Listen to this Post

Introduction: A Ransomware Cartel Ascends from the Ashes
In the ever-shifting world of cybercrime, power vacuums are rare—and when they occur, they breed new titans. The downfall of several major ransomware-as-a-service (RaaS) groups in Q2 2025, most notably RansomHub, Babuk-Bjorka, Lockbit, and Cactus, has reshaped the ransomware ecosystem. Emerging strongest from this collapse is DragonForce, a group known for its “cartel” model and ruthless marketing machine. With Check Point Research’s latest Q2 report as our lens, we dissect the key players, strategic shifts, and the disturbing ways artificial intelligence is being weaponized in ransomware operations.
Summary: RansomHub Falls, DragonForce Rises
DragonForce, a ransomware-as-a-service (RaaS) group launched in 2023, has surged in influence following the mysterious disappearance of rival group RansomHub in April. According to Check Point Research’s Q2 report, DragonForce is now positioning itself as the dominant cartel by absorbing or inheriting operations from defunct ransomware groups. The group’s white-label affiliate model allows external actors to launch attacks using DragonForce’s infrastructure under unique branding, creating a decentralized but unified criminal network.
In Q2 alone, DragonForce claimed 58 new victims out of more than 250 total listings on its dark web leak site. Although this doesn’t match the 207 claimed by Qilin or 143 by Akira, the group’s growth trajectory is undeniable. Notably, DragonForce published a backend screenshot from RansomHub as supposed proof of the merger or migration.
To counter growing law enforcement scrutiny, DragonForce implemented tighter affiliate vetting and publicly claimed it avoids attacking healthcare targets. Their stated mission is financial gain, not destruction—”We are not here to kill — we are here to make money,” they say.
The report also highlights increasing sophistication across the ransomware landscape. Qilin nearly doubled its activity after RansomHub vanished, growing from 35 victims a month to nearly 70. Qilin’s comprehensive affiliate toolkit includes ransomware builders, DDoS capabilities, and even negotiation consultants.
Another emerging trend is the incorporation of AI tools into ransomware campaigns. Groups like FunkSec, Xanthorox, and Global Group are experimenting with large language models to optimize malware development and psychological manipulation during negotiations.
Despite the appearance of consolidation, Check Point’s experts caution that the ransomware world remains volatile. While DragonForce and Qilin look dominant now, law enforcement efforts and infighting mean the cybercriminal ecosystem continues to fragment and evolve.
What Undercode Say:
The DragonForce story is not just one of technological dominance—it’s a case study in ransomware brand strategy, ruthless opportunism, and the cartelization of cybercrime. What we’re seeing is not simply the rise of another cyber gang; this is the birth of a ransomware conglomerate.
Strategic Opportunism
DragonForce’s success can be attributed to a vacuum it didn’t just stumble into—it actively capitalized on. The timing of RansomHub’s disappearance and DragonForce’s sudden spike in victims is not coincidental. Whether through recruitment, merger, or impersonation, DragonForce moved fast to acquire both talent and territory in the digital underground.
Marketing as a Weapon
Where traditional ransomware gangs operate in the shadows, DragonForce embraces visibility. From its name appearing in forum logos to public-facing statements distancing itself from healthcare attacks, this gang has mastered the PR game. It’s the ransomware version of corporate rebranding: position yourself as “ethical,” even while running a criminal syndicate.
Cartel Infrastructure
Unlike older monolithic models of ransomware, DragonForce’s affiliate system decentralizes operations while centralizing branding and support. This mirrors the “franchise model” seen in real-world cartels. The result? Resilience. If one affiliate falls, the cartel persists. It’s scalable, flexible, and hard to dismantle.
Weaponized AI
The integration of AI in ransomware signals the dawn of automated cyber extortion. LLMs are now being used to craft negotiation strategies, generate malware variants, and impersonate executives. This shifts the balance of power—AI-enhanced gangs can operate faster, smarter, and with chilling precision.
Qilin’s Silent Surge
Qilin, though quieter in branding, is no less dangerous. By absorbing RansomHub affiliates and ramping up DDoS capabilities and legal “leverage” (i.e., weaponizing GDPR violations), Qilin is mastering the full-spectrum attack model. They don’t just hack—they corner victims legally, digitally, and psychologically.
The Myth of Consolidation
Check Point’s warning is key: while it appears we’re heading toward cartel-style consolidation, the cybercriminal underworld remains fragmented and chaotic. Every takedown creates room for two more startups. This is less like Amazon buying Whole Foods and more like a Mafia turf war—with the added complication of no geography, no borders, and anonymous players.
🔍 Fact Checker Results:
✅ DragonForce did claim over 250 victims, 58 of which occurred in Q2.
✅ RansomHub vanished in April 2025, with a possible migration to DragonForce.
✅ Qilin’s attack rate nearly doubled after RansomHub’s disappearance.
📊 Prediction:
As law enforcement continues targeting high-profile ransomware gangs, smaller and mid-tier affiliates will increasingly gravitate toward cartel-like structures like DragonForce for protection, branding, and infrastructure. Expect DragonForce to evolve from a gang into a ransomware-as-a-service platform, offering tailored services including AI-driven extortion tools, legal exploitation toolkits, and deepfake-enhanced phishing campaigns. Meanwhile, Qilin’s quiet professionalism may make it even harder to detect and dismantle—expect a surge in stealthier, compliance-targeted ransomware in the next 6–12 months.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.darkreading.com
Extra Source Hub:
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




