HomeSecurityRansomware: New groups emerge and LockBit returns

Ransomware: New groups emerge and LockBit returns

The third quarter of 2025 is marking a turning point for the ransomware. According to new research from Check Point Research, the number of active ransomware groups reached 85, the highest level ever detected. What was once a controlled market with dominantransomware-as-a-service) platforms is now a fragmented landscape filled with small, agile, and often short-lived criminal operations.

LockBit ransomware

From “Giants” to Small Groups: The Decentralization of Ransomware

Law enforcement pressure, as well as the fluctuations of the black market, have broken up large RaaS groups, creating a wave of new, independent actors. Many of them are former partners of defunct organizations such as RansomHub, 8Base, and BianLian, who now operate autonomously.

See also: Chinese hackers abuse Anthropic's AI model Claude

The result is a mosaic of leak sites, each with its own threat landscape, attack rate, and level of trustworthiness. In the third quarter, the following were recorded:

  • 1,592 new victims,
  • 535 leaks per month on average,
  • and a striking shift in power:
    the ten largest groups are responsible for just 56% of incidents, compared to 71% at the beginning of the year.

The market is not shrinking; it is fragmenting and redefining itself.

Limited Influence of Authorities – Why Ransomware Businesses “Mutate”

Despite the dynamic dismantling operations that continue in 2025, the overall intensity of attacks is not decreasing. The root cause is structural: police operations hit the infrastructure, not the attackers.

When a group loses servers or domain names, its collaborators simply move, rebrand, or join other collectives within days. Decentralization, rather than weakening ransomware, makes it more resilient – ​​and less predictable.

At the same time, smaller groups, who do not need to maintain a “corporate image”, are not committed to honoring ransom agreements. This leads to a further decline in payment rates, which are already hovering at only 25–40%. Organizations no longer trust that they will receive decryption keys.

See also: New phishing campaign targets hotel customers

Ransomware: New groups emerge and LockBit returns

LockBit 5.0: The Return of the “Big Player”

In this chaotic environment, the return of LockBit with version 5.0 in September 2025 is a defining event. The team, which had been disbanded in 2024 by Operation Cronos, appears renewed with:

  • new variants for Windows, Linux and ESXi,
  • faster encryption mechanisms,
  • advanced detection avoidance techniques,
  • and personalized portals for negotiation with each victim.

Within the first month, at least 12 organizations were hit. The move shows that partners are returning to platforms that offer credibility — a critical element in a market where many micro-perpetrators are “disposable.”

DragonForce: Ransomware as… Marketing

On the other hand, groups like DragonForce are investing in a completely different strategy: image. In September, they made statements of “collaborations” with LockBit and Qilin, without any technical evidence of a common infrastructure having been found so far.

The team attempts to build credibility through:

  • corporate alliance press releases,
  • stolen data analysis services ,
  • systematic presence in underground forums.

Ransomware is now becoming a branding game.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Police target Rhadamanthys, VenomRAT & Elysium malware – Arrests also made in Greece

Ransomware: New groups emerge and LockBit returns

Where they hit: Geographic and Sector Trends

The US remains the top target, accounting for around 50% of cases. It also stands out:

  • South Korea, which enters the international top ten for the first time due to Qilin's aggressiveness in the financial sector.
  • Europe, where Germany and the United Kingdom are under constant pressure from groups like Safepay and INC Ransom.

Sectorally, manufacturing and business services dominate with around 10% of the total, while health remains at 8%.

Towards an Even More Difficult 2026

Q3 2025 clearly shows that ransomware resilience is not diminishing — it’s just changing form. Every group breakup spawns new small units. The return of LockBit may signal a new consolidation, but also a greater risk of coordinated attacks.

For cybersecurity experts, the era of monitoring only the “names” is over. The real picture lies behind them: in the partnerships, the movement of infrastructure and the financial incentives that keep one of the most profitable forms of cybercrime alive.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS