logo

Qilin Ransomware Rises Following the Collapse of RansomHub RaaS

ID: badfae66-af6f-5de0-8270-1ab443d6e05b

STIX ID: report--badfae66-af6f-5de0-8270-1ab443d6e05b

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-08-03

Date Updated: 2026-04-13

Author: Priya

...
...

Q2 2025 saw major disruption in the ransomware-as-a-service ecosystem: several dominant groups (including RansomHub, Babuk-Bjorka, FunkSec, BianLian, 8Base, Cactus, and Hunters International) abruptly exited or were disrupted by law enforcement, LockBit suffered an internal data leak, and Qilin nearly doubled activity—recruiting displaced affiliates and offering expanded extortion services (legal assistance, DDoS, spam and data-exposure focused tactics); overall, reported new victims fell to 1,607 in Q2 from 2,289 in Q1 and global ransomware payment rates dropped to roughly 25–27%.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.