The ransomware landscape in 2025 is marked by the collapse and absorption of established groups like RansomHub, LockBit, Everest, and BlackLock, creating instability within the criminal ecosystem. Meanwhile, the new ransomware group Qilin is rising rapidly with advanced cross-platform malware, comprehensive affiliate services, and innovative features redefining ransomware-as-a-service models. #RansomHub #LockBit #Qilin #DragonForce #BlackLock
Keypoints
- RansomHub, once dominant in 2024, disappeared abruptly in March 2025, with its infrastructure absorbed by the rival group DragonForce.
- LockBit and Everest ransomware leak sites were defaced by an anonymous actor “XOXO from Prague,” leaking LockBit’s internal data and damaging its reputation.
- BlackLock was breached via a Local File Inclusion vulnerability; DragonForce subsequently defaced its site and leaked internal materials, suggesting a possible soft takeover.
- Qilin is emerging as a major ransomware group using custom Rust and C malware supporting Windows, Linux, and ESXi systems with advanced operational features for affiliates.
- Qilin offers a full-service cybercrime platform including encryption customization, legal consultation during ransom negotiations, spam tools, and PB-scale data storage.
- Qilin ransomware actively targets virtualization environments by enumerating and controlling VMware vCenter, ESXi, and Nutanix hosts, deploying sophisticated payloads.
- Technical analysis reveals Qilin’s Windows loader uses tools like PsExec for network spreading, cleans logs, prints ransom notes via printers, and changes desktop wallpapers to demand ransom.
MITRE Techniques
- [T1569.002] System Services: Service Execution – Qilin ransomware executes malicious actions using command-line parameters and service execution tools like PsExec. (‘The ransomware operates by executing a series of malicious actions…’)
- [T1070.004] Indicator Removal: File Deletion – The ransomware deletes shadow copies and related files to inhibit recovery. (‘Qilin deletes shadow copies…’)
- [T1070.001] Indicator Removal: Clear Windows Event Logs – Clears Windows event logs to cover tracks. (‘Clears windows event logs to cover its tracks, making detection harder…’)
- [T1218] System Binary Proxy Execution – Uses system binaries like PowerShell and PsExec to execute its payload and spread. (‘Runs a PowerShell command to identify and print ransom notes via printers.’)
- [T1087] Account Discovery – Enumerates domain hosts to facilitate lateral movement. (‘Enumerating all domain hosts…’)
- [T1120] Peripheral Device Discovery – Discovers printers to distribute ransom notes. (‘…PowerShell command to identify and print ransom notes via any discovered printers.’)
- [T1675] ESXi Administration Command – Commands used to enumerate and control VMware ESXi hosts. (‘…identifies all linked ESXi hosts, changes the root password, and enables SSH access.’)
- [T1486] Data Encrypted for Impact – Encrypts victim data to demand ransom payments, targeting virtualized and traditional environments. (‘Steal sensitive data… disrupt systems… encrypt target data.’)
- [T1490] Inhibit System Recovery – Deletes shadow copies and disables snapshots to prevent recovery. (‘Cleans system logs and deletes shadow copies… removes all snapshots on ESXi and Nutanix hosts.’)
Indicators of Compromise
- [IP Addresses] FTP data shares and hosting – 185.208.156.157, 185.196.10.19, 80.64.16.87 (WikiLeaks v2 project server)
- [SHA-256 Hashes] Malware samples – Windows variant: 31c3574456573c89d444478772597db40f075e25c67b8de39926d2faa63ca1d8; Linux variant: 13cda19a9bf493f168d0eb6e8b2300828017b0ef437f75548a6c50bfb4a42a09a7, and others
- [File Names] Ransom notes suffixed with _RECOVER.txt – detailed payment instructions dropped on infected machines
- [Domains] Qilin WikiLeaks V2 hosted by OPTIMA LLC – active until at least April 2025
Read more: https://www.cybereason.com/blog/threat-alert-qilin-seizes-control