Immune — Self Heal, an iStudio Technologies product
Threat Intelligence28 Aug 2026 · 6 min read

The ransomware group shakeup: what Qilin's rise means for hospitals

Law-enforcement takedowns of major ransomware brands were supposed to be good news. Instead, the affiliates behind them scattered and reorganized — and the resulting churn has made the threat to hospitals broader and harder to predict, not smaller.

By Immune Threat Research

Takedowns don't remove the people

Over the past two years, some of the most notorious ransomware brands have been disrupted or have gone quiet — LockBit was hit by law enforcement, ALPHV/BlackCat imploded, and RansomHub went dark in April 2025. On paper, that looks like progress. In practice, the operators and affiliates behind those brands did not disappear; they moved.

When RansomHub shut down, researchers watched its affiliates migrate almost immediately to other operations. One tracker noted Qilin's share of reported incidents in one sector nearly tripling in a single quarter as displaced affiliates moved across, per Paubox's analysis of the consolidation. The talent and the tooling simply changed letterhead.

Qilin: the brand that absorbed the fallout

Qilin has been the clearest beneficiary. After the disruptions to LockBit, ALPHV/BlackCat, and RansomHub, it absorbed displaced affiliates and, by mid-2025, had become one of the most active ransomware threats in the world — claiming hundreds of victims across more than 60 countries, according to threat-group profiling by Halcyon. Healthcare has been a recurring target since the group's earliest days.

It is not a lone actor. Flare's analysis of ransomware activity against EMEA healthcare identified 14 distinct threat-actor groups going after healthcare targets in its sample, including Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, and 3AM. The ecosystem is crowded, and it is competitive.

More brands, more often

The churn shows up in the numbers. Black Kite's tracking found the count of active ransomware groups climbing to 146 by mid-2026, with dozens of new brands entering the market over a single year — more than one new operation per week, sustained. For a hospital security team, that means the specific group behind the next attack is almost impossible to predict, and yesterday's indicators-of-compromise for a named gang are a fragile defense.

Why this changes the defensive math

When the threat was a handful of stable brands, signature- and reputation-based defenses could keep some pace. A fragmented, fast-rebranding ecosystem breaks that model: new affiliates bring new tooling, and new brands have no track record to match against. The constant across all of them is behavior — encryption, lateral movement, credential abuse, and data exfiltration look similar regardless of the logo on the ransom note.

That is the case for defending on behavior and resilience rather than group attribution. Immune detects ransomware by what it does, not who is doing it, contains it before it can spread across a hospital network, and self-heals affected clinical systems from immutable backups — so it does not matter whether the next attacker is Qilin, a RansomHub successor, or a brand that did not exist last month.

Sources

Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.

Turn this threat intelligence into resilience

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems — whatever group is behind the next attack.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.