RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

RansomHub, a prominent ransomware-as-a-service (RaaS) operation, experienced a sudden shutdown of its online infrastructure on April 1, 2025. This event led to uncertainty among affiliates, with some migrating to Qilin, while others speculated about a potential takeover by DragonForce. The incident underscores the evolving nature of the ransomware landscape, with groups experimenting with new business models and tactics to maintain their influence and profitability.

Edward Kiledjian @ekiledjian