Target Industry

Indiscriminate, opportunistic targeting. Critical infrastructure, government, healthcare, manufacturing, education, and private enterprises are all at risk.

Overview

Recent dark web chatter suggests that DragonForce is attempting to formalise a cartel with two of the most prominent ransomware groups: LockBit and Qilin. If successful, this coalition could reshape the ransomware ecosystem, consolidating power among major RaaS (Ransomware-as-a-Service) operators. 

The timing is significant. Qilin is currently the most active ransomware group, responsible for around 15% of global ransomware compromises in the last 30 days, while LockBit has relaunched under LockBit 5.0 following disruption by law enforcement in 2024. DragonForce itself restructured as a cartel in March 2025 and has since targeted competitors such as Mamona and BlackLock RaaS, while absorbing RansomHub. 

Competition between RaaS offerings has intensified in 2025, with groups offering lower ransom cuts to affiliates (Qilin advertises an 85/15 split, LockBit up to 90% for top performers) and value-added services including legal and negotiation support, DDoS capabilities, and even AI-powered chatbots. DragonForce’s push for cartelisation appears aimed at stabilising an increasingly volatile and competitive market. 

Impact

If operationalised, the cartel could lead to: 

  • Larger, more coordinated ransomware campaigns 
  • Greater consistency in extortion tactics (data theft, leaks, DDoS, harassment) 
  • Reduced inter-group conflict and victim overlap 
  • Slower RaaS innovation due to diminished market competition 
  • Increased financial, reputational, and operational damage to victims 

Threat Assessment

Whether this cartel becomes a lasting alliance remains questionable. Historically, ransomware groups have struggled to maintain long-term partnerships due to competing financial motives, language and cultural divides (notably between Russian- and English-speaking operators), and distrust around profit-sharing. However, should the collaboration progress, it as potential to reshape targeting strategies. 

By reducing public conflicts and coordinating terms, these actors may seek to maximise revenues while limiting fragmentation in the market. Therefore there is a realistic possibility of a more structured division of victims or geographies, fewer “gang-on-gang” disputes, and potentially more consistent extortion tactics across multiple brands. 

The coalition, driven by DragonForce, is likely an attempt at quelling fears in the criminal landscape after the groups publicised attacks against competing RaaS. Furthermore is the cooperation holds, we are likely to see a slowing of RaaS innovation due to the lack of market competition. 

Containment, Mitigations & Remediations

  • Invest in dark web credential monitoring solutions to identify any leaked credentials before they can be used in an attempted attack. In 2025, 23% of ransomware attacks were reportedly initiated by the exploitation of compromised credentials. 
  • Strengthen negotiation playbooks: organisations should anticipate a more standardised set of demands and tactics from affiliates aligned with these groups. 
  • Enhance monitoring of entry vectors commonly used by these actors (RDP, VPN appliances, Citrix, Fortinet, phishing campaigns). 
  • Review crisis communication plans to prepare for harassment or public smear tactics, particularly if DragonForce’s hacktivist flair is integrated into cartel operations. 
  • Maintain a strong, intelligence led patching policy that prioritises vulnerabilities that are under active exploitation or those that have a published proof of exploit. 

Threat Groups

Qilin: 

Currently Qilin is the most active ransomware group accounting for 15% of all ransomware compromises over the past 30 days. In recent months Qilin advertises a 85%-15% split with affiliates and additional services such as in-house legal, negotiation support, and DDoS features, highly likely designed to compete against other RaaS. \

The group is known to target education, local government, and industrial firms, with regular use of triple/quadruple extortion (data theft, leaks, DDoS, and direct victim harassment). Multilingual communications and broad targeting make Qilin flexible across both Western and Asian markets. 

Initial access: 

  • Credential theft (phished or reused credentials) 
  • Phishing and business-email-compromise (BEC) flows 
  • Exploitation of known server/OT/enterprise CVEs on exposed services 
  • Compromised third-party/vendor access and supply-chain footholds 

LockBit: 

After operations were impacted by law enforcement in 2024, LockBit has recently relaunched operations under LockBit 5.0 after a 4 month hiatus. The group is known for offering affiliates flexible RaaS options, sophisticated negotiation support, and aggressive extortion methods. Additionally the group offers affiliates between70% and 90% of ransom based on performance.  

Historically LockBit targeting prioritises healthcare, manufacturing, government, and critical infrastructure across Europe and North America. Russian-speaking core operators, though affiliates span multiple regions and languages. 

Initial access: 

  • Compromised RDP / cracked weak Remote Desktop credentials 
  • Stolen VPN/remote-admin credentials 
  • Phishing (malicious attachments, credential harvesting) 
  • Purchased access from Initial Access Brokers (IABs) 
  • Exploitation of unpatched internet-facing appliances and services 
  • Exposed management consoles and poorly-segmented Windows services. 

DragonForce: 

In March 2025, DragonForce publicly restructured itself as a ransomware cartel. 

The group provides backend services such as admin panels, leak sites, encryption tooling to affiliates while permitting them to run other ransomware brands (Ransom Bay white label service). Active recruitment and promotion on Russian-language forums (e.g., RAMP) while maintaining English-facing outreach for global affiliate onboarding. 

Initial access: 

  • Affiliate-sourced access (access bought or shared within cartel) 
  • Phishing and social-engineering 
  • Exposed RDP/VPN/remote admin interfaces 
  • Exploitation of public-facing vulnerabilities on network appliances and web apps 
  • Compromised MSP/third-party credentials for lateral pivoting 

Tactics, Techniques, and Procedures

  • Initial Access: Phishing (T1566), compromised RDP/VPN credentials (T1078), exploitation of public-facing applications (T1190), supply-chain compromise (T1195). 
  • Execution: Command and scripting interpreter (T1059), malware deployment via web shells and remote admin tools. 
  • Persistence: Valid accounts (T1078), registry modification (T1112). 
  • Exfiltration & Impact: Data staged for exfiltration (T1074), data encrypted for impact (T1486), data exfiltration over C2 channels (T1041), denial of service via network floods (T1498). 

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content