Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemthreat-infrastructure-trackingransomware-tooling-evolution

Law Enforcement Disruption and Ransomware Group Realignment in 2025

Updated 3mo agoFirst seen Oct 8, 20256 sources

Law enforcement agencies have intensified their efforts against major ransomware groups, leading to significant disruptions in the global ransomware ecosystem. In Q2 2025, prominent ransomware-as-a-service (RaaS) groups such as LockBit and RansomHub either ceased operations or stopped publishing victim data, resulting in a fractured landscape previously dominated by a few powerful actors. This shift was largely attributed to coordinated international law enforcement operations, which in May 2025 dismantled over 300 malicious servers, shut down more than 650 domains, and issued arrest warrants for at least 20 individuals connected to ransomware and initial access malware infrastructure. The takedown of LockBit’s infrastructure in late 2024 under Operation Cronos set a precedent, demonstrating the vulnerability of even the most prolific ransomware groups when faced with unified global action. As a result, the ransomware ecosystem became more fragmented, with smaller, agile actors attempting to fill the void left by the dismantled groups. Concurrently, the profitability of ransomware attacks has declined due to evolving regulations, including bans on ransom payments, further pressuring threat actors. Despite these setbacks, LockBit has attempted a resurgence, announcing a strategic alliance with other major ransomware groups, Qilin and DragonForce, in Q3 2025. This coalition aims to share techniques, resources, and infrastructure, potentially restoring LockBit’s reputation among affiliates and increasing the operational capabilities of all involved groups. The emergence of LockBit 5.0, capable of targeting Windows, Linux, and ESXi systems, marks a technological advancement in their toolkit, first advertised in September 2025. Qilin, now the most active ransomware group, claimed over 200 victims in Q3 2025, with a particular focus on North American organizations. The alliance between LockBit, Qilin, and DragonForce is expected to trigger a surge in attacks, especially on critical infrastructure and sectors previously considered low risk. The ongoing evolution of the ransomware threat landscape underscores the dynamic interplay between law enforcement actions and the adaptability of cybercriminal groups. The future trajectory of ransomware will likely depend on the continued effectiveness of law enforcement operations and the ability of threat actors to reorganize and innovate. Organizations are advised to remain vigilant, as the threat landscape remains volatile and unpredictable. The collaboration among major ransomware groups signals a potential escalation in both the scale and sophistication of future attacks. The global cybersecurity community must continue to coordinate efforts to counter these evolving threats and mitigate their impact on critical sectors.

Share:
Law Enforcement Disruption and Ransomware Group Realignment in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 8, 20259mo ago

Researchers report no evidence yet of joint cartel operations

By October 2025, reporting on the new alliance noted that there was still no observed evidence of joint attacks or a shared leak site operated by DragonForce, Qilin, and LockBit. The cartel had been announced, but its operational integration had not yet been publicly demonstrated.

Sep 1, 202510mo ago

LockBit authorizes affiliates to target critical infrastructure

As part of the new alliance announced in September 2025, LockBit changed its targeting rules and allowed affiliates to attack critical infrastructure sectors that had previously been treated as off-limits. This marked a notable escalation in ransomware risk to sensitive sectors.

DragonForce, Qilin, and LockBit announce a ransomware cartel

In early September 2025, the three ransomware-as-a-service groups announced an alliance to coordinate attacks and share resources in response to mounting law enforcement pressure. The move was framed as an effort to strengthen market position and help restore LockBit's standing after earlier disruptions.

Feb 1, 20242y ago

Operation Cronos disrupts LockBit infrastructure and leads to arrests

In February 2024, law enforcement seized LockBit infrastructure and arrested members, significantly damaging the group's operations and reputation. The crackdown increased pressure across the ransomware ecosystem and set conditions for later criminal consolidation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Organizations
11 linked
fbiMazeLapsus$Asahi Group HoldingsLockBitReliaQuestQilinDarksideDragonForceShinyHuntersScattered Spider
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.