LockBit Alumni, Qilin, Hyflock, and The Gentlemen Consolidate Ransomware Landscape
Key Takeaways The first quarter of 2026 saw a significant increase in ransomware attacks, with 2,122 new victims, making it the second-highest Q1 on record. New Ransomware-as-a-Service (RaaS)...
Key Takeaways
- The first quarter of 2026 saw a significant increase in ransomware attacks, with 2,122 new victims, making it the second-highest Q1 on record.
- New Ransomware-as-a-Service (RaaS) programs, Hyflock and The Gentlemen, have emerged, claiming direct links to former LockBit and Qilin operators.
- These new groups leverage advanced tactics, including rapid encryption, multi-platform support, and sophisticated affiliate management, to expand their reach.
- The ransomware market is consolidating, with the top 10 groups responsible for 71% of all reported victims in Q1 2026.
Ransomware Ecosystem Transforms as Alumni Launch New Operations
The global ransomware landscape underwent a notable shift during the first quarter of 2026, marked by a surge in activity and the emergence of new, highly organized criminal enterprises. This period witnessed former operators from established ransomware groups launching their own competing programs, bringing with them valuable institutional knowledge and refined tactics.
Table Of Content
Tracking data leak sites revealed 2,122 new victims in Q1 2026, placing it as the second-highest first-quarter total ever recorded. This substantial activity underscores the persistent growth of the ransomware business, despite ongoing and significant efforts from law enforcement agencies to disrupt these operations, as detailed in a recent report.
New RaaS Programs: Hyflock and The Gentlemen
Among the most prominent developments of the quarter were the introductions of two new Ransomware-as-a-Service (RaaS) programs: Hyflock and The Gentlemen. Both groups rapidly gained traction, appearing in May 2026 and actively recruiting affiliates through well-known dark web forums. What distinguished their arrival was their explicit claims of direct ties to LockBit and Qilin, two of the most historically active and impactful ransomware organizations.
A report shared with Cyber Security News (CSN) by Flare highlighted that these new programs are being launched by operators who assert prior experience with LockBit and Qilin. These individuals are leveraging their expertise in encryption infrastructure, ransom negotiation strategies, and affiliate management to build novel criminal ventures. While Flare acknowledges that these lineage claims are self-reported and lack independent verification, the intricate operational details present in their recruitment advertisements suggest a level of experience that would be challenging to falsify.
This resurgence and reorganization within the ransomware community can be partly attributed to Operation Cronos, the law enforcement action in February 2024 that successfully seized LockBit’s infrastructure. This takedown dispersed a large network of skilled affiliates, who essentially functioned as independent contractors. Two years later, many of these former contractors appear to have regrouped, opting to establish their own operations rather than await the recovery of their previous affiliations.
Further analysis of Q1 2026 data indicates a rapid consolidation of the ransomware market, with a smaller number of dominant players capturing a larger share of illicit activity. The top 10 groups collectively accounted for 71% of all recorded victims during the quarter, a stark contrast to the more fragmented landscape observed just two quarters prior. Qilin emerged as the leading group with 338 victims, while LockBit 5.0 secured fourth place, claiming 163 victims.
Deep Dive into The Gentlemen and Hyflock
The Gentlemen RaaS program experienced explosive growth, escalating from 40 victims in Q4 2025 to 166 in Q1 2026, marking a 315% increase. This surge positioned it as the third most active ransomware group globally within a single quarter. The group’s founder, operating under the pseudonym hastalamuerte, reportedly departed Qilin following a payment dispute and subsequently cultivated The Gentlemen into one of the fastest-expanding programs in the ransomware sphere. In May 2026, the group solidified its position by securing an official partnership with BreachForums, granting it access to a vast network of initial access brokers and penetration testers.
The Gentlemen’s primary appeal to affiliates lies in its generous 90% profit share, which surpasses LockBit’s historical offering by ten percentage points. Its ransomware locker is designed to operate without requiring administrator privileges, supports a wide array of environments including Windows, Linux, NAS, BSD, and ESXi, and features a “silent mode” engineered to bypass common file-rename detection mechanisms. Each build automatically generates a ransom note pre-populated with the affiliate’s contact information, granting them full control over the negotiation process.
Hyflock, on the other hand, distinguishes itself through a focus on fully integrated tooling. The program’s comprehensive panel provides affiliates with capabilities for purchasing initial access, automated negotiation rooms, AI-driven analysis of victim data, and access to a red team for assistance during intrusions. The actor hyflock123 claims that their encryptor operates at approximately twice the speed of LockBit 3.0, although this assertion has not yet been independently verified through benchmarks.
What You Should Do
Security analysts emphasize that the emergence of faster encryption, reduced skill barriers for operators, and the integration of AI for financial analysis of stolen data necessitate a proactive defense strategy. Organizations must prioritize detecting intrusions earlier in the attack chain.
- Monitor Group Policy Object (GPO) Modifications: Both Hyflock and The Gentlemen are known to leverage GPO-based spreading. Enterprises should meticulously monitor Group Policy modification logs for any suspicious activity.
- Isolate Cloud Backup Credentials: Hyflock specifically targets active cloud backups. Ensure that cloud backup credentials are isolated and not accessible via domain administrator paths.
- Enhance Monitoring for “Silent” Attacks: The Gentlemen’s silent mode encrypts files without altering file names or modification dates. Defenders should focus on detecting rapid partial-write patterns from non-elevated processes, rather than relying solely on file extension changes.
- Extend Endpoint Detection to Non-Windows Systems: Both new ransomware programs target ESXi, Linux, and NAS hosts, which often lack comprehensive endpoint detection coverage. Implement robust endpoint detection and response (EDR) solutions across all critical infrastructure, regardless of operating system.
- Implement Robust Credential Monitoring: A 2025 Verizon DBIR report indicated that 54% of ransomware victims had their domain credentials exposed in stealer marketplaces prior to an attack. Proactive credential monitoring is a critical first line of defense.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| QTox Handle | 37BC1EC8D8EEE7ECEA44A953855DAC628DF0920CE41EE4164006BDC95ADEBA5738C870A23686 | Hyflock RaaS operator recruitment contact on QTox, posted on Duty-Free forum |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.