Breaking: RansomHub Vanishes Overnight as Affiliates Rush to Qilin Amid DragonForce Takeover Claims


# RansomHub Infrastructure Goes Offline, Triggering Shifts in Ransomware Landscape

RansomHub’s online infrastructure unexpectedly went offline on April 1, 2025, causing significant disruption among affiliates of the ransomware-as-a-service (RaaS) operation. According to Singapore-based Group-IB, this outage has prompted many affiliates to migrate to competitor Qilin, whose data leak site disclosures have doubled since February.

Since its emergence in February 2024, RansomHub had quickly filled the void left by high-profile groups LockBit and BlackCat, attracting prominent affiliates like Scattered Spider and Evil Corp with generous payment splits. The group’s success stemmed from its acquisition of Knight (formerly Cyclops) code and its versatile multi-platform encryptor that works across Windows, Linux, FreeBSD, and ESXi systems.

## Aftermath and Industry Shifts

The infrastructure downtime has created what GuidePoint Security describes as “affiliate unrest.” Rival group DragonForce has claimed on the RAMP forum that RansomHub is moving to their infrastructure under a new “DragonForce Ransomware Cartel.” Similarly, BlackLock appears to be collaborating with DragonForce following a defacement of its leak site in March.

DragonForce’s new “cartel” business model represents a departure from traditional RaaS operations. Rather than simply recruiting affiliates to use their ransomware, DragonForce provides infrastructure and tools while allowing affiliates to create their own brands.

## Emerging Ransomware Threats

The ransomware landscape continues to evolve with several new players adopting innovative tactics:

– **Anubis**: Emerged in February 2025 with a “data ransom” extortion-only approach, threatening to publish investigative articles about stolen data and inform regulatory authorities.

– **ELENOR-corp**: A Mimic ransomware variant targeting healthcare organizations using credential harvesting and sophisticated anti-forensic measures.

– **CrazyHunter**: Targeting Taiwanese sectors using BYOVD techniques via an open-source tool called ZammoCide.

– **Elysium**: A Ghost/Cring variant that terminates services, disables backups, and modifies boot policies to complicate recovery.

– **FOG**: Abuses the name of the U.S. Department of Government Efficiency in phishing campaigns.

– **Hellcat**: Exploits zero-day vulnerabilities in platforms like Atlassian Jira.

– **Hunters International**: Rebranded as “World Leaks” for extortion-only operations.

– **Interlock**: Uses the ClickFix strategy for multi-stage attacks deploying ransomware and backdoors.

– **Qilin**: Employs sophisticated phishing techniques targeting MSPs to reach their customers.

These developments highlight ransomware operators’ ability to adapt and innovate despite law enforcement disruptions, with groups increasingly splintering into smaller operations and frequently rebranding to maintain operational continuity.

Share This Article