Halcyon: Ransomware gangs use AI and EDR-kill tactics to speed up attacks in Q2 2026

Ransomware operators are accelerating attacks and increasingly disabling endpoint detection and response (EDR) tools before encryption, according to Halcyon’s Q2 2026 Ransomware Evolution Report.

Halcyon recorded 1,988 publicly claimed ransomware attacks from 89 active groups targeting organisations across 101 countries during Q2 2026. While overall attack claims fell 5.7% quarter on quarter, the company said attacker tactics became more advanced, pointing to a shift toward faster, more automated and harder-to-detect operations.

A key trend highlighted in the report is the wider use of techniques designed to neutralise EDR capabilities early in an intrusion. Halcyon said what was previously a specialist capability is becoming standard practice among leading ransomware groups, reducing the time defenders have to detect and contain incidents.

The report also points to AI moving from experimentation to operational use, including malware disguised as AI productivity tools, AI-assisted victim negotiations, and what Halcyon researchers believe may be the first “agentic ransomware” capable of autonomously conducting key stages of an intrusion.

Among group activity, Halcyon said TheGentlemen overtook Qilin as the most active group by June after scaling operations with custom tooling intended to disable dozens of security products. DragonForce, meanwhile, was cited for attacks that can progress from initial compromise to ransomware deployment in under an hour by exploiting edge infrastructure vulnerabilities. Manufacturing was the most targeted sector, accounting for almost one in five attacks, followed by construction, business services, retail and software.

Ross Asquith, Solutions Engineering Director, Europe, Halcyon, said:

“What we’re seeing is a ransomware ecosystem that is becoming faster, more automated and far more effective at neutralising the security tools organisations rely on. The widespread use of techniques designed to disable endpoint protection, combined with AI-powered tooling that lowers the barrier to entry for attackers, means organisations can no longer assume traditional controls will buy them the time they need to respond. Resilience today depends on assuming attackers will get in and building the ability, at speed, to detect, contain, recover and continue operating.”

Halcyon also reported growing evidence of ransomware being used to support state objectives, citing Iran-linked actors increasingly disguising espionage campaigns as criminal ransomware operations. The company added that continued data theft and extortion is reinforcing the need for organisations to strengthen both prevention and recovery capabilities.