Team Cymru Details Ransomware Infrastructure Trends Across 20+ Investigations

Summary
Analysis of more than 20 ransomware investigations found recurring use of Rclone, FileZilla, RDP, remote-management tools, VPS hosting, VPNs, and Tor. Team Cymru says static IP blocking is insufficient and recommends behavior-based detection.
Key points
- Team Cymru analyzed network indicators from more than 20 ransomware investigations conducted with a DFIR partner, covering incidents from April 2025 to April 2026.
- The research found cross-group use of Rclone and FileZilla for data exfiltration, and RDP and SSH for remote access.
- Akira operators used varied VPS infrastructure and tools including Rclone, Cobalt Strike, and AnyDesk; some incidents involved exploitation of SonicWall SSL VPN devices.
- DragonForce affiliates repeatedly used RDP for access and lateral movement, with Cobalt Strike and Tor also observed.
- Other cases included Clop exploitation of a Gladinet CentreStack system and ransomware affiliates abusing legitimate remote-management tools, VPNs, and tunneling services.
- The analysis highlights the limits of static IP- and ASN-based blocking and recommends monitoring anomalous data flows, remote-access activity, tool abuse, and tunneling.
- Specific investigation IOCs were not published; the article includes example Team Cymru Scout queries for threat hunting.
Article Details
- Attack Vectors
- Akira operators used VPS infrastructure for intrusion, C2 and exfiltration. Reported activity included exploitation of SonicWall SSL VPN appliances, Cobalt Strike beaconing, AnyDesk remote access and Rclone transfers over FTP or SFTP.
- DragonForce affiliates used RDP for access and lateral movement. One observed host conducted RDP brute-force activity; other infrastructure supported Cobalt Strike C2, payload delivery and proxied or Tor-routed access.
- In a Clop data-theft incident, exploitation traffic targeted a Gladinet CentreStack File Transfer Service system. Two source IP addresses were attributed to commercial VPN services.
- An INC Ransom affiliate used Rclone for exfiltration. A Qilin incident involved SFTP exfiltration infrastructure and OpenSSH activity.
- A Lynx incident involved initial access through a Fortinet FortiGate appliance and Rclone-based exfiltration, with 1VPN used to obscure the operator's traffic.
- A MedusaLocker affiliate used RDP access nodes, SSH/SFTP exfiltration infrastructure and a Chisel implant chained with a Cloudflare Worker to establish a reverse SOCKS proxy.
- A separate intrusion used a leaked version of LockBit3 and abused SimpleHelp for remote administration.
- Defensive Notes
- Restrict external RDP exposure, enforce multi-factor authentication, and monitor anomalous RDP authentication patterns and Tor exit-node traffic.
- Monitor MFT appliances for anomalous outbound data flows and maintain robust patch management rather than relying solely on static IP or ASN reputation blocking.
- Detect anomalous use of exfiltration tools, remote administration software, proxies and tunnels; vet threat-hunting query results before permanently blocking infrastructure.
- Team Cymru states that it did not publicly share the investigation-specific IOCs because of their sensitivity.
MITRE ATT&CK
T1021.001 · Remote Desktop ProtocolDragonForce affiliates used RDP for access and lateral movement; MedusaLocker activity also involved RDP access nodes.T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolReported ransomware incidents used SFTP-based infrastructure for data exfiltration, including Akira Rclone nodes and infrastructure associated with Qilin and MedusaLocker.T1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolAn Akira incident included a Rclone FTP exfiltration node.T1090 · ProxyOperators used proxy infrastructure, including an Akira GOST SOCKS5 chain and a MedusaLocker reverse SOCKS proxy established with Chisel and a Cloudflare Worker.T1105 · Ingress Tool TransferIn a DragonForce incident, an FTP server was used to ingress additional tooling, and another host staged and delivered a Cobalt Strike Beacon payload.T1110 · Brute ForceA host used by a DragonForce affiliate was observed conducting RDP brute-force activity.T1190 · Exploit Public-Facing ApplicationAkira incidents involved initial access through exploitation of SonicWall appliances; exploitation traffic in a Clop incident targeted a Gladinet CentreStack File Transfer Service system.T1219 · Remote Access ToolsAkira abused AnyDesk for remote access and C2, while a separate intrusion abused SimpleHelp for remote administration.
Threat Actors
AkiraRansomware gang whose infrastructure was examined across six incidents between June and December 2025.ClopRansomware gang associated with a December 2025 data-theft extortion incident targeting a Gladinet CentreStack File Transfer Service system.DragonForceRansomware gang whose affiliates were examined across three incidents between April 2025 and February 2026.INC RansomRansomware gang whose affiliate used Rclone for data exfiltration in an October 2025 incident.LynxRansomware group involved in a February 2026 incident with initial access through a Fortinet FortiGate appliance.MedusaLockerRansomware gang whose affiliate used RDP, SSH/SFTP exfiltration infrastructure and a reverse SOCKS proxy in a March 2026 incident.QilinRansomware gang to which a December 2025 incident involving SFTP exfiltration infrastructure was attributed.
Malware
Akirayear from a range of ransomware gangs. For this research, Team Cymru analyzed the infrastructure used by Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, and Lynx over the course of one year, from April 2025LockBit3● Incident 2 (December 2025) involved the leaked version of LockBit3 for an intrusion in which the operator abused SimpleHelp, a legitimate remote monitoring and management (RMM) platform, via infrastructure hosted
Vendors
Cloudflareoriginated from five IP addresses, with two notably attributable to commercial VPN services, including Cloudflare's WARP consumer VPN and Private Internet Access (PIA). The remaining three exploitation source IPs wereFortinet● Incident 4 (February 2026) involved the Lynx ransomware group obtaining initial access through a Fortinet FortiGate appliance, with infrastructure within AS16276 facilitating Rclone-based exfiltration alongside theGladinet(MFT) platforms as a primary tactic. In this instance, the DFIR team encountered the targeting of a Gladinet CentreStack File Transfer Service system. From analysis of available logs, exploitation trafficSonicWalltwo separate VPS providers, AS55286 and AS16276, used to facilitate initial access via exploitation of SonicWall appliances, aligning with broader industry reporting of Akira affiliates targeting SonicWall SSL VPN
Products
AnyDesk● AnyDesk: a proprietary remote desktop application that provides platform-independent remote access to personal computers and other devices.Cloudflare Workersexfiltration infrastructure within AS50340, and AS62212 hosting a Chisel implant chained with a Cloudflare Worker to establish a reverse SOCKS proxy, which is a notably more sophisticated persistence and tunnellingFortinet FortiGate● Incident 4 (February 2026) involved the Lynx ransomware group obtaining initial access through a Fortinet FortiGate appliance, with infrastructure within AS16276 facilitating Rclone-based exfiltration alongside theGladinet CentreStack File Transfer Serviceas a primary tactic. In this instance, the DFIR team encountered the targeting of a Gladinet CentreStack File Transfer Service system. From analysis of available logs, exploitation traffic originated from five IPSimpleHelp2 (December 2025) involved the leaked version of LockBit3 for an intrusion in which the operator abused SimpleHelp, a legitimate remote monitoring and management (RMM) platform, via infrastructure hosted within AS9009.SonicWall SSL VPNof SonicWall appliances, aligning with broader industry reporting of Akira affiliates targeting SonicWall SSL VPN devices throughout 2025.Team Cymru Scout™Customers with Team Cymru Scout™ can use the following set of queries to identify infrastructure matching the behavior of the ransomware gangs highlighted in this blog. These queries are examples of how customers canWARPfrom five IP addresses, with two notably attributable to commercial VPN services, including Cloudflare's WARP consumer VPN and Private Internet Access (PIA). The remaining three exploitation source IPs were hosted on
Tools
ChiselAS56694 and AS49505, SSH/SFTP-based exfiltration infrastructure within AS50340, and AS62212 hosting a Chisel implant chained with a Cloudflare Worker to establish a reverse SOCKS proxy, which is a notably moreCobalt Strike● In Incident 1 (June 2025) demonstrated a more diversified infrastructure footprint, with Cobalt Strike beaconing observed to AS42624, AnyDesk being abused for C2 purposes via AS63018, and an additional Rclone FTPFileZilla2) shows the distribution of techniques across the various ransomware gangs. Tools such as Rclone and FileZilla are some of the most commonly used for data exfiltration used by a wide variety of gangs, as shown inGo Simple Tunnel (GOST)● Incident 5 (December 2025), the Akira operator leveraged infrastructure within AS14061 to host a Go Simple Tunnel (GOST) SOCKS5 proxy chain configuration.RClone(see Figure 2) shows the distribution of techniques across the various ransomware gangs. Tools such as Rclone and FileZilla are some of the most commonly used for data exfiltration used by a wide variety of gangs,