Mapping the Emerging Alliance Between Qilin, DragonForce, and LockBit
## Cybersecurity: Analysis of Ransomware Alliances
Cybersecurity: Analysis of Ransomware Alliances
In September 2025, a significant development occurred in the ransomware landscape. DragonForce announced an alliance with Qilin and LockBit on a Russian underground forum. This announcement, made on Fri, Sep 15, 2025, highlighted the groups' intention to navigate a challenging criminal environment characterized by increased law enforcement pressure and operational fragmentation.
A detailed analysis by the Cyber Intelligence Team examined this coalition's credibility and implications. The investigation focused on ransomware claim data from 2025, revealing strategic repositioning within a fragmented threat landscape. The alliance serves multiple purposes beyond traditional operational integration.
Recent law enforcement actions have targeted major ransomware groups, including the dismantling of HIVE (Jan 2023), AlphV/BlackCat (Dec 2023), and LockBit (Feb 2024). Operation Cronos severely impacted LockBit, compromising its administrative infrastructure and revealing internal weaknesses.
The ransomware model's appeal has diminished due to this operational pressure, leading to a fragmented landscape. While ransomware claims increased by 61% from Jan to Nov 2025, the top groups' market share declined from 54.8% in 2024 to 53.1% in 2025, indicating a wider distribution of activities.
The alliance announcement led to diverse outcomes for the involved groups. Qilin experienced a significant rise, surpassing Akira in September 2025 to hold 13.07% of total claims for the year. This increase coincided with the alliance announcement, suggesting enhanced visibility or attraction to operators.
In September 2025, a significant development occurred in the ransomware landscape.
DragonForce showed steady growth, moving from ninth place in August 2025 to eighth by late October. However, LockBit has remained inactive since June 2025, despite announcing a new version in September.
A significant event on the XSS forum also occurred around this time. On Sep 2, 2025, forum administrators conducted a poll regarding the reinstatement of the LockBitSupp account, which was ultimately rejected on Sep 9, just before the alliance announcement.
The analysis indicates that the alliance may be a reputational strategy for survival rather than genuine operational collaboration. LockBit's inactivity and forum ban position it as a liability, potentially using the alliance to maintain brand relevance.
The ransomware threat model is evolving, with groups prioritizing data-exfiltration-only campaigns over traditional encryption-based models. This shift reduces operational risk while maintaining extortion potential, reflecting adaptation to law enforcement pressure and decreasing victim payment rates, which fell by 65% in 2025.
The Qilin-DragonForce-LockBit alliance illustrates the criminal ecosystem's adaptation to international law enforcement actions. Whether symbolic or substantive, the coalition represents strategic shifts among threat actors prioritizing survival and visibility. Continuous monitoring of ransomware trends and tactical changes remains crucial for threat intelligence operations.
Based on reporting by GBHackers.
