IOC Radar
TLP:WHITE1 IOC

IT threat evolution in Q1 2026. Non-mobile statistics

SE
Securelist
Published May 18, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAkiraBlackCatLockBitINFRASTRUCTUREunknownCAPABILITYAkiraBlackCatCl0pVICTIMunknown
Adversary(3)
Infrastructure
Capability(7)
Victim

Attack Flow7 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/7
Exploit Public-Facing Application
ActionExploit firewall vulnerability
The Interlock group exploited a zero-day vulnerability (CVE-2026-20131) in Cisco Secure FMC firewall management software for initial access.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise1

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2026-20131
exploitintel-blogmalware
High
59
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph1 total IOCs
CVE
CVE1Actors3Malware5REPORTIT threat evolution in Q1 AkiraBlackCatLockBitAkiraBlackCatCl0pINC RansomLockBit
scroll to zoom · drag to pan · click IOC to open