Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Qilin's own affiliate now outposts it

3 min read
16:08UTC

Leak-site postings tracked by ransomware.live ran The Gentlemen at 31 victims against Qilin's 19 over ten days to 3 August. Group-IB documented that the crew began inside Qilin's own affiliate programme and left over a $48,000 argument.

TechnologyDeveloping
Key takeaway

Score ransomware exposure by access route, not by which brand signs the ransom note.

Leak-site postings logged by ransomware.live between 24 July and 3 August ran The Gentlemen at 31 victims and Qilin at 19 1. A leak site is the extortion shopfront where a crew publishes the names of organisations it says it has breached, so the count measures claims made rather than intrusions verified. Group-IB, the Singapore-headquartered investigations firm, documented on 19 March that The Gentlemen, which also trades as Hastalamuerte, began life inside Qilin's affiliate programme under the handle ArmCorp 2.

Group-IB traces the split to money. A public argument over $48,000 of unpaid commission split the crew off around 22 July 2025, and a Windows ransomware sample from the new operation had already reached VirusTotal on 17 July 2025, five days before the falling-out; the administrator later admitted building his own locker while still earning under Qilin's programme 3. Affiliate exits on this beat tend to get read as consequences of law-enforcement pressure. This one was a payroll dispute in a business with payroll disputes like any other, planned in advance.

The two published figures for what The Gentlemen pays its affiliates do not agree, and the disagreement matters more than the gap. Group-IB puts the crew at roughly 20 members and the affiliate share at 70 to 80 per cent of receipts 4. The group profile on ransomware.live gives 90 per cent 5. Group-IB publishes named investigative analysis; ransomware.live aggregates tracker metadata, much of it what the crews say about themselves. Any recruitment-economics argument built on either number stays unfalsifiable until one of the two is withdrawn.

This briefing owes readers a correction on the same subject. On 30 June we reported that BlackFog's June figures named Qilin the most active brand for a second consecutive month . They do not. BlackFog's June edition puts a newly emerged group trading as 2019 at the head of the month with 12 claimed victims out of 102 attacks across 31 active groups 6. Qilin led May, with 11 of the 95 attacks BlackFog counted across 37 groups , and did not lead twice.

The ten-day posting count and BlackFog's monthly tally are not the same measurement, from the same tracker, on the same basis, and BlackFog has not published July, so the inversion reads as a lead rather than an overtake. The larger problem sits under both numbers. A brand table treats The Gentlemen and Qilin as two operations when the first is staffed out of the second, and it credits a leader with under 12 per cent of a month's activity. Check Point Research sinkholed the crew's SystemBC command server, which is how it first reached this beat as a single line on 19 April .

Deep Analysis

In plain English

Ransomware gangs like Qilin don't do all the hacking themselves. They build the malware and lease it to smaller partner crews, called affiliates, who break into victim networks and split the ransom payment with the gang that built the tool. The Gentlemen started life as one of Qilin's affiliates, using the name ArmCorp, before a dispute over an unpaid $48,000 commission in July 2025 led it to launch its own competing ransomware brand instead. In the ten days from 24 July to 3 August 2026, tracking site ransomware.live counted more new victims posted by The Gentlemen, 31, than by its former parent Qilin, 19, though this is a short snapshot, not a confirmed monthly leadership change.

Deep Analysis
Root Causes

The split traces to a specific dispute, not an ideological break: Group-IB documents that the operator behind The Gentlemen, then a Qilin affiliate called ArmCorp, had a Windows ransomware sample of its own operation on VirusTotal five days before a public $48,000 payment argument with Qilin in July 2025. The defection followed money already owed, not a change in targeting philosophy.

The structural condition that makes this kind of split repeatable is the RaaS model itself: Qilin's core developers lease tooling to independent affiliates who already run their own attack infrastructure. An affiliate with a functioning locker and a live grievance can become a competing brand overnight, because the technical barrier to leaving was never high to begin with.

What could happen next?
  • Consequence

    A ten-day leak-site inversion is not yet confirmed against BlackFog's monthly tally, which had not published a July edition as of 3 August; treating this as a leadership change would outrun the evidence.

  • Precedent

    The Gentlemen is now a second documented case on this beat, alongside the operator sitting on both INC Ransom and Lynx panels, of ransomware brands being affiliate spin-outs rather than distinct organisations.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

Group-IB· 3 Aug 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.