltrates it to 81.177.215[.]15:9443, and can establish a SOCKS proxy for network pivoting. The group has also weaponized a zero-day vulnerability in ktapi.sys, a Kontron driver, to bypass Windows security protections and terminate processes from Microsoft, ESET, Palo Alto Networks, and SentinelOne.
### VECT and TeamPCP’s Supply Chain-Ransomware Hybrid
A Sophos investigation revealed a partnership between VECT and TeamPCP, announced in March 2026, combining supply chain credential theft with ransomware deployment. TeamPCP, previously operating as CipherForce, rebranded after listing six victims in February 2026. However, VECT’s encryptor contains critical flaws, destroying files larger than 128 KB instead of encrypting them a defect TeamPCP claims it never used in attacks.
The alliance represents a shift toward industrialized ransomware deployment, lowering the barrier for cybercriminals by merging large-scale supply chain attacks with mature RaaS operations. Despite technical shortcomings, the model poses a growing threat to enterprises.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
500
APRIL 2026
633
Ransomware
01 Apr 2026 • Arctic Wolf
Aurora Ransomware Affiliate Victims: Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations
Aurora Ransomware Affiliate Exposed: AI-Assisted Attacks Target 20+ Organizations
488
CRITICAL-145
ARC1787834061
Aurora Ransomware Affiliate Exposed: AI-Assisted Attacks Target 20+ Organizations
A Russian-speaking affiliate behind the Aurora ransomware was uncovered after an exposed server revealed months of malicious activity, including the use of an AI coding assistant to refine attacks. Between April and July 2026, the operator targeted over 20 organizations across nine countries, primarily in manufacturing, food, agriculture, and professional services.
Investigators from CloudSEK gained unprecedented visibility into the affiliate’s operations after discovering an unsecured directory containing tools, command histories, credential material, and chat logs from Cursor, an AI-powered coding assistant. The records show the operator drafting and optimizing attack sequences in Russian, including exploits for Active Directory Certificate Services a critical vulnerability that grants domain-level access.
The affiliate followed a repeatable playbook, leveraging tools like NetExec for network reconnaissance, ASREPRoasting and Kerberoasting for credential theft, and BloodHound for mapping attack paths. For deeper access, they employed noPac exploits, NTLM relay attacks (via PetitPotam, PrinterBug, and DFSCoerce), and certificate-service abuse. Notably, the operator used rented SOCKS proxies to obscure their origin and avoid detection.
Aurora’s ransomware was built from a single Zig codebase, an unusual choice for such malware. The Windows variant (sap.exe) and Linux/ESXi locker (encrypt.out) were distributed via a public Cloudflare R2 bucket, then deployed to staging hosts. The malware disabled System Restore, volume shadow copies, and backups before encryption. On ESXi servers, it killed running VMs and encrypted virtual machine files, amplifying disruption.
At least four victims appeared on Aurora’s Tor leak site, and payment records analyzed by CloudSEK and TRM Labs confirmed two ransom settlements, with funds laundered through shared infrastructure. The operator’s logs excluded CIS-allocated IPs and domains, but Russian-language notes and tool documentation reinforced the attribution.
Defenders are advised to monitor Active Directory for credential theft, disable LLMNR/NBT-NS, enforce SMB signing, and rotate krbtgt passwords after suspected breaches. Securing virtualization interfaces and certificate templates can also mitigate risks.
Indicators of Compromise (IoCs) include the Aurora Tor negotiation site, SHA-256 hashes for the Windows (sap.exe) and Linux/ESXi (encrypt.out) lockers, and multiple operator VPS IPs used for proxies and C2 communication.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
633
FEBRUARY 2026
630
JANUARY 2026
670
Cyber Attack
01 Jan 2026 • Arctic Wolf
ConnectWise, LogMeIn, Kaseya, O&O Software, WebEx, Arctic Wolf, Oracle and Google: ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026
624
HIGH-46
ARCCONO&OLOGKASORAWEBGOO1784262481
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026
A series of high-profile cyber threats and law enforcement actions have marked the first half of 2026, targeting individuals, businesses, and critical infrastructure across multiple regions.
### Phishing Campaigns Exploit RMM Tools and AI-Generated Lures
A sustained phishing operation, SeasonalInvite, has been active since January 2026, abusing commercial Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr to compromise Windows and macOS users. The campaign leverages seasonal themes, distributing malicious links via phishing emails and poisoned search results. Researchers identified 959 eCard-themed domains and a traffic distribution system (TDS) using 2,658 gate pages to evade security scanners. The phishing pages appear to be AI-generated, suggesting threat actors used large language models (LLMs) to rapidly adapt their tactics.
### Chrome Sync Feature Abused for Surveillance
A legitimate Chrome feature designed for cross-device synchronization has been weaponized by stalkers and cybercriminals. By briefly accessing a victim’s device, attackers can add a controlled Google account and enable sync, allowing them to monitor browsing history, bookmarks, and saved passwords in real time. The method requires no malware, making detection difficult.
### Spanish Police Dismantle €140M Cybercrime Network
Authorities in Spain, in collaboration with international partners, disrupted a €140 million cybercrime operation involving fake investment platforms, CEO fraud, and adversary-in-the-middle (AitM) attacks. Four suspects were arrested two in Portugal, one in Spain, and one in Panama. The group used 800+ bank accounts and a network of "money mules" to launder funds, funneling stolen cryptocurrency through third-country accounts.
### UAT-11795 Deploys Starland RAT and WLDR Implant in U.S. and Europe
A Russian-speaking threat actor, UAT-11795, has been targeting users in the U.S. and Europe since June 2025 with a Python-based remote access trojan (RAT) called Starland and a PowerShell-based C2 implant (WLDR agent). The campaign uses trojanized installers for popular software like MobaXterm, WebEx, Zoom, and DBeaver, delivering payloads via ClickFix lures. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine, enabling stealthy data exfiltration and further payload deployment.
### Ransomware Attack Encrypts Network in Under 24 Hours
An unnamed ransomware group compromised an internet-facing IIS web server in June 2026, deploying a Rust-based ransomware strain dubbed Spirals within 24 hours. The attackers used an ASP.NET web shell for initial access, disabled endpoint security, dumped the Security Account Manager (SAM) hive, and spread laterally using PsExec. The ransom note threatened to publish stolen data after six days if demands were not met.
### Vidar Stealer and XMRig Miner Campaign Targets Global Victims
A financially motivated campaign detected in April 2026 delivers Vidar stealer (targeting browser credentials, cookies, and crypto wallets) and XMRig cryptocurrency miner via malvertising. The malware, distributed through cracked software lures, uses the Factory-v3 malware-as-a-service (MaaS) framework. Operators monetize stolen data on criminal markets while generating passive income from hijacked CPU cycles.
### Fake GitHub Repositories Spread Windows Infostealer
A Russian-speaking threat actor created 290+ fake GitHub repositories impersonating trusted vendors like Arctic Wolf to distribute a Windows infostealer with the same codebase as BoryptGrab-Lineage. The malware targets 41 cryptocurrency wallet paths and 19+ browsers, exfiltrating stolen data to a Russian-hosted C2 server. The campaign highlights the risks of brandjacking and supply chain attacks.
### Dutch Authorities Arrest Alleged Mastermind Behind 700-Person Scam Network
A 46-year-old man with Israeli and Polish citizenship was arrested in the Netherlands for allegedly running a global investment fraud network employing 700+ scammers across 20 call centers. Victims were manipulated into depositing funds often in cryptocurrency into fake platforms, with scammers maintaining contact for months to build trust. The operation is linked to €140 million in losses.
### New Phishing Toolkits and MFA Bypass Techniques Emerge
- Jalisco: An AI-powered device code phishing toolkit that provisions fresh OAuth codes in real time, bypassing time-based MFA defenses.
- OmegaLord: A JavaScript-based credential harvester that impersonates a PDF reader and collects phone numbers alongside passwords to intercept MFA codes.
### U.S. and Allies Sanction Russian Cybercrime Groups
The U.S., U.K., and Australia imposed sanctions in November 2025 on Media Land LLC, ML.Cloud LLC, and three Russian nationals Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova for cybercrimes causing $62+ million in losses. The Rewards for Justice (RFJ) program offers up to $10 million for information on their activities.
### Critical Vulnerabilities Added to CISA’s KEV Catalog
CISA added two high-severity flaws to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-46817: An improper privilege management vulnerability in Oracle E-Business Suite.
- KNX Protocol Connection Authorization Option 1: An overly restrictive account lockout mechanism with unknown exploitation details.
### Eastern European C2 Infrastructure Mapped
A Hunt.io analysis uncovered 3,900+ threat-activity-enabling servers across 302 Eastern European providers, with Russia’s Media Land leading (1,277 IPs), followed by Tactical RMM (232) and Acunetix (173). The findings underscore the region’s role in hosting cybercriminal infrastructure.
### Malicious NuGet Packages Drop Surveillance Payloads
Eleven malicious NuGet packages, masquerading as game utilities and productivity tools, were found delivering a Python-based infostealer ("pepesoft.exe") from GitHub and Hugging Face. The payload uses AWS-style key material for remote configuration, binds activations to hardware, and includes a BitTorrent fallback mechanism.
### Windows Bind Links Exploited to Bypass EDR
Bitdefender researchers demonstrated three techniques File-Binding, Process-Binding, and Silo-Binding that abuse Windows’ bind links to evade EDR detection. While Microsoft rated the findings as low severity (requiring admin access), the methods highlight potential gaps in endpoint security.
### Key Takeaways
- Phishing and RMM abuse remain dominant attack vectors, with AI-generated lures increasing in sophistication.
- MFA bypass techniques (e.g., device code phishing, OAuth abuse) are evolving, reducing the effectiveness of traditional defenses.
- Ransomware and infostealers continue to target businesses and individuals, with 24-hour encryption timelines becoming more common.
- Law enforcement actions have disrupted major cybercrime networks, but threat actors rapidly adapt.
- Supply chain risks persist, with fake repositories and trojanized software posing significant threats.
The first half of 2026 has seen a surge in financially motivated cybercrime, state-linked activity, and novel evasion techniques, underscoring the need for robust detection and response strategies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
673
Vulnerability
12 Dec 2025 • Arctic Wolf
Fortinet and Arctic Wolf: Attackers are exploiting auth bypass vulnerability on FortiGate firewalls (CVE-2025-59718)
Exploitation of CVE-2025-59718 to Bypass Authentication on Fortinet FortiGate Firewalls
669
LOW-4
FORARC1765986943
Fortinet Firewall Vulnerabilities Exploited in Active Attacks
Attackers are actively exploiting a recently disclosed vulnerability (CVE-2025-59718) to bypass authentication on Fortinet’s FortiGate firewalls, enabling them to export sensitive system configuration files. Arctic Wolf researchers reported the campaign on Tuesday, warning that stolen configurations may contain network infrastructure details, security policies, and encrypted credentials—data that could facilitate future attacks.
The vulnerability, along with a related flaw (CVE-2025-59719), stems from improper cryptographic signature verification. Both can be exploited by sending a crafted SAML response to a vulnerable device, tricking it into granting unauthorized access. CVE-2025-59718 affects FortiOS (FortiGate), FortiProxy, and FortiSwitchManager, while CVE-2025-59719 impacts FortiWeb.
Fortinet disclosed the vulnerabilities on December 9, 2025, and released patches, advising customers to upgrade or disable the FortiCloud SSO login feature if enabled. The flaw is not active by default but can be triggered if administrators register devices to FortiCare without disabling the "Allow administrative login using FortiCloud SSO" option.
Arctic Wolf observed intrusions beginning December 12, with attackers using malicious SSO logins—primarily targeting the admin account—before exfiltrating configurations via the GUI. The attacks originated from IP addresses linked to multiple hosting providers.
CISA has added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to remediate the flaw by December 23, 2025. Organizations using affected Fortinet products are advised to check logs for suspicious activity and reset compromised credentials if breaches are detected.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
673
OCTOBER 2025
671
JUNE 2025
765
Ransomware
16 Jun 2025 • Arctic Wolf
Sophos, Barracuda Networks and Arctic Wolf: Black Hat: Organizations Face Multiple Ransomware Hits
Ransomware Resurgence: Barracuda Report Reveals Alarming Trends at Black Hat USA 2025
662
HIGH-103
SOPBARARC1768969865
Ransomware Resurgence: Barracuda Report Reveals Alarming Trends at Black Hat USA 2025
At Black Hat USA 2025, Barracuda Networks unveiled a stark report on ransomware’s evolving threat landscape, revealing that 31% of victims were attacked multiple times in the past year a trend driven by fragmented security defenses and persistent gaps in protection. The findings, based on a survey of 2,000 IT and security decision-makers across North America, Europe, and Asia-Pacific, paint a troubling picture of modern cyber threats.
Key takeaways from the report include:
- 57% of organizations suffered a successful ransomware attack in the last 12 months.
- 71% of those hit by email breaches were also targeted by ransomware, underscoring email as a primary attack vector.
- Only 32% of victims paid a ransom, and just half of those recovered all their data.
- Fragmented security tools and insufficient coverage in critical areas particularly email security left organizations vulnerable to repeat attacks.
Adam Khan, Barracuda’s VP of global security operations, highlighted that less than half of ransomware victims had implemented email security solutions, despite email being a leading entry point. The report also noted that ransomware attacks are now multi-dimensional, combining data encryption, theft, and secondary payloads for maximum disruption.
Beyond financial losses, attacks inflicted reputational damage (41%), lost business opportunities (25%), and pressure on partners and employees (22%), signaling a shift toward broader operational and psychological impact.
---
Sophos and Rubrik Partner to Strengthen Microsoft 365 Resilience
In a separate announcement, Rubrik and Sophos unveiled a strategic partnership to deliver the first MDR-optimized Microsoft 365 backup and recovery solution, integrated into Sophos Central. The offering aims to combat ransomware, account compromise, and data loss across SharePoint, Exchange, OneDrive, and Teams by unifying threat detection and recovery in a single workflow.
Raja Patel, Sophos’ chief product officer, emphasized the solution’s ability to simplify operations for partners, enabling automated recovery triggered by MDR alerts and creating new revenue streams. Rubrik CEO Bipul Sinha noted the partnership’s focus on AI-driven threats, stressing the need for rapid recovery capabilities in an era of sophisticated breaches.
---
Darktrace’s 2025 Mid-Year Retrospective: AI-Powered Threats and SaaS Exploitation
Darktrace’s retrospective of H1 2025 highlighted the growing use of AI by threat actors, including highly convincing phishing emails and automated campaigns at unprecedented scale. The report also flagged SaaS exploitation as a critical concern, citing lack of visibility and business-level controls in cloud environments.
Nathaniel Jones, Darktrace’s VP of security and AI strategy, warned that user vigilance alone is insufficient, advocating for AI-driven defense systems to counter advanced threats like Blind Eagle. While law enforcement collaborations such as the takedown of Lumma Stealer show progress, the report cautioned that new threats will continue to emerge, with AI adoption expected to expand into deepfakes, malware development, and tooling.
---
Additional Black Hat Announcements
Other notable developments included:
- Arctic Wolf, Flashpoint, and Cyera unveiling new threat intelligence and data security initiatives.
- Industry-wide discussions on AI’s dual role in both offensive and defensive cyber operations.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Arctic Wolf ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in August 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in July 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in June 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in May 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in April 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in March 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in February 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in January 2026 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in December 2025 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in November 2025 ??
What was Arctic Wolf's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Arctic Wolf's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Arctic Wolf ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Arctic Wolf's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?