Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Qilin's own affiliate now outposts it

3 min read
12:09UTC

Leak-site postings tracked by ransomware.live ran The Gentlemen at 31 victims against Qilin's 19 over ten days to 3 August. Group-IB documented that the crew began inside Qilin's own affiliate programme and left over a $48,000 argument.

TechnologyDeveloping
Key takeaway

Score ransomware exposure by access route, not by which brand signs the ransom note.

Leak-site postings logged by ransomware.live between 24 July and 3 August ran The Gentlemen at 31 victims and Qilin at 19 1. A leak site is the extortion shopfront where a crew publishes the names of organisations it says it has breached, so the count measures claims made rather than intrusions verified. Group-IB, the Singapore-headquartered investigations firm, documented on 19 March that The Gentlemen, which also trades as Hastalamuerte, began life inside Qilin's affiliate programme under the handle ArmCorp 2.

Group-IB traces the split to money. A public argument over $48,000 of unpaid commission split the crew off around 22 July 2025, and a Windows ransomware sample from the new operation had already reached VirusTotal on 17 July 2025, five days before the falling-out; the administrator later admitted building his own locker while still earning under Qilin's programme 3. Affiliate exits on this beat tend to get read as consequences of law-enforcement pressure. This one was a payroll dispute in a business with payroll disputes like any other, planned in advance.

The two published figures for what The Gentlemen pays its affiliates do not agree, and the disagreement matters more than the gap. Group-IB puts the crew at roughly 20 members and the affiliate share at 70 to 80 per cent of receipts 4. The group profile on ransomware.live gives 90 per cent 5. Group-IB publishes named investigative analysis; ransomware.live aggregates tracker metadata, much of it what the crews say about themselves. Any recruitment-economics argument built on either number stays unfalsifiable until one of the two is withdrawn.

This briefing owes readers a correction on the same subject. On 30 June we reported that BlackFog's June figures named Qilin the most active brand for a second consecutive month . They do not. BlackFog's June edition puts a newly emerged group trading as 2019 at the head of the month with 12 claimed victims out of 102 attacks across 31 active groups 6. Qilin led May, with 11 of the 95 attacks BlackFog counted across 37 groups , and did not lead twice.

The ten-day posting count and BlackFog's monthly tally are not the same measurement, from the same tracker, on the same basis, and BlackFog has not published July, so the inversion reads as a lead rather than an overtake. The larger problem sits under both numbers. A brand table treats The Gentlemen and Qilin as two operations when the first is staffed out of the second, and it credits a leader with under 12 per cent of a month's activity. Check Point Research sinkholed the crew's SystemBC command server, which is how it first reached this beat as a single line on 19 April .

Deep Analysis

In plain English

Ransomware gangs like Qilin don't do all the hacking themselves. They build the malware and lease it to smaller partner crews, called affiliates, who break into victim networks and split the ransom payment with the gang that built the tool. The Gentlemen started life as one of Qilin's affiliates, using the name ArmCorp, before a dispute over an unpaid $48,000 commission in July 2025 led it to launch its own competing ransomware brand instead. In the ten days from 24 July to 3 August 2026, tracking site ransomware.live counted more new victims posted by The Gentlemen, 31, than by its former parent Qilin, 19, though this is a short snapshot, not a confirmed monthly leadership change.

Deep Analysis
Root Causes

The split traces to a specific dispute, not an ideological break: Group-IB documents that the operator behind The Gentlemen, then a Qilin affiliate called ArmCorp, had a Windows ransomware sample of its own operation on VirusTotal five days before a public $48,000 payment argument with Qilin in July 2025. The defection followed money already owed, not a change in targeting philosophy.

The structural condition that makes this kind of split repeatable is the RaaS model itself: Qilin's core developers lease tooling to independent affiliates who already run their own attack infrastructure. An affiliate with a functioning locker and a live grievance can become a competing brand overnight, because the technical barrier to leaving was never high to begin with.

What could happen next?
  • Consequence

    A ten-day leak-site inversion is not yet confirmed against BlackFog's monthly tally, which had not published a July edition as of 3 August; treating this as a leadership change would outrun the evidence.

  • Precedent

    The Gentlemen is now a second documented case on this beat, alongside the operator sitting on both INC Ransom and Lynx panels, of ransomware brands being affiliate spin-outs rather than distinct organisations.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

Group-IB· 3 Aug 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.