Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Qilin leads ransomware a second month

1 min read
18:20UTC

BlackFog's June report kept Qilin at the top of ransomware activity for a second month, despite Europol's Operation Saffron hitting 25 gangs in May.

TechnologyDeveloping
Key takeaway

Qilin led ransomware activity for a second month running, undented by Europol's 25-gang takedown in May.

BlackFog, a cybersecurity firm that tracks ransomware activity, named Qilin the most active brand in its State of Ransomware report for June 2026, at 16% of undisclosed attacks and 8% of disclosed. The June ranking marks Qilin's second consecutive monthly lead, after it also led BlackFog's May tally , and it held even as Europol's Operation Saffron disrupted around 25 gangs in May . 1

Qilin's run through that enforcement pressure points at its affiliate-recruitment model. Affiliates are the freelance operators who carry out attacks using a brand's tooling in exchange for a cut. As takedowns strand affiliates from smaller crews, the largest recruiter absorbs them rather than shrinking. Saffron hit the infrastructure of two dozen operations; it did not touch the labour market they draw from, and that is the gap the June figures expose.

Deep Analysis

In plain English

Ransomware gangs sometimes act like criminal franchises: a core group builds the malicious software and negotiates with victims, while 'affiliates' actually break into networks and split the ransom. A cyber-security firm called BlackFog tracks which gang is most active each month, and for the second month running that gang is called Qilin. What makes this notable is that European police had just run a big operation the month before, called Operation Saffron, disrupting around 25 different ransomware groups {{EVREF:/t/cyber-threats-and-defences/6/europol-seizes-first-vpn-in-saffron-raid/}}. Qilin still came out on top, which suggests that arresting or shutting down rival gangs does not necessarily reduce total ransomware activity; the criminals doing the actual break-ins often just switch to whichever gang is still standing.

Deep Analysis
Root Causes

Qilin runs a ransomware-as-a-service affiliate model with an unusually generous revenue split, reportedly up to 85% to affiliates versus the 70% more typical among rival brands, which is why disrupted gangs' affiliates tend to migrate to Qilin rather than disappear when law enforcement takes a competitor offline.

Operation Saffron's roughly 25 gang disruptions in May targeted infrastructure and arrests rather than the affiliate marketplace itself. Removing a service operator's servers does not remove the freelance affiliates who did the actual intrusions, and those affiliates simply re-register under whichever brand offers the best terms.

What could happen next?
  • Meaning

    Qilin's second consecutive monthly lead despite Operation Saffron suggests law-enforcement disruption campaigns reshuffle which brand affiliates use rather than reduce total ransomware volume.

  • Risk

    If Qilin continues absorbing displaced affiliates, its higher-than-median ransom demands could become the market's new benchmark rather than an outlier.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

BlackFog· 4 Jul 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.