Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Home/Threats/LockBit Alumni, Qilin, Hyflock, and The Gentlemen Consolidate Ransomware Landscape
Threats

LockBit Alumni, Qilin, Hyflock, and The Gentlemen Consolidate Ransomware Landscape

Key Takeaways The first quarter of 2026 saw a significant increase in ransomware attacks, with 2,122 new victims, making it the second-highest Q1 on record. New Ransomware-as-a-Service (RaaS)...

David kimber
David kimber
June 16, 2026 4 Min Read
51 0

Key Takeaways

  • The first quarter of 2026 saw a significant increase in ransomware attacks, with 2,122 new victims, making it the second-highest Q1 on record.
  • New Ransomware-as-a-Service (RaaS) programs, Hyflock and The Gentlemen, have emerged, claiming direct links to former LockBit and Qilin operators.
  • These new groups leverage advanced tactics, including rapid encryption, multi-platform support, and sophisticated affiliate management, to expand their reach.
  • The ransomware market is consolidating, with the top 10 groups responsible for 71% of all reported victims in Q1 2026.

Ransomware Ecosystem Transforms as Alumni Launch New Operations

The global ransomware landscape underwent a notable shift during the first quarter of 2026, marked by a surge in activity and the emergence of new, highly organized criminal enterprises. This period witnessed former operators from established ransomware groups launching their own competing programs, bringing with them valuable institutional knowledge and refined tactics.

Table Of Content

  • Key Takeaways
  • Ransomware Ecosystem Transforms as Alumni Launch New Operations
  • New RaaS Programs: Hyflock and The Gentlemen
  • Deep Dive into The Gentlemen and Hyflock
  • What You Should Do

Tracking data leak sites revealed 2,122 new victims in Q1 2026, placing it as the second-highest first-quarter total ever recorded. This substantial activity underscores the persistent growth of the ransomware business, despite ongoing and significant efforts from law enforcement agencies to disrupt these operations, as detailed in a recent report.

New RaaS Programs: Hyflock and The Gentlemen

Among the most prominent developments of the quarter were the introductions of two new Ransomware-as-a-Service (RaaS) programs: Hyflock and The Gentlemen. Both groups rapidly gained traction, appearing in May 2026 and actively recruiting affiliates through well-known dark web forums. What distinguished their arrival was their explicit claims of direct ties to LockBit and Qilin, two of the most historically active and impactful ransomware organizations.

A report shared with Cyber Security News (CSN) by Flare highlighted that these new programs are being launched by operators who assert prior experience with LockBit and Qilin. These individuals are leveraging their expertise in encryption infrastructure, ransom negotiation strategies, and affiliate management to build novel criminal ventures. While Flare acknowledges that these lineage claims are self-reported and lack independent verification, the intricate operational details present in their recruitment advertisements suggest a level of experience that would be challenging to falsify.

This resurgence and reorganization within the ransomware community can be partly attributed to Operation Cronos, the law enforcement action in February 2024 that successfully seized LockBit’s infrastructure. This takedown dispersed a large network of skilled affiliates, who essentially functioned as independent contractors. Two years later, many of these former contractors appear to have regrouped, opting to establish their own operations rather than await the recovery of their previous affiliations.

Further analysis of Q1 2026 data indicates a rapid consolidation of the ransomware market, with a smaller number of dominant players capturing a larger share of illicit activity. The top 10 groups collectively accounted for 71% of all recorded victims during the quarter, a stark contrast to the more fragmented landscape observed just two quarters prior. Qilin emerged as the leading group with 338 victims, while LockBit 5.0 secured fourth place, claiming 163 victims.

Deep Dive into The Gentlemen and Hyflock

The Gentlemen RaaS program experienced explosive growth, escalating from 40 victims in Q4 2025 to 166 in Q1 2026, marking a 315% increase. This surge positioned it as the third most active ransomware group globally within a single quarter. The group’s founder, operating under the pseudonym hastalamuerte, reportedly departed Qilin following a payment dispute and subsequently cultivated The Gentlemen into one of the fastest-expanding programs in the ransomware sphere. In May 2026, the group solidified its position by securing an official partnership with BreachForums, granting it access to a vast network of initial access brokers and penetration testers.

The Gentlemen’s primary appeal to affiliates lies in its generous 90% profit share, which surpasses LockBit’s historical offering by ten percentage points. Its ransomware locker is designed to operate without requiring administrator privileges, supports a wide array of environments including Windows, Linux, NAS, BSD, and ESXi, and features a “silent mode” engineered to bypass common file-rename detection mechanisms. Each build automatically generates a ransom note pre-populated with the affiliate’s contact information, granting them full control over the negotiation process.

Hyflock, on the other hand, distinguishes itself through a focus on fully integrated tooling. The program’s comprehensive panel provides affiliates with capabilities for purchasing initial access, automated negotiation rooms, AI-driven analysis of victim data, and access to a red team for assistance during intrusions. The actor hyflock123 claims that their encryptor operates at approximately twice the speed of LockBit 3.0, although this assertion has not yet been independently verified through benchmarks.

What You Should Do

Security analysts emphasize that the emergence of faster encryption, reduced skill barriers for operators, and the integration of AI for financial analysis of stolen data necessitate a proactive defense strategy. Organizations must prioritize detecting intrusions earlier in the attack chain.

  • Monitor Group Policy Object (GPO) Modifications: Both Hyflock and The Gentlemen are known to leverage GPO-based spreading. Enterprises should meticulously monitor Group Policy modification logs for any suspicious activity.
  • Isolate Cloud Backup Credentials: Hyflock specifically targets active cloud backups. Ensure that cloud backup credentials are isolated and not accessible via domain administrator paths.
  • Enhance Monitoring for “Silent” Attacks: The Gentlemen’s silent mode encrypts files without altering file names or modification dates. Defenders should focus on detecting rapid partial-write patterns from non-elevated processes, rather than relying solely on file extension changes.
  • Extend Endpoint Detection to Non-Windows Systems: Both new ransomware programs target ESXi, Linux, and NAS hosts, which often lack comprehensive endpoint detection coverage. Implement robust endpoint detection and response (EDR) solutions across all critical infrastructure, regardless of operating system.
  • Implement Robust Credential Monitoring: A 2025 Verizon DBIR report indicated that 54% of ransomware victims had their domain credentials exposed in stealer marketplaces prior to an attack. Proactive credential monitoring is a critical first line of defense.

Indicators of Compromise (IoCs):-

Type Indicator Description
QTox Handle 37BC1EC8D8EEE7ECEA44A953855DAC628DF0920CE41EE4164006BDC95ADEBA5738C870A23686 Hyflock RaaS operator recruitment contact on QTox, posted on Duty-Free forum

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

LockBit Alumni and Qilin Drive Ransomware Ecosystem Consolidation

Next Post

The Quarry Phishing: Attackers Abuse RMM Tools in IRS, SSA Scams

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Windows WalletService Bug (CVE-2024-XXXX) Lets Attackers Escalate Privileges
August 10, 2026
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us