Tag RansomHub

Qilin Ransomware Introduces “Call Lawyer” Feature to Increase Pressure on Victims for Higher Ransoms

June 20, 2025
Ransomware / Cybercrime

The operators of the Qilin ransomware-as-a-service (RaaS) platform have unveiled a new “Call Lawyer” feature intended to pressure victims into paying larger ransoms. This strategic move comes as the group ramps up its activities to capitalize on the decline of competing cybercriminals. According to Israeli cybersecurity firm Cybereason, this feature is integrated into the affiliate panel, allowing affiliates to present legal counsel offers to victims.

This development marks a resurgence in Qilin’s operations at a time when other once-dominant ransomware factions, such as LockBit, Black Cat, and others, have faced sudden shutdowns and operational issues. Active since October 2022 and also known as Gold Feather and Water Galura, Qilin has emerged as a significant player in the ransomware landscape.

Data from dark web leak sites reveals that Qilin was responsible for 72 attacks in April 2025 and an estimated 55 in May, placing it behind only Safepay (72) and Luna Moth (67) in activity.

Qilin Ransomware Introduces “Call Lawyer” Feature to Boost Pressure on Victims June 20, 2025 In a notable shift within the landscape of ransomware attacks, the Qilin ransomware-as-a-service (RaaS) group has recently added a new feature aimed at compelling victims to comply with ransom demands. The “Call Lawyer” functionality, as reported…

Read More

Qilin Ransomware Introduces “Call Lawyer” Feature to Increase Pressure on Victims for Higher Ransoms

June 20, 2025
Ransomware / Cybercrime

The operators of the Qilin ransomware-as-a-service (RaaS) platform have unveiled a new “Call Lawyer” feature intended to pressure victims into paying larger ransoms. This strategic move comes as the group ramps up its activities to capitalize on the decline of competing cybercriminals. According to Israeli cybersecurity firm Cybereason, this feature is integrated into the affiliate panel, allowing affiliates to present legal counsel offers to victims.

This development marks a resurgence in Qilin’s operations at a time when other once-dominant ransomware factions, such as LockBit, Black Cat, and others, have faced sudden shutdowns and operational issues. Active since October 2022 and also known as Gold Feather and Water Galura, Qilin has emerged as a significant player in the ransomware landscape.

Data from dark web leak sites reveals that Qilin was responsible for 72 attacks in April 2025 and an estimated 55 in May, placing it behind only Safepay (72) and Luna Moth (67) in activity.

Scattered Spider Takes Advantage of VMware vSphere

Fraud Management & Cybercrime, Social Engineering Hacking Tactics Linked to Retail and Airline Breaches Akshaya Asokan (asokan_akshaya) • July 25, 2025 Image: Shutterstock A group of adolescent cybercriminals known as Scattered Spider has recently targeted VMware hypervisors, successfully infiltrating corporate environments through Active Directory. This emerging threat landscape has led…

Read MoreScattered Spider Takes Advantage of VMware vSphere

Another Medical Practice Shuts Down Following Cyberattack

Business Continuity Management / Disaster Recovery, Cryptocurrency Fraud, Fraud Management & Cybercrime Alpha Wellness Announces Permanent Closure Following ‘Devastating’ Cyberattack Marianne Kolbasuk McGee (HealthInfoSec) • July 22, 2025 Image: Alpha Medical Centre A small medical provider in Georgia, Ascension Health Services LLC, operating as Alpha Wellness and Alpha Medical Centre,…

Read MoreAnother Medical Practice Shuts Down Following Cyberattack

British Police Dismantle Spider Silk Operation, Arresting Four Suspects in England

Cybercrime, Fraud Management & Cybercrime, Geo Focus: The United Kingdom Arrests Made in Connection with April Ransomware Strikes Against M&S, Co-Op, and Harrods Mathew J. Schwartz (euroinfosec) • July 10, 2025 Image: Andy Sutherland/Shutterstock British authorities have apprehended four individuals linked to a series of high-profile cybersecurity incidents affecting top-tier…

Read MoreBritish Police Dismantle Spider Silk Operation, Arresting Four Suspects in England

Honor Among Thieves: The M&S Hacking Group Sparks Turf War

Cybercriminal Landscape Shifting as DragonForce Targets RansomHub Affiliates Recent developments in the cybercrime realm have emerged, with the hacking group DragonForce reportedly targeting affiliates of RansomHub in a move that raises concerns over the stability within the ransomware ecosystem. Genevieve Stark, head of cybercrime analysis at Google Threat Intelligence Group,…

Read MoreHonor Among Thieves: The M&S Hacking Group Sparks Turf War

LockBit Leaks Expose Efforts to Recruit Ransomware Newcomers

Fraud Management & Cybercrime, Ransomware ‘Lite Panel’ Provides Easy Entry for Ransomware Operators at $777, Reports Researcher Mathew J. Schwartz (euroinfosec) • May 16, 2025 Ransomware groups are continually evolving their strategies to extort organizations, both large and small. The introduction of a more accessible “lite” version of LockBit’s ransomware-as-a-service…

Read MoreLockBit Leaks Expose Efforts to Recruit Ransomware Newcomers