Threat Landscape Analysis
Qilin has spent most of 2026 as the world’s most active ransomware operation. Independent trackers differ on exact victim counts because they measure different things (leak site listings, confirmed incidents, or leaked backend databases), but the direction is consistent. Sophos X-Ops has logged nearly 1,500 Qilin victims on its leak site over a recent twelve month span, with Akira and a newer rival called The Gentlemen trailing behind. Check Point research puts Qilin’s share of the criminal market at roughly sixteen percent. For one month in the summer, a rival briefly took the top spot. Comparitech data showed The Gentlemen edging past Qilin in June, posting 115 victims against Qilin’s 78, the first time in many months anyone had displaced Qilin from the lead.
Researchers do not read this as a sign that ransomware is slowing down. It reflects a consolidation of experienced affiliates into fewer, better funded criminal organizations running mature platforms. For defenders, that consolidation changes the economics of the threat. Modern ransomware operators no longer depend solely on sophisticated exploits. They increasingly exploit the most reliable delivery mechanism ever created, which is a file that an employee already trusts.
One Pattern Appears Across Nearly Every Ransomware Family
Every group named above develops its own malware, its own negotiation style and its own affiliate economics, yet nearly all of them still depend on a remarkably narrow set of delivery methods. Microsoft Office documents, PDF files, ZIP and RAR archives, ISO and VHD disk images, JavaScript files, Visual Basic Script, Windows shortcut files, malicious installers, HTML phishing attachments and chained compressed archives account for the overwhelming majority of initial infections across the ransomware landscape.
These files are built to look completely ordinary. A purchase order. An invoice. A shipping notification. A tax document. A supplier contract. An HR policy update. By the time endpoint protection notices anything unusual, the attacker has frequently already executed code, established persistence, harvested credentials and begun moving laterally through the network.
The Ransomware Market Has Become a Business
Law enforcement operations over the past several years disrupted dominant brands including LockBit, ALPHV/BlackCat and RansomHub. Rather than disappearing, the affiliates who once worked under those names migrated to whichever platform offered the best terms. That migration is the engine behind today’s consolidation.
The groups winning that competition for talent behave like software vendors courting resellers. They maintain professionally built encryptors, run negotiation portals and payment infrastructure, operate victim management dashboards and public data leak sites, and in some cases provide technical support to affiliates the way a legitimate SaaS company would support a customer. The revenue split has become the clearest signal of how competitive this recruitment has gotten. Qilin has offered affiliates as much as eighty five percent of a ransom payment. The Gentlemen, a group that broke away from Qilin after a dispute over an unpaid affiliate commission, went further and set its share at ninety percent specifically to pull experienced operators away from competitors.
The result is an industrialized ecosystem in which attackers specialize in gaining initial access while a much smaller number of ransomware developers focus entirely on improving encryption, evasion and extortion pressure.
Qilin, Formerly Agenda
Qilin first surfaced in 2022 under the name Agenda. The malware was originally written in Go before the group rewrote it in Rust for better cross platform performance and to complicate reverse engineering. Qilin has since built one of the most technically mature RaaS platforms in the criminal market, and it absorbed a large share of the affiliates displaced when competing operations collapsed.
Qilin attacks typically begin with phishing emails carrying malicious Office or PDF attachments, compromised VPN credentials, exploitation of internet facing vulnerabilities, malicious ZIP archives, fake software installers, or ClickFix style social engineering. Once an attacker gains a foothold, the typical progression runs through PowerShell loaders, credential theft tools, privilege escalation utilities, lateral movement frameworks, Active Directory discovery, data exfiltration and finally enterprise wide encryption. Manufacturing has become Qilin’s most frequently hit sector, with professional services, healthcare, education, government and critical infrastructure organizations also appearing consistently in its victim data.
Qilin’s most consequential attack to date targeted Synnovis, a pathology services provider supporting several London hospitals, an incident that forced the cancellation of thousands of appointments and procedures. That attack remains a reference point for how much operational damage a single successful ransomware intrusion against a healthcare supply chain can cause.
The Gentlemen
The Gentlemen is the fastest scaling ransomware operation on record. The group’s founders previously ran a Qilin affiliate crew and split off in mid 2025 after a payment dispute. Within roughly five months, The Gentlemen reached a victim count that took Akira a year and Qilin a year and a half to reach, a trajectory researchers at Halcyon compare to the early rise of LockBit 3.0, long considered the benchmark for how fast a RaaS brand can grow.
The group’s technical approach borrows heavily from its rivals. Its developers reverse engineered samples from Babuk, Qilin, LockBit 5.0 and Medusa, then selectively incorporated the strongest encryption routines and evasion techniques into a custom Go based encryptor with a dedicated locker for ESXi. Initial access most often runs through exploited Fortinet appliances, exposed remote management interfaces and credentials purchased from initial access brokers or pulled from infostealer logs. Once inside a domain, the group can deploy ransomware through a Group Policy based mechanism that pushes the payload to every computer on the network at once, one of the more aggressive deployment methods researchers have documented in an active RaaS platform.
In May 2026 the group’s own backend infrastructure was breached, exposing internal chat logs, affiliate rosters and negotiation transcripts. The leak gave researchers a rare look inside a modern RaaS operation and did not appear to slow the group down. It continued adding victims through the following month, briefly surpassing Qilin’s monthly total in June.
Akira, LockBit 5.0 and Play
Akira remains one of the most consistently active ransomware families in the world and has ranked alongside Qilin among the top handful of operations by victim volume. The group began by focusing on Linux environments and VMware ESXi servers before expanding aggressively into Windows enterprise networks. Common infection paths include malicious email attachments, VPN appliance vulnerabilities, exposed remote management software, stolen credentials and software supply chain compromise. Akira affiliates tend to spend extended time inside a network stealing data before triggering encryption, a pattern intended to maximize double extortion leverage. Industrial organizations remain frequent targets.
LockBit has re-emerged under new infrastructure despite major international law enforcement action against its earlier operators, with LockBit 5.0 campaigns leveraging phishing documents, malicious ISO and VHD images, JavaScript downloaders, DLL sideloading, scheduled task persistence and lateral movement built on legitimate Windows administration tools. A significant number of former LockBit affiliates have since resurfaced inside newer operations, including The Gentlemen, spreading LockBit’s playbook throughout the broader ecosystem rather than retiring it.
Play remains a highly active enterprise focused ransomware family that leans more heavily than most on vulnerability exploitation rather than phishing alone, frequently targeting Microsoft Exchange servers, Fortinet VPN appliances, remote management software and exposed RDP services. Phishing documents still provide one of the simplest paths in, particularly against finance and human resources staff, and Play operators commonly deploy custom loaders alongside legitimate administrative tools to minimize the chance of early detection.

Why FileDNA CADR Changes the Equation
Most cybersecurity products focus on detecting malicious behavior after code has already started to execute. FileDNA takes a different approach. Rather than waiting for malware to run, FileDNA Content Analysis, Disarm and Reconstruction examines the file itself before it ever reaches a user or a downstream security tool.
For supported file formats, FileDNA validates the true structure of a file rather than trusting its extension, identifies embedded active content and hidden scripts or executable objects, strips macros and embedded code, removes malicious JavaScript, rebuilds a clean version of the document that preserves the legitimate business content, and produces a forensic analysis report for SOC teams. Because nearly every ransomware campaign described in this article still depends on getting a malicious container opened by a human being, removing the executable content upstream closes off the opportunity before an attacker ever gets a foothold.
This approach is meant to complement existing endpoint security, EDR, XDR, STEM and sandbox technology rather than replace it. Instead of asking endpoint protection to catch malware after it starts running, CADR is designed to prevent a large share of document based attacks from ever reaching that stage. For organizations processing thousands of inbound documents every day, that upstream layer can meaningfully reduce incident response workload, cut down on false positive investigation time, and lower the operational cost tied to ransomware related incidents.
File level control like CADR relevant against the specific groups driving the current ransomware surge, Qilin, The Gentlemen, Akira, LockBit 5.0 and Play, and the shared delivery mechanics that make an upstream – all of them at once.
Defense Has to Start Earlier
Modern ransomware groups will keep improving their encryption, their stealth and their extortion tactics. Nearly all of them still depend on one unavoidable requirement, which is getting a malicious file opened by a person. Whether the operator behind an attack is Qilin, The Gentlemen, Akira, LockBit or Play, the chain almost always starts with a document, an archive or an installer that the victim believed they could trust.
Stopping a weaponized file before it ever executes remains one of the most effective ways to break that chain before it starts. As ransomware organizations grow larger, more professional and more consolidated, moving security further upstream, from behavioral detection after the fact to file sanitization before the fact, may prove to be one of the more valuable defensive investments an organization can make this year.
References
Infosecurity Magazine, Qilin Dominates Ransomware Market, 2026.
Industrial Cyber, Global Ransomware Activity Rises Modestly in May as Qilin, The Gentlemen and DragonForce Lead Attacks, 2026.
Halcyon, Threat Assessment: The Gentlemen Ransomware Group, 2026.
Fortra, The Gentlemen Ransomware: What You Need to Know, 2026.
Dark Reading, The Gentlemen Rapidly Rises to Ransomware Prominence, 2026.
Check Point Software, Qilin Ransomware (Agenda): A Deep Dive, 2025.
MOXFIVE, Qilin Ransomware 2026: TTPs, Victims and Defense Guide.
CyberSecurityNews, The Gentlemen Ransomware Group Uses Fortinet Exploits, AI and Custom C2 Frameworks, 2026.