Group IB: Ransomware Groups Reorganize RaaS Ecosystem Through Independence and Absorption of Rivals
TECHWORLD ·
✦ AI Summary
Group-IB analyzed this year’s changes in the ransomware ecosystem and the groups to watch in a Threat Intelligence-based report.
The report said that, away from a structure centered on a small number of large RaaS groups, attack groups are becoming more independent and consolidation among rival groups is accelerating, while public trading of enterprise network access rights fell 27% in 2025 and shifted to a private premium market.
It also highlighted the spread of Extortion-only attacks without file encryption, rising supply chain attacks against MSPs and open-source ecosystems, and the broader use of AI, while laying out proactive response measures and 5 priorities.
Group-IB released a report based on its Threat Intelligence. The report covered key changes in this year’s ransomware ecosystem and analyzed ransomware groups to watch. In the announcement, Group-IB said the ecosystem’s center of gravity is moving away from a structure dominated by a small number of large RaaS groups. It also said attack groups are becoming more independent at a faster pace, while consolidation and absorption among competing groups is accelerating.
The report also examined changes in the structure of the enterprise network access market. Public trades in the market fell 27% in 2025. It added that high-value access rights are shifting to a private premium market.
The report also outlined changes in monetization methods and targets. The Extortion-only model, which does not involve file encryption, is spreading, and the report described it as a way to monetize stolen data. It also said supply chain attacks against MSPs and attacks on the open-source ecosystem are increasing. Such supply chain attacks are characterized by targeting paths that provide access to multiple customers, the report said.
As AI usage expands into ransomware development, stolen data classification, ransom pricing and post-attack monetization, ransomware attacks are becoming both more automated and more sophisticated.
Against this backdrop, the report said the independence of attack groups is accelerating within the existing RaaS-centered structure, while the reorganization of group power is also speeding up.
In the past, the ransomware threat landscape was dominated by a small number of major groups such as LockBit, BlackCat and Cl0p. At the time, major RaaS platforms recruited affiliate attackers, and those affiliates would secure access to enterprise networks and then encrypt systems to share the proceeds.
A defining feature of that structure was that it was relatively predictable. As a result, security teams could understand much of the overall threat landscape just by analyzing the major ransomware groups and programs.
The report said trust in the criminal underground ecosystem is collapsing. It added that this collapse is driving affiliate attackers to go independent and also intensifying competition among groups.
There have been repeated cases of affiliates leaving major programs, including cases in which they left with affiliate funds and cases in which they refused to make payments. After the RansomHub infrastructure was disrupted, DragonForce also claimed that it had joined the group’s cartel. The Gentlemen split from Qilin over an unpaid fee issue involving USD 48,000.
There have also been cases of groups absorbing affiliate attackers and cases of attacks on rival infrastructure. The Gentlemen was analyzed as having built a competing group. In this trend, the number of independent groups has increased.
Some independent groups continued using network access rights obtained through existing programs. Some independent groups also sustained new attack activity. As internal fund and settlement disputes, talent poaching and attacks on rival infrastructure continued within affiliate programs, the independent groups were able to maintain an operational base.
At the same time, the enterprise network access market has been reorganized around private premium trades rather than public ones. Publicly advertised access-right sales in 2025 fell 27%. This 27% decline was analyzed as the result of high-value credentials and access rights moving to private channels rather than of market contraction. As a result, the access-right market has split into a public market for opportunistic access and a premium market for pre-vetted transactions between attackers.
The report said the ransomware revenue model is moving away from file encryption and ransom demands toward an extortion model that monetizes stolen data itself without file encryption. It said the source of revenue is the stolen data itself, creating a structure that generates income regardless of whether victims pay the ransom.
In this context, Hunters International shifted to World Leaks. Hunters International is providing affiliate attackers with tools dedicated to data theft. SnowTeam also launched Leak Bazaar in March.
Leak Bazaar sorts stolen corporate data by category and resells it repeatedly. The report said this shows how the ransomware revenue model is shifting toward the distribution and resale of stolen data.
Along with these changes, ransomware targets are also expanding. Rather than attacking individual companies directly, ransomware groups are choosing service providers as targets, and supply chain attacks against service providers and the open-source ecosystem are taking place. The report said service providers have privileged access to dozens or even hundreds of customer environments, so attacking them can expand both the scale and impact of damage.
As an example, the report cited signs that Vect Ransomware worked with TeamPCP earlier this year. In that process, TeamPCP simultaneously compromised 5 open-source ecosystems. Vect Ransomware later offered individual affiliate keys to 300,000 members of BreachForums and began recruiting attackers on a large scale.
According to the report, AI was used across the full attack chain, including ransomware development, stolen data analysis and ransom pricing. There were signs that AI was used in the development of The Gentlemen’s ransomware builder. AI-driven development traces were also found on data leak sites operated by multiple groups.
AI was used to classify stolen data by type and to screen documents related to cyber insurance. It was also used to adjust ransom demands based on the victim company’s insurance coverage and other information. At the same time, post-attack monetization is also becoming more sophisticated.
Based on these changes, Group-IB said the existing ransomware model centered on large franchises is becoming more distributed and more private. It also said independence and consolidation among attack groups, data-centric extortion, supply chain attacks and the use of AI are combining. Group-IB said a new threat ecosystem is taking shape.
Among the various ransomware groups, Group-IB selected 8 groups to watch based on attack scale, innovation in operations and strategic importance. Among them, Qilin was presented as a particularly notable group on the list.
Qilin recorded 1,062 attacks in 2025 and posted the highest attack volume with 389 attacks in Q1. After emerging as Agenda in 2022, Qilin switched to a Rust-based payload in 2023 and also shifted to a RaaS model in 2023.
Qilin used a data theft-plus-encryption approach and made double extortion its core tactic. It also released a 'legal department' in 2025 that said it would submit evidence of victim companies’ regulatory violations to authorities, and it disclosed plans to operate a call center supporting 7 languages in 2025.
The main initial intrusion vectors for Qilin were Fortinet edge device CVE-2024-21762 and Fortinet edge device CVE-2024-55591. In addition, affiliates from Qilin broke away to form new groups, and The Gentlemen and Devman were cited as groups formed by former Qilin affiliates.
Akira and Cl0p showed differences in scale and operating methods. Akira recorded 695 attacks in 2025 and 201 in Q1, and its main attack regions were concentrated in North America and Europe. Its main attack environments were Windows, Linux and ESXi, and its primary targets were SCADA and production-system hosting hypervisors.
Akira also showed the operational characteristics of enterprise-style ransomware during negotiations. Its negotiation package consisted of decryption of stolen data, guarantees against data deletion and disclosure, security reports and protection against repeat attacks. The ransom was set in line with the victim company’s ability to pay, and the negotiation style relied on sustained pressure.
Cl0p recorded 541 attacks in 2025 and 128 in Q1. Cl0p showed operational characteristics centered on its own core attack capabilities rather than on public affiliate recruitment, and in 2025 it targeted exploitation of vulnerabilities in Cleo MFT, Crush FTP and Oracle E-Business Suite. In the past, there were attacks on MOVEit, GoAnywhere and Accellion, and the group focused on supply chain attacks that simultaneously compromised multiple customers using a specific platform.
SafePay is a private group, and it is understood that its core developers directly command attacks rather than relying on an affiliate network. SafePay had 384 attacks confirmed through 2025.
The Ingram Micro attack is presented as a representative case of SafePay. In that attack, 3.5TB of data was stolen and the number of affected people was tallied at more than 42,000. This shows that large-scale attacks can be carried out by only a small number of specialized attackers even without a large RaaS affiliate network.
DragonForce is presented as a case of expanding its power by absorbing the infrastructure and affiliates of rival ransomware groups. DragonForce recorded 217 attacks in 2025 and 101 attacks in Q1. In 2025, DragonForce attacked the BlackCat leak site and disabled BlackCat infrastructure. It also claimed movement to its own infrastructure after the disruption of the RansomHub infrastructure.
DragonForce exploited SimpleHelp RMM vulnerabilities. The exploited vulnerabilities were CVE-2024-57726, CVE-2024-57727 and CVE-2024-57728. Through this, DragonForce compromised MSPs and expanded attacks across multiple customer networks.
The Gentlemen is an independent group that split from Qilin’s affiliate structure. The Gentlemen recorded 455 attacks in 2025 and 211 in Q1. Accordingly, The Gentlemen was described as the second-largest group by attack volume.
The Gentlemen possesses a database of about 14,700 pre-compromised Fortigate devices. The group uses a method that exploits CVE-2024-55591 and serves to provide access rights to affiliates. It was also confirmed to have used AI tools in ransomware development, and the tools cited included ChatGPT, Gemini and Claude.
In May 2026, The Gentlemen’s internal backend was compromised and more than 16GB of internal files were leaked. Even after the backend compromise, however, The Gentlemen continued recruiting affiliates and also continued its attack activity.
INC Ransom operated in 66 countries and targeted more than 190 industries. INC Ransom recorded 360 attacks in 2025 and 144 in Q1. Its main initial intrusion vector was Citrix NetScaler ADC/gateway vulnerabilities, while its data-theft tool was Restic and its evasion method involved renaming files to names such as 'winupdate.exe.'
First observed in January this year, the group showed the characteristics of a multi-platform RaaS supporting Windows, Linux and ESXi, and it operated by combining supply chain attacks with large-scale affiliate recruitment. The organizations and companies confirmed as victims were Scotland's NHS, McLaren Health Care, Yamaha Motor and Texas Star Bar. It also applied psychological pressure to law enforcement agencies, recovery firms and cyber insurers.
In March, it worked with TeamPCP. The linked supply chain compromise targets were Trivy, Checkmarx KICS, LiteLLM and Telnyx Python SDK. It also provided individual affiliate keys to 300,000 registered members of BreachForums.
However, the leak site was taken offline in mid-April. As a result, the group’s push to expand by combining supply chain compromise and affiliate expansion also came to a halt.
The group also had encryption flaws. Files larger than 128KB could not be recovered, and the analysis concluded that it effectively operated in a form close to a Wiper.
Group-IB argued that the ransomware threat remains persistent and emphasized that response should begin before an attack occurs, not afterward. It said monitoring of access-right trading and supply chains is especially necessary, along with proactive response centered on detecting attacks before ransomware encryption begins.
As the basis for that assessment, Group-IB said 79 active ransomware groups were confirmed in Q1 this year and that leak-site attack postings totaled 2,393 cases. It explained that the 2,393 cases represented a 4.5% increase from the previous quarter.
To respond to these threat changes, Group-IB recommended that corporate security teams focus on 5 priorities. The priorities were: monitoring the cybercrime underground market before attacks; managing partners and service providers as part of the Attack Surface; prioritizing detection of early-stage intrusion and data theft over ransomware encryption; emergency patching of internet-connected edge device vulnerabilities; and preparing for psychological and legal pressure from attackers.
Source: TECHWORLD · Lee Gwang-jae
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406745
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.