Team Cymru Details Ransomware Infrastructure Trends Across 20+ Investigations

· Original article ↗

Summary

Analysis of more than 20 ransomware investigations found recurring use of Rclone, FileZilla, RDP, remote-management tools, VPS hosting, VPNs, and Tor. Team Cymru says static IP blocking is insufficient and recommends behavior-based detection.

Key points

  • Team Cymru analyzed network indicators from more than 20 ransomware investigations conducted with a DFIR partner, covering incidents from April 2025 to April 2026.
  • The research found cross-group use of Rclone and FileZilla for data exfiltration, and RDP and SSH for remote access.
  • Akira operators used varied VPS infrastructure and tools including Rclone, Cobalt Strike, and AnyDesk; some incidents involved exploitation of SonicWall SSL VPN devices.
  • DragonForce affiliates repeatedly used RDP for access and lateral movement, with Cobalt Strike and Tor also observed.
  • Other cases included Clop exploitation of a Gladinet CentreStack system and ransomware affiliates abusing legitimate remote-management tools, VPNs, and tunneling services.
  • The analysis highlights the limits of static IP- and ASN-based blocking and recommends monitoring anomalous data flows, remote-access activity, tool abuse, and tunneling.
  • Specific investigation IOCs were not published; the article includes example Team Cymru Scout queries for threat hunting.

Article Details

Attack Vectors
  • Akira operators used VPS infrastructure for intrusion, C2 and exfiltration. Reported activity included exploitation of SonicWall SSL VPN appliances, Cobalt Strike beaconing, AnyDesk remote access and Rclone transfers over FTP or SFTP.
  • DragonForce affiliates used RDP for access and lateral movement. One observed host conducted RDP brute-force activity; other infrastructure supported Cobalt Strike C2, payload delivery and proxied or Tor-routed access.
  • In a Clop data-theft incident, exploitation traffic targeted a Gladinet CentreStack File Transfer Service system. Two source IP addresses were attributed to commercial VPN services.
  • An INC Ransom affiliate used Rclone for exfiltration. A Qilin incident involved SFTP exfiltration infrastructure and OpenSSH activity.
  • A Lynx incident involved initial access through a Fortinet FortiGate appliance and Rclone-based exfiltration, with 1VPN used to obscure the operator's traffic.
  • A MedusaLocker affiliate used RDP access nodes, SSH/SFTP exfiltration infrastructure and a Chisel implant chained with a Cloudflare Worker to establish a reverse SOCKS proxy.
  • A separate intrusion used a leaked version of LockBit3 and abused SimpleHelp for remote administration.
Defensive Notes
  • Restrict external RDP exposure, enforce multi-factor authentication, and monitor anomalous RDP authentication patterns and Tor exit-node traffic.
  • Monitor MFT appliances for anomalous outbound data flows and maintain robust patch management rather than relying solely on static IP or ASN reputation blocking.
  • Detect anomalous use of exfiltration tools, remote administration software, proxies and tunnels; vet threat-hunting query results before permanently blocking infrastructure.
  • Team Cymru states that it did not publicly share the investigation-specific IOCs because of their sensitivity.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

AnyDesk●  AnyDesk: a proprietary remote desktop application that provides platform-independent remote access to personal computers and other devices.Cloudflare Workersexfiltration infrastructure within AS50340, and AS62212 hosting a Chisel implant chained with a Cloudflare Worker to establish a reverse SOCKS proxy, which is a notably more sophisticated persistence and tunnellingFortinet FortiGate●  Incident 4 (February 2026) involved the Lynx ransomware group obtaining initial access through a Fortinet FortiGate appliance, with infrastructure within AS16276 facilitating Rclone-based exfiltration alongside theGladinet CentreStack File Transfer Serviceas a primary tactic. In this instance, the DFIR team encountered the targeting of a Gladinet CentreStack File Transfer Service system. From analysis of available logs, exploitation traffic originated from five IPSimpleHelp2 (December 2025) involved the leaked version of LockBit3 for an intrusion in which the operator abused SimpleHelp, a legitimate remote monitoring and management (RMM) platform, via infrastructure hosted within AS9009.SonicWall SSL VPNof SonicWall appliances, aligning with broader industry reporting of Akira affiliates targeting SonicWall SSL VPN devices throughout 2025.Team Cymru Scout™Customers with Team Cymru Scout™ can use the following set of queries to identify infrastructure matching the behavior of the ransomware gangs highlighted in this blog. These queries are examples of how customers canWARPfrom five IP addresses, with two notably attributable to commercial VPN services, including Cloudflare's WARP consumer VPN and Private Internet Access (PIA). The remaining three exploitation source IPs were hosted on

Tools

Countries

Related Articles