
FulcrumSec Targets Manchester Airports Group as Krybit and Qilin Escalate Global Extortion Campaigns
A significant surge in ransomware activity over the last 48 hours has seen FulcrumSec target UK aviation infrastructure while Krybit expands its footprint in Southeast Asia. Concurrently, Qilin is exploiting new PAN-OS vulnerabilities.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-0257
- Source:
- Encrygma Intelligence via ASEC and DeXpose
- Read Time:
- 5 min
Executive Summary
Between September 1 and September 3, 2026, the global threat landscape experienced a sharp escalation in ransomware operations. The most prominent incident involved the FulcrumSec group claiming a successful breach of the Manchester Airports Group (MAG), a critical UK infrastructure operator. Simultaneously, the Krybit ransomware group has intensified its targeting of high-value sectors in Thailand and India, including luxury real estate and medical institutes. Intelligence also indicates that the Qilin ransomware collective is actively exploiting a recently identified authentication-bypass vulnerability in Palo Alto Networks (PAN-OS) to facilitate initial access. These events underscore a period of high operational tempo for both emerging and established Ransomware-as-a-Service (RaaS) affiliates.
Threat Analysis
The attack on Manchester Airports Group by FulcrumSec represents a direct threat to the aviation sector. The group has threatened to release sensitive internal data unless a ransom is paid, following the classic double-extortion model. In Southeast Asia, Krybit has emerged as a dominant threat, successfully compromising Reignwood Park Thailand and the Vedantaa Institute of Medical Sciences in India. These attacks demonstrate a shift toward targeting regional luxury markets and healthcare providers where data sensitivity is high. Furthermore, the ASEC Blog reports that Black X has targeted South Korean automotive manufacturers, indicating a coordinated effort by multiple groups to exploit industrial supply chains.
Technical Details
Technical analysis of recent Qilin campaigns reveals the exploitation of CVE-2026-0257, an authentication-bypass vulnerability affecting PAN-OS GlobalProtect portal and gateway components. Once access is gained, Qilin affiliates utilize PsExec for lateral movement and wevtutil.exe to clear Windows event logs, effectively hindering forensic investigations. FulcrumSec appears to be utilizing a modified version of the LockBit 3.0 builder, though they operate as an independent entity. Their TTPs include the use of RDP for persistence and the deployment of custom PowerShell scripts to disable Microsoft Defender Real-Time Protection before executing the final payload.
Attribution Assessment
FulcrumSec is currently assessed as an emerging cybercriminal collective, likely composed of former affiliates from larger, now-disrupted groups. Their infrastructure shows overlaps with previous 'BlackCat' operations. Krybit, while newer, displays a high level of professionalization in their leak site management, suggesting a well-funded RaaS operation. Qilin remains one of the most sophisticated actors, with Cybersrcc noting their ability to rapidly integrate new exploits into their toolkit. The recent activity by Black X and ZaWoo suggests a regional specialization, possibly originating from East Asian threat clusters.
Implications
The targeting of Manchester Airports Group highlights the persistent vulnerability of critical national infrastructure (CNI). Successful data exfiltration in this sector can lead to significant regulatory fines under GDPR and long-term reputational damage. The exploitation of CVE-2026-0257 by Qilin suggests that organizations relying on legacy VPN and gateway configurations are at immediate risk. The broadening of targets to include luxury real estate in Thailand indicates that ransomware groups are diversifying their victim profiles to find 'softer' targets with high liquidity.
Recommendations
Encrygma Intelligence recommends the following immediate actions: 1. Patching: Urgently apply updates for PAN-OS GlobalProtect to mitigate CVE-2026-0257. 2. Credential Hygiene: Implement mandatory multi-factor authentication (MFA) across all external-facing services, particularly RDP and VPNs. 3. Monitoring: Deploy Sigma rules to detect the use of wevtutil.exe for log clearing and unauthorized PsExec activity. 4. Backup Integrity: Ensure offline, immutable backups are maintained and tested regularly to counter double-extortion tactics.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin and TheGentlemen Lead Global Ransomware Surge Targeting Critical Infrastructure and Professional Services

Krybit Ransomware Syndicate Escalates Global Campaign Targeting Critical Infrastructure and Legal Entities

