The Qilin ransomware by the numbers story paints a striking picture of how one group rose to dominate the cyber-extortion landscape. In 2025 alone, Qilin claimed responsibility for more than 700 confirmed attacks, placing it among the most aggressive ransomware operations worldwide.
First emerging in 2023, Qilin quickly evolved into a large-scale criminal enterprise. Its activity grew from 45 reported incidents in its first year to nearly 180 in 2024. After the collapse of rival gang RansomHub in early 2025, dozens of affiliates joined Qilin, boosting its reach and resources almost overnight.
How Qilin operates and expands
Qilin functions as a ransomware-as-a-service (RaaS) platform, offering its malware, negotiation tools, and infrastructure to affiliates. In exchange, it takes a share of every ransom payment. This model allows the group to scale quickly while maintaining a professionalized brand similar to a tech company — complete with “customer service” chat features and legal-style ransom negotiation templates.
The group’s success lies in its business-like structure. It provides affiliates with easy-to-use dashboards, customizable payloads, and multi-platform attack kits capable of infecting both Windows and Linux systems. Because of this, Qilin’s affiliates can launch coordinated attacks worldwide with minimal technical expertise.
Key targets and global impact
Qilin primarily targets industries where downtime translates directly to financial loss. Manufacturing, healthcare, energy, and finance remain top priorities. The group has also attacked public institutions, including hospitals and local governments, disrupting operations and compromising sensitive data.
Among Qilin’s most notable incidents are the attacks against Asahi Holdings in Japan, which caused beverage supply issues, and Volkswagen Group France, where over 150 GB of corporate data was stolen. These high-profile hits reveal the group’s confidence and operational reach.
Why Qilin keeps growing
The Qilin ransomware by the numbers phenomenon reflects how modern ransomware thrives on scale, automation, and adaptability. The gang continuously recruits affiliates on dark web forums, offering generous profit splits and technical support. Because its infrastructure uses distributed servers and encrypted communication channels, tracing attacks back to their operators has proven difficult.
Moreover, Qilin’s business-driven approach and high success rate make it an appealing option for other threat actors. Analysts warn that if law enforcement fails to disrupt its financial operations, Qilin could surpass the activity levels of LockBit and BlackCat within the next year.
How to defend against Qilin attacks
Cybersecurity experts recommend several critical steps:
- Regularly patch exposed systems and software.
- Segment networks to limit lateral movement.
- Maintain encrypted, offline backups and test recovery frequently.
- Monitor for abnormal encryption behaviour or data exfiltration.
- Train employees to recognize phishing and credential theft attempts.
Conclusion
The Qilin ransomware by the numbers analysis shows a group that has combined business acumen with cybercrime. Its RaaS model, relentless affiliate recruitment, and ability to adapt have made it one of the most dangerous ransomware syndicates of 2025. Unless organizations strengthen defenses and international cooperation increases, Qilin’s influence is likely to expand even further in the coming year.


0 responses to “Qilin ransomware by the numbers: one of the most prolific cybercrime groups”