LockBit Alumni and Qilin Drive Ransomware Ecosystem Consolidation
Key Takeaways The first quarter of 2026 saw a significant resurgence in ransomware activity, with 2,122 new victims reported, marking the second-highest Q1 total on record. New...
Key Takeaways
- The first quarter of 2026 saw a significant resurgence in ransomware activity, with 2,122 new victims reported, marking the second-highest Q1 total on record.
- New Ransomware-as-a-Service (RaaS) programs, Hyflock and The Gentlemen, have emerged, reportedly founded by former operators of the notorious LockBit and Qilin ransomware groups.
- These new RaaS offerings feature enhanced capabilities, including faster encryption, broader platform support (Windows, Linux, NAS, BSD, ESXi), advanced tooling like AI-based victim analysis, and attractive affiliate revenue splits.
- The ransomware market is consolidating, with the top 10 groups responsible for 71% of all recorded victims in Q1 2026, indicating a shift towards fewer, more dominant players.
Ransomware Landscape Sees Significant Consolidation and New Entrants from Veteran Operators
The global ransomware ecosystem experienced a notable shift in the first quarter of 2026. This period was characterized by a surge in activity and the emergence of new, sophisticated ransomware-as-a-service (RaaS) programs, many reportedly launched by seasoned operators from previously dominant criminal organizations.
Table Of Content
According to data leak site monitoring, a staggering 2,122 new victims were identified during Q1 2026. This figure represents the second-highest first-quarter total ever recorded, underscoring the persistent and escalating nature of the ransomware threat despite ongoing efforts by law enforcement agencies worldwide. The report by Flare, shared with Cyber Security News (CSN), highlights this concerning trend.
New RaaS Programs Emerge with Veteran Expertise
May 2026 marked the rapid successive appearance of two new RaaS programs: Hyflock and The Gentlemen. Both quickly began recruiting affiliates on dark web forums, drawing significant attention due to their claimed origins. Operators behind these new ventures asserted direct ties to LockBit and Qilin, two of the most prolific ransomware groups in recent history.
Flare’s report emphasizes that while these claims of lineage are self-reported and lack independent verification, the detailed operational knowledge showcased in their recruitment pitches suggests genuine expertise. This expertise encompasses critical aspects of ransomware operations, including encryption infrastructure, ransom negotiation tactics, and affiliate management, indicating a transfer of institutional knowledge into these nascent criminal enterprises.
This development is particularly significant in the context of Operation Cronos, the law enforcement action in February 2024 that dismantled LockBit’s infrastructure. That takedown effectively displaced a large network of skilled affiliates. Two years later, it appears these former contractors are not merely waiting for previous groups to re-establish themselves but are actively building their own independent operations.
Market Consolidation and Dominant Players
The Q1 2026 data also reveals a ransomware market undergoing rapid consolidation. The top 10 ransomware groups were responsible for a staggering 71% of all recorded victims during the quarter. This represents a stark contrast to the more fragmented activity observed just two quarters prior.
- Qilin led the pack, claiming 338 victims.
- LockBit 5.0, despite the earlier takedown, managed to return to fourth place, accounting for 163 victims.
Deep Dive into Hyflock and The Gentlemen
The Gentlemen: A Rapid Ascent
The Gentlemen RaaS program experienced explosive growth, escalating from 40 victims in Q4 2025 to 166 in Q1 2026—a remarkable 315% increase that positioned it third globally within a single quarter. The program’s founder, operating under the alias “hastalamuerte,” reportedly departed from Qilin following a payment dispute. This individual has since propelled The Gentlemen into one of the fastest-growing RaaS programs in the criminal underworld.
In a strategic move, The Gentlemen secured an official partnership with BreachForums in May 2026, granting it access to a vast network of initial access brokers and penetration testers. The program’s appeal to affiliates is further amplified by its generous 90% revenue share, a full ten percentage points higher than LockBit’s historical offering. Technologically, The Gentlemen’s locker operates without requiring administrator privileges, supports a wide array of environments including Windows, Linux, NAS, BSD, and ESXi, and incorporates a “silent mode” designed to bypass common file-rename detection mechanisms. Each build automatically generates a ransom note pre-populated with the affiliate’s contact details, empowering them with complete control over negotiation processes.
Hyflock: Integrated Tooling and Speed Claims
Hyflock distinguishes itself through a focus on fully integrated tooling for its affiliates. Its operational panel offers a comprehensive suite of features, including initial-access purchasing, automated negotiation rooms, AI-driven analysis of stolen victim data, and even access to a red team to support affiliates during intrusions. The actor “hyflock123” has boasted that Hyflock’s encryptor operates at approximately twice the speed of LockBit 3.0, although this claim has yet to be independently verified through benchmarks.
What You Should Do
The evolving ransomware landscape, characterized by faster encryption, lower skill barriers, and AI-enhanced capabilities, necessitates a proactive and robust defense strategy. Defenders must prioritize early intrusion detection and comprehensive endpoint protection. Here are concrete steps:
- Enhance Monitoring for Group Policy Modifications: Both Hyflock and The Gentlemen leverage Group Policy Object (GPO)-based spreading. Organizations should implement rigorous logging and real-time monitoring of GPO changes to detect suspicious activity early in the attack chain.
- Isolate Cloud Backup Credentials: Hyflock specifically targets active cloud backups. Ensure that cloud backup credentials are strictly isolated and not accessible via domain administrator paths to prevent their compromise during a network intrusion.
- Focus on Behavioral Detection, Not Just Signatures: The Gentlemen’s “silent mode” avoids changing file names or modification dates. Security teams should prioritize monitoring for rapid partial-write patterns from non-elevated processes rather than relying solely on file extension changes as an indicator of compromise.
- Extend Endpoint Detection and Response (EDR) Coverage: Many ransomware programs, including Hyflock and The Gentlemen, target ESXi, Linux, and Network Attached Storage (NAS) hosts, which often lack comprehensive endpoint detection. Expand EDR coverage to these critical, often overlooked, environments.
- Proactive Credential Monitoring: Verizon’s 2025 DBIR highlighted that 54% of ransomware victims had domain credentials exposed in stealer marketplaces prior to an attack. Implement continuous monitoring for leaked credentials on the dark web and actively rotate passwords for accounts found compromised.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| QTox Handle | 37BC1EC8D8EEE7ECEA44A953855DAC628DF0920CE41EE4164006BDC95ADEBA5738C870A23686 | Hyflock RaaS operator recruitment contact on QTox, posted on Duty-Free forum |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.