Qilin Ransomware Rises Following the Collapse of RansomHub RaaS
ID: badfae66-af6f-5de0-8270-1ab443d6e05b
STIX ID: report--badfae66-af6f-5de0-8270-1ab443d6e05b
Feed Name: Cyber Press
Q2 2025 saw major disruption in the ransomware-as-a-service ecosystem: several dominant groups (including RansomHub, Babuk-Bjorka, FunkSec, BianLian, 8Base, Cactus, and Hunters International) abruptly exited or were disrupted by law enforcement, LockBit suffered an internal data leak, and Qilin nearly doubled activity—recruiting displaced affiliates and offering expanded extortion services (legal assistance, DDoS, spam and data-exposure focused tactics); overall, reported new victims fell to 1,607 in Q2 from 2,289 in Q1 and global ransomware payment rates dropped to roughly 25–27%.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
