Takedowns don't remove the people
Over the past two years, some of the most notorious ransomware brands have been disrupted or have gone quiet — LockBit was hit by law enforcement, ALPHV/BlackCat imploded, and RansomHub went dark in April 2025. On paper, that looks like progress. In practice, the operators and affiliates behind those brands did not disappear; they moved.
When RansomHub shut down, researchers watched its affiliates migrate almost immediately to other operations. One tracker noted Qilin's share of reported incidents in one sector nearly tripling in a single quarter as displaced affiliates moved across, per Paubox's analysis of the consolidation. The talent and the tooling simply changed letterhead.
Qilin: the brand that absorbed the fallout
Qilin has been the clearest beneficiary. After the disruptions to LockBit, ALPHV/BlackCat, and RansomHub, it absorbed displaced affiliates and, by mid-2025, had become one of the most active ransomware threats in the world — claiming hundreds of victims across more than 60 countries, according to threat-group profiling by Halcyon. Healthcare has been a recurring target since the group's earliest days.
It is not a lone actor. Flare's analysis of ransomware activity against EMEA healthcare identified 14 distinct threat-actor groups going after healthcare targets in its sample, including Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, and 3AM. The ecosystem is crowded, and it is competitive.
More brands, more often
The churn shows up in the numbers. Black Kite's tracking found the count of active ransomware groups climbing to 146 by mid-2026, with dozens of new brands entering the market over a single year — more than one new operation per week, sustained. For a hospital security team, that means the specific group behind the next attack is almost impossible to predict, and yesterday's indicators-of-compromise for a named gang are a fragile defense.
Why this changes the defensive math
When the threat was a handful of stable brands, signature- and reputation-based defenses could keep some pace. A fragmented, fast-rebranding ecosystem breaks that model: new affiliates bring new tooling, and new brands have no track record to match against. The constant across all of them is behavior — encryption, lateral movement, credential abuse, and data exfiltration look similar regardless of the logo on the ransom note.
That is the case for defending on behavior and resilience rather than group attribution. Immune detects ransomware by what it does, not who is doing it, contains it before it can spread across a hospital network, and self-heals affected clinical systems from immutable backups — so it does not matter whether the next attacker is Qilin, a RansomHub successor, or a brand that did not exist last month.
Sources
- Paubox — How ransomware consolidation increases risk for healthcare
- Halcyon — Qilin threat group profile
- Flare — Impact analysis of ransomware attacks on EMEA healthcare
- Black Kite — 2026 Ransomware Report
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
