Ransomware Quarterly Report: 703+ Victims Across Six Active RaaS Brands
Insomnia's latest ransomware report tracks 703+ publicly named victims, six active RaaS brands and a 13-hour median time-to-encrypt, while highlighting intermittent encryption, Rust-based lockers and ESXi targeting.
Xcademia Team
Xcademia Research Team

Ransomware Activity Reaches New Highs in Insomnia's Quarterly Tracking
Ransomware activity continued to intensify in the current quarter, according to cybersecurity company Insomnia, which says its threat-intelligence feed is tracking six distinct active ransomware-as-a-service, or RaaS, brands.
The report identifies 703 publicly named victims, an estimated $206.4 million in ransoms paid during the quarter, and a 13-hour median time-to-encrypt across the tracked ransomware ecosystem. Insomnia also says affiliates are moving between ransomware brands following recent law-enforcement disruptions.
These figures represent Insomnia's own threat-intelligence tracking and estimates. The company does not provide enough methodological detail in the report to independently validate the full ecosystem-wide totals.
Six Ransomware Brands Dominate Insomnia's Tracking
Insomnia's quarterly table identifies six active ransomware groups and provides its estimates for victim counts, median ransom demands and time-to-encrypt.
Ransomware group | Model | Q-victims | Median ransom | Time-to-encrypt |
|---|---|---|---|---|
LockBit 5.0 | RaaS | 182 | $742,000 | 14.3 hours |
Cl0p | Mass exploitation | 94 | $2.1 million | 7.0 hours |
Akira | RaaS / double extortion | 121 | $610,000 | 18.2 hours |
Black Basta | RaaS | 77 | $1.45 million | 9.6 hours |
RansomHub | Affiliate-driven | 165 | $830,000 | 11.9 hours |
Play | Direct intrusion + leak site | 64 | $520,000 | 21.0 hours |
According to Insomnia, LockBit 5.0 recorded the largest victim count among the six tracked brands at 182, followed by RansomHub at 165 and Akira at 121.
Cl0p had the highest median ransom listed in the report at $2.1 million, while Play had the longest reported median time-to-encrypt at 21 hours.

Entry Vectors Shift Toward Internet-Facing Infrastructure
Insomnia identifies several entry vectors in its quarterly tracking.
Edge appliances are described as the primary entry vector, while the report marks valid accounts as rising. Phishing is classified as declining, while supply-chain attacks are described as specialised rather than a dominant category.
The findings reinforce the importance of protecting internet-facing infrastructure and controlling legitimate credentials. However, the report does not provide percentages or a detailed methodology for these classifications.
Intermittent Encryption Changes the Ransomware Detection Challenge
One of the operational trends highlighted by Insomnia is the continued use of intermittent encryption.
Rather than encrypting every byte of a targeted file, the technique described in the report encrypts approximately 16 bytes per 16 KB. Insomnia says this approach can reduce the amount of activity that conventional detection mechanisms observe while still rendering files unusable.
The technique illustrates an important change in ransomware behavior: attackers do not necessarily need to maximize encryption activity to maximize disruption.
For defenders, that can make behavioral detection more important than relying exclusively on the volume of encryption operations.
Rust-Based Ransomware Adds Another Reverse-Engineering Challenge
Insomnia also reports continued movement toward Rust-based ransomware binaries.
According to the report, five of the top ten lockers tracked by the company are now produced as Rust binaries. Insomnia says the use of Rust can complicate reverse engineering and slow the development of decryptors.
The report does not identify all ten lockers in this section or provide additional comparative technical measurements.

ESXi and vCenter Become a Major Ransomware Target
Another trend identified by Insomnia is increased targeting of VMware ESXi and vCenter environments.
The company says attackers are using weaknesses in unpatched VMware infrastructure to encrypt entire data centres in a single burst.
Virtualization infrastructure is particularly significant in ransomware operations because compromising a centralized virtualization environment can potentially affect many workloads at once.
Insomnia's report specifically recommends checking ESXi environments for ransomware-related indicators as part of its ransomware-readiness sweep.
The report does not provide a numerical increase for ESXi and vCenter targeting, so the trend should be understood as Insomnia's observed assessment rather than a quantified industry-wide measurement.
Data-Only Extortion Remains Another Ransomware Strategy
Encryption is not always necessary for attackers seeking leverage.
Insomnia highlights data-only extortion, in which attackers steal information and threaten to publish or otherwise expose it without encrypting the victim's systems.
The report specifically associates this strategy with Cl0p and Lace Tempest and links it to mass exploitation of managed file-transfer products.
This approach changes the defensive problem. Organizations must protect not only system availability but also sensitive information and the systems used to transfer it.
Insomnia Demonstrates Its Ransomware Readiness Workflow
The report also includes command examples for Insomnia's ransomware-readiness workflow.
# Run the full ransomware-readiness preset
$ insomnia -t corp.local --preset ransomware-readiness --ai-validate
# Check every ESXi host in scope for the current RansomEXX / Akira indicators
$ insomnia hunt --actor ransomware-affiliate --target-class esxi
# Produce a CISO-ready readiness brief
$ insomnia report --preset ransomware-readiness --format pdfThe commands demonstrate three parts of the workflow described by the company: running a ransomware-readiness assessment, hunting ESXi systems for specified ransomware indicators, and generating a PDF readiness report.
Insomnia also says its engagements can produce a ransomware-readiness score intended to represent an organization's ability to detect, contain and recover from ransomware.
The company says CISOs have begun using this metric for board reporting, but the report does not provide adoption figures or independent validation of the metric.
What Security Leaders Should Prioritize
Insomnia recommends three immediate actions for security teams.
First, the company recommends auditing internet-facing edge devices and reviewing relevant vulnerability information.
Second, organizations should validate that backups are offline, tested and version-controlled. A backup strategy is only useful during ransomware recovery if the organization can actually restore from it.
Third, Insomnia recommends running live tabletop exercises against ransomware playbooks so incident-response teams can practice their roles before an actual attack.
These recommendations are consistent with a broader defensive principle: ransomware preparedness involves prevention, detection and recovery rather than focusing exclusively on malware detection.

Analysis: Ransomware Defense Is Becoming More Infrastructure-Centric
The announcement highlights a broader shift toward ransomware campaigns that target the infrastructure supporting an organization's operations, not simply individual endpoints.
Internet-facing appliances, legitimate credentials, virtualization platforms and managed file-transfer systems can all become important parts of an attack path.
The combination of intermittent encryption, data-only extortion and virtualization targeting also means that ransomware defense cannot depend on a single detection signal.
For enterprises, this could mean placing greater emphasis on exposure management, identity security, virtualization security, backup validation and rehearsed recovery procedures alongside endpoint protection.
At the same time, the report's headline figures should be interpreted in context. The 703+ victims, $206.4 million estimated ransom figure and 13-hour median time-to-encrypt are Insomnia's reported or estimated measurements, rather than independently established global ransomware statistics.
What the Report Does Not Disclose
Insomnia does not provide detailed methodology for how its 703+ publicly named victims were collected, how the estimated $206.4 million ransom figure was calculated, or how the median time-to-encrypt was derived.
It also does not provide percentage breakdowns for the reported entry-vector categories.
Additional details were not disclosed in the report.
For that reason, the findings are best treated as a view into Insomnia's tracked ransomware ecosystem rather than a complete measurement of global ransomware activity.
The Bottom Line
Insomnia's latest ransomware report identifies six active brands across its tracking and highlights 703+ publicly named victims, a reported $206.4 million in estimated quarterly ransom payments and a 13-hour median time-to-encrypt.
The report's technical observations focus on several recurring themes: intermittent encryption, Rust-based lockers, ESXi and vCenter targeting, credential-based access and data-only extortion.
For defenders, the practical message is broader than malware detection alone. Internet-facing infrastructure, identity controls, virtualization environments, backup recovery and incident-response readiness all remain important parts of ransomware resilience.
Source: Insomnia Security Blog
About the Author