Summary: Infostealer malware has become the standard entry method for ransomware attacks in Germany, increasingly replacing exploit-based attack vectors.
From January to May 2026, the ransomware.live platform recorded 182 ransomware incidents in Germany – an increase of 7.7 percent compared to the same period in the previous year. The growing trend shows: attackers are increasingly using stolen credentials from infostealer campaigns as an entry point instead of direct exploits.
Data from ransomware.live, operated by Julien Mousqueton, document 182 confirmed ransomware incidents in Germany in the first five months of 2026. This represents an increase of 7.7 percent compared to January to May 2025.
The observed attack pattern shows a shift in tactics: while ransomware campaigns traditionally began with the use of zero-days or known exploits, attackers have increasingly started by deploying infostealer malware first. This malware family steals login credentials, browser cookies, API tokens and other credentials that are subsequently used for direct system access.
For CISOs, this means an expansion of the attack surface to include the phase before the actual encryption attack. Infostealer campaigns often occur via phishing, infected downloads or watering hole attacks and can remain undetected for long periods. Stolen credentials enable attackers to authenticate legitimately, which complicates detection and prevention measures.
This shift requires an adjustment of defense strategies: in addition to exploit prevention, credential hygiene, multi-factor authentication, endpoint detection, network monitoring of suspicious logons and continuous threat hunting come to the fore.
Source: www.security-insider.de · Published 20 July 2026
Lumi AI News — AI-assisted curation according to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.