The third quarter of 2025 is marking a turning point for the ransomware. According to new research from Check Point Research, the number of active ransomware groups reached 85, the highest level ever detected. What was once a controlled market with dominantransomware-as-a-service) platforms is now a fragmented landscape filled with small, agile, and often short-lived criminal operations.

From “Giants” to Small Groups: The Decentralization of Ransomware
Law enforcement pressure, as well as the fluctuations of the black market, have broken up large RaaS groups, creating a wave of new, independent actors. Many of them are former partners of defunct organizations such as RansomHub, 8Base, and BianLian, who now operate autonomously.
See also: Chinese hackers abuse Anthropic's AI model Claude
The result is a mosaic of leak sites, each with its own threat landscape, attack rate, and level of trustworthiness. In the third quarter, the following were recorded:
- 1,592 new victims,
- 535 leaks per month on average,
- and a striking shift in power:
the ten largest groups are responsible for just 56% of incidents, compared to 71% at the beginning of the year.
The market is not shrinking; it is fragmenting and redefining itself.
Limited Influence of Authorities – Why Ransomware Businesses “Mutate”
Despite the dynamic dismantling operations that continue in 2025, the overall intensity of attacks is not decreasing. The root cause is structural: police operations hit the infrastructure, not the attackers.
When a group loses servers or domain names, its collaborators simply move, rebrand, or join other collectives within days. Decentralization, rather than weakening ransomware, makes it more resilient – and less predictable.
At the same time, smaller groups, who do not need to maintain a “corporate image”, are not committed to honoring ransom agreements. This leads to a further decline in payment rates, which are already hovering at only 25–40%. Organizations no longer trust that they will receive decryption keys.
See also: New phishing campaign targets hotel customers

LockBit 5.0: The Return of the “Big Player”
In this chaotic environment, the return of LockBit with version 5.0 in September 2025 is a defining event. The team, which had been disbanded in 2024 by Operation Cronos, appears renewed with:
- new variants for Windows, Linux and ESXi,
- faster encryption mechanisms,
- advanced detection avoidance techniques,
- and personalized portals for negotiation with each victim.
Within the first month, at least 12 organizations were hit. The move shows that partners are returning to platforms that offer credibility — a critical element in a market where many micro-perpetrators are “disposable.”
DragonForce: Ransomware as… Marketing
On the other hand, groups like DragonForce are investing in a completely different strategy: image. In September, they made statements of “collaborations” with LockBit and Qilin, without any technical evidence of a common infrastructure having been found so far.
The team attempts to build credibility through:
- corporate alliance press releases,
- stolen data analysis services ,
- systematic presence in underground forums.
Ransomware is now becoming a branding game.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Police target Rhadamanthys, VenomRAT & Elysium malware – Arrests also made in Greece

Where they hit: Geographic and Sector Trends
The US remains the top target, accounting for around 50% of cases. It also stands out:
- South Korea, which enters the international top ten for the first time due to Qilin's aggressiveness in the financial sector.
- Europe, where Germany and the United Kingdom are under constant pressure from groups like Safepay and INC Ransom.
Sectorally, manufacturing and business services dominate with around 10% of the total, while health remains at 8%.
Towards an Even More Difficult 2026
Q3 2025 clearly shows that ransomware resilience is not diminishing — it’s just changing form. Every group breakup spawns new small units. The return of LockBit may signal a new consolidation, but also a greater risk of coordinated attacks.
For cybersecurity experts, the era of monitoring only the “names” is over. The real picture lies behind them: in the partnerships, the movement of infrastructure and the financial incentives that keep one of the most profitable forms of cybercrime alive.
