Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Mapping the Emerging Alliance Between Qilin, DragonForce, and LockBit

## Cybersecurity: Analysis of Ransomware Alliances

Cybersecurity: Analysis of Ransomware Alliances

In September 2025, a significant development occurred in the ransomware landscape. DragonForce announced an alliance with Qilin and LockBit on a Russian underground forum. This announcement, made on Fri, Sep 15, 2025, highlighted the groups' intention to navigate a challenging criminal environment characterized by increased law enforcement pressure and operational fragmentation.

A detailed analysis by the Cyber Intelligence Team examined this coalition's credibility and implications. The investigation focused on ransomware claim data from 2025, revealing strategic repositioning within a fragmented threat landscape. The alliance serves multiple purposes beyond traditional operational integration.

Recent law enforcement actions have targeted major ransomware groups, including the dismantling of HIVE (Jan 2023), AlphV/BlackCat (Dec 2023), and LockBit (Feb 2024). Operation Cronos severely impacted LockBit, compromising its administrative infrastructure and revealing internal weaknesses.

The ransomware model's appeal has diminished due to this operational pressure, leading to a fragmented landscape. While ransomware claims increased by 61% from Jan to Nov 2025, the top groups' market share declined from 54.8% in 2024 to 53.1% in 2025, indicating a wider distribution of activities.

The alliance announcement led to diverse outcomes for the involved groups. Qilin experienced a significant rise, surpassing Akira in September 2025 to hold 13.07% of total claims for the year. This increase coincided with the alliance announcement, suggesting enhanced visibility or attraction to operators.

In September 2025, a significant development occurred in the ransomware landscape.
Ben Emerson · Thehackingpost

DragonForce showed steady growth, moving from ninth place in August 2025 to eighth by late October. However, LockBit has remained inactive since June 2025, despite announcing a new version in September.

A significant event on the XSS forum also occurred around this time. On Sep 2, 2025, forum administrators conducted a poll regarding the reinstatement of the LockBitSupp account, which was ultimately rejected on Sep 9, just before the alliance announcement.

The analysis indicates that the alliance may be a reputational strategy for survival rather than genuine operational collaboration. LockBit's inactivity and forum ban position it as a liability, potentially using the alliance to maintain brand relevance.

Advertisement

The ransomware threat model is evolving, with groups prioritizing data-exfiltration-only campaigns over traditional encryption-based models. This shift reduces operational risk while maintaining extortion potential, reflecting adaptation to law enforcement pressure and decreasing victim payment rates, which fell by 65% in 2025.

The Qilin-DragonForce-LockBit alliance illustrates the criminal ecosystem's adaptation to international law enforcement actions. Whether symbolic or substantive, the coalition represents strategic shifts among threat actors prioritizing survival and visibility. Continuous monitoring of ransomware trends and tactical changes remains crucial for threat intelligence operations.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories