New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit
## Cybersecurity: Alliance Between Ransomware Groups
Cybersecurity: Alliance Between Ransomware Groups
On September 15, 2025, the ransomware group DragonForce announced an alliance with Qilin and LockBit through a post on a Russian underground forum. This coalition is a strategic response to increased pressure from international law enforcement, which has disrupted several primary ransomware operations in recent years.
Law enforcement actions have dismantled group infrastructures, identified collective administrators, and issued international arrest warrants, making the ransomware ecosystem more fragmented and challenging for groups to recruit operators.
The coalition aims to address challenges within the ransomware criminal ecosystem. Recent data show a 61% year-over-year increase in ransomware claims from January to November 2025 compared to the same period in 2024. However, the top ransomware groups now account for a smaller share of total attacks, declining from 54.8% in 2024 to 53.1% in 2025, indicating a spread across more groups.
Yarix analysts identified this trend while monitoring ransomware claims throughout 2025, assessing the potential risk and credibility of the alliance announcement.
On September 15, 2025, the ransomware group DragonForce announced an alliance with Qilin and LockBit through a post on a Russian underground forum.
Research indicates a decline in ransom payments. The median ransom payment dropped by 65% in Q3 2025 compared to the previous quarter, falling to approximately USD 140,000. Only 23% of victims paid ransoms during this period, reflecting improved organizational preparedness and backup strategies. This reduction has forced ransomware groups to reconsider their operational models.
Changes in Attack Operations and Group Activity
Data Leak Site activity analysis shows distinct patterns among the three allied groups. Qilin emerged as the most active ransomware group in 2025, accounting for 13.07% of all claims between January and November. DragonForce demonstrated steady growth, moving from ninth place in August to eighth place by October 2025, maintaining operational continuity throughout the year.
LockBit showed a different trajectory, publishing no claims from June through November 2025, indicating an inability to recover from Operation Cronos, a major law enforcement action in February 2024.
The timing of these trends raises questions about whether the alliance represents genuine operational integration or a branding strategy. Yarix researchers noted that LockBit's inclusion might primarily serve to preserve its reputation. The lack of operational signals from LockBit, combined with the autonomous growth of Qilin and DragonForce, suggests that the coalition might be more symbolic than functional. However, the increase in Qilin's activity following the announcement demonstrates that even symbolic alliances can attract criminal operators.
Based on reporting by Cyber Security News.
