Skip to content
live markets
S&P 5007,785.76▲ 3.21%NASDAQ26,729.16▲ 2.38%DOW53,732.41▲ 2.33%GOLD4,437.30▲ 11.33%WTI82.40▲ 4.37%BRENT88.52▲ 5.09%EUR/USD1.1573▲ 1.66%USD/JPY159.31▼ 1.92%DXY99.64▼ 1.09%BTC$63,008▼ 0.10%ETH$1,879▲ 0.00%SOL$75.36▲ 0.10%TOTAL CRYPTO$2.25T▲ 0.11%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

Qilin Ransomware Claims 104 Victims in August, Tops Global List

The Qilin ransomware group claimed 104 victims in August, nearly doubling second-place Akira, as new entrants reshape the global threat landscape.

Partner Surfshark VPN

The Qilin ransomware group claimed 104 victims in August, cementing its position as the world’s most active ransomware operation and nearly doubling the total of second-place Akira, which reported 56 attacks. The figures, compiled by security researchers at GBHackers, mark the fourth time in five months that Qilin topped the global ransomware leaderboard, underscoring the group’s relentless expansion and sophisticated affiliate recruitment strategy.

Affiliate Model Fuels Growth

Since the decline of RansomHub in April, Qilin has addressed 398 claimed victims, representing 18.4 percent of all ransomware incidents logged over the past five months. This figure places Qilin more than 70 percent ahead of Akira, which follows at 10.7 percent of total attacks. The group’s rapid growth can be attributed to its robust affiliate program, which offers lucrative incentives and flexible ransomware-as-a-service (RaaS) models. Affiliates departing former RansomHub or other operations find Qilin’s technical features particularly attractive, including multi-tier encryption chains, anonymous payment processing, and customizable leak sites. Total ransomware activity rose to 467 incidents in August, marking the fourth consecutive monthly increase, though still below February’s record highs.

New Entrants Reshape the Landscape

Perhaps the most striking development was the ascent of Sinobi, a newcomer that vaulted into third place after only two months of activity. Sinobi claimed 41 victims, 39 of which are U.S.-based, with the remainder in Australia and Taiwan. Initial speculation linked Sinobi to the Lynx group due to code overlaps and similarities in data leak site design, but Lynx continues to post fresh victims, suggesting the groups operate separately. The Gentlemen group, first observed in early September, has already posted over 30 victims, while Cephalus, first seen in early August, listed ten victims on its onion data leak site. Two Cephalus victims overlap with Qilin and Kawa4096, suggesting alliance networks aimed at amplifying extortion pressure.

Geographic and Sector Targets

Construction, professional services, manufacturing, and healthcare remain the most targeted sectors, followed by IT and technology companies and the automotive and finance industries. Geographically, the United States endures the lion’s share of attacks, but Europe and Canada, particularly Germany and the United Kingdom, continue to experience substantial activity. In the Asia-Pacific region, BlackNevas and Dire Wolf were significant threats, with South Korea, Japan, Thailand, Singapore, and Taiwan each suffering four or more attacks. Meanwhile, LockBit has launched its 5.0 release in an effort to rebound from law enforcement disruptions in 2024, showcasing novel evasion techniques and enhanced negotiation portals. Security researchers urge organizations to strengthen cyber resilience through network segmentation, zero trust policies, immutable backups, and proactive vulnerability management.

Sources: GBHackers; Cyble; Recorded Future; The Record

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch France Tax Authority Confirms Breach Affecting 680,000 Taxpayers Read →