Brazil in Akira and Qilin's ransomware sights
Manufacturing, technology and business services are the main targets in Brazil, as Akira, Qilin and DragonForce go after hypervisors.
Brazil appears in several 2026 ransomware threat intelligence reports, with manufacturing and technology hit hardest and a rising focus on hypervisors and corporate VPNs. Reports from ISH Tecnologia, Brandefense, Derp.ca and other threat intelligence firms place Akira, Qilin, DragonForce and LockBit5 among the most active groups in the period.
Brazil landed at the center of several 2026 ransomware threat intelligence reports. An analysis by ISH Tecnologia cited by Estado de Minas found that the sectors most affected in the country were manufacturing and technology, followed by business services and retail. The same study said threat groups are moving away from a narrow focus on workstations and concentrating instead on hypervisors and corporate environments.
Hypervisors and perimeter access
According to that review, the most active campaigns are exploiting VMware ESXi, Microsoft Hyper-V and Nutanix. The attack conditions that make this easier include low adoption of multifactor authentication, hypervisors without dedicated protection layers, and backups reachable over the network.
In the same vein, the report attributes a greater focus by Akira, Qilin and DragonForce on compromising hypervisors inside organizations in Brazil and across Latin America. The aim is not just to encrypt isolated endpoints, but to target control points that can affect virtualization, backups and operational availability at the same time.
VPN exposure remains a recurring entry vector as well. A CSO Online article, citing Huntress, said advanced actors used VPNs for initial access in about 70% of cases. The same piece said Akira is known for exploiting VPN vulnerabilities and abusing legitimate credentials, especially in Ivanti, Cisco and Fortinet products.
Brandefense added that the most commonly observed initial access vector for Akira was Cisco AnyConnect SSL VPN in environments without MFA, with specific reference to CVE-2023-20269. The firm also said Akira affiliates expanded their focus to other edge-device vulnerabilities, including Cisco IOS XE and Palo Alto GlobalProtect.
Most heavily hit sectors
Activity dashboards point to pressure on specific industries. Brandefense placed LockBit5 among the ransomware groups with the strongest growth in activity in the second quarter of 2026 and said Brazil was among its five most targeted countries, alongside the United States, Italy, Germany and Mexico. During that period, the group's most attacked sectors were business services, manufacturing, technology and healthcare.
Infosecurity Magazine also reported that in the second quarter of 2026, manufacturing was the most targeted industry globally by ransomware, followed by business services, retail and software. In the same report, Qilin led ransomware activity for the period, while DragonForce, Akira and LockBit 5.0 were also among the top groups by attack claims.
AhnLab, in its June 2026 report, showed the same pattern. Manufacturing was the most affected sector worldwide that month, followed by information and communications, professional, scientific and technical services, and health and social welfare. The same firm placed Qilin at the top of its ransomware group ranking for the month, with Akira, LockBit 5.0 and DragonForce in the top 10.
Brazil in global trackers
Other trackers reinforce the regional picture. Derp.ca ranked Akira, Qilin and DragonForce among the most active ransomware groups globally in 2026, with hundreds of claimed victims, and marked Brazil as one of the countries with the highest number of cases in its Top Countries section.
On a narrower track, Nteve cited a gang with nearly 600 victims across more than 60 countries, based on ransomware.live data, which counts attacks in Brazil and other Latin American countries, though it does not identify specific victims or sectors inside the country. Mallory.ai, meanwhile, used ransomware.live data to mention PP+K as a victim of an attack attributed to Qilin, identifying the company as based in Brazil, although it provided no technical details about the incident.
Brandefense also noted that LockBit5 supports Windows, Linux, macOS, VMware ESXi and FreeBSD, an unusually broad platform footprint among leading groups. In Akira's case, ransomware.live describes most of its initial access vectors as brute-force attempts against Cisco VPN devices using single-factor authentication.
Sources
- Ransomware Tracker - Derp.caderp.ca· Derp.ca
- Ransomware Wing — victims, groups and patternspulse.kalir.io· Pulse (kalir.io)
- Ransomware avança 17,8% e mira o Brasil e toda a LATAMem.com.br· Estado de Minas
- Top 5 Ransomware Groups in Q2 2026: Who They Are ...brandefense.io· Brandefense
- Las plataforma de servicios criminales evolucionannteve.com· Nteve
- Akira group profileransomware.live· ransomware.live
- Qilin Leads Global Ransomware Victim Claims Across ...mallory.ai· Mallory.ai
- Ransomware Groups Increasingly Deploy EDR Killers to Sidestep Defensesinfosecurity-magazine.com· Infosecurity Magazine
- Ransomware groups are hammering your vulnerable VPNscsoonline.com· CSO Online
- 2026년 6월 랜섬웨어 동향 보고서asec.ahnlab.com· AhnLab Security Intelligence Center



