Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Error’d: Pickup Sticklers

      September 27, 2025

      From Prompt To Partner: Designing Your Custom AI Assistant

      September 27, 2025

      Microsoft unveils reimagined Marketplace for cloud solutions, AI apps, and more

      September 27, 2025

      Design Dialects: Breaking the Rules, Not the System

      September 27, 2025

      Building personal apps with open source and AI

      September 12, 2025

      What Can We Actually Do With corner-shape?

      September 12, 2025

      Craft, Clarity, and Care: The Story and Work of Mengchu Yao

      September 12, 2025

      Cailabs secures €57M to accelerate growth and industrial scale-up

      September 12, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025
      Recent

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025

      Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

      September 28, 2025

      The first browser with JavaScript landed 30 years ago

      September 27, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured
      Recent
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Qilin Remains Top Ransomware Group as Attacks Rise

    Qilin Remains Top Ransomware Group as Attacks Rise

    August 15, 2025

    Qilin top ransomware group

    Qilin continues to stake a claim as the top ransomware group in the wake of the decline of RansomHub earlier this year.

    In July, Qilin led all ransomware groups in claimed victims for the third time in the four months since RansomHub went offline in a possible compromise by rival DragonForce, according to a Cyble blog post published this week.

    Qilin’s 73 victims in July accounted for 17% of the month’s total of 423 victims, while INC Ransom was second with 59, boosted by critical infrastructure attacks and an increase in victim disclosures, Cyble said. SafePay, Akira and Play rounded out the top five ransomware groups for the month.

    Qilin Leads as Ransomware Attacks Rise

    July’s total was the third consecutive monthly increase in ransomware victims, Cyble said, following a three month decline from February’s record ransomware attacks (image below).

    Ransomware attacks by month July 2025
    Ransomware attacks by month through July 2025 (Cyble)

    Cyble noted that while ransomware victims in recent months have been half of February’s record, the long-term uptrend for ransomware attacks remains intact, as 2025’s lowest month (402 attacks in May) remains well above the lows of 2023 (161 in January 2023) and 2024 (243 in January 2024).

    The U.S. remains by far the most attacked country with 223 victims, eight times greater than second-place Canada (chart below).

    top countries for ransomware attacks July 2025
    Top countries for ransomware attacks, July 2025 (Cyble)

    Critical Infrastructure, Supply Chain Targeted by Ransomware

    Cyble noted that there were 25 possible critical infrastructure ransomware incidents in July, and an additional 20 incidents targeted the software supply chain, highlighting the seriousness of many of the attacks. The blog post detailed eight of the more significant incidents during the month, in addition to technical details on attacks, emerging ransomware groups and new ransomware variants.

    Professional Services, Construction, Manufacturing, Healthcare and IT were the five most attacked sectors, accounting for nearly half of all ransomware attacks during July.

    Among the vulnerabilities apparently exploited by ransomware groups were CVE‑2025‑5777, a Citrix NetScaler ADC and Gateway Out-of-Bounds Read vulnerability, and four Microsoft SharePoint vulnerabilities (CVE-2025-53770, CVE-2025-53771, CVE‑2025‑49704 and CVE‑2025‑49706), among others.

    Nearly 40 new ransomware variants were identified in July, in addition to several new threat groups.

    Emerging ransomware groups identified in the Cyble blog included the BEAST Ransomware Group, D4RK4RMY, Payouts King, Sinobi, AiLock ransomware, and KaWaLocker ransomware.

    New ransomware variants included DeadLock, Crux, and a powerful new Linux ransomware variant from the Gunra ransomware group.

    “With the finances and motivation to support ongoing research and development, ransomware groups can be counted on to continually evolve, and security teams must prepare for these evolving threats,” Cyble concluded.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSand Blast
    Next Article Taiwan Web Servers Breached by UAT-7237 Using Customized Open-Source Hacking Tools

    Related Posts

    Development

    Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

    September 28, 2025
    Development

    Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

    September 28, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Laravel Factories and Seeders: All You Need to Know

    Development

    Learning from PHP Log to File Example

    Development

    Coding Agents See 75% Surge: SimilarWeb’s AI Usage Report Highlights the Sectors Winning and Losing in 2025’s Generative AI Boom

    Machine Learning

    Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials

    Development

    Highlights

    Machine Learning

    The future of quality assurance: Shift-left testing with QyrusAI and Amazon Bedrock

    April 17, 2025

    This post is co-written with Ameet Deshpande and Vatsal Saglani from Qyrus. As businesses embrace…

    8 Venture Firms in Cybersecurity Making Big Moves in 2025

    June 19, 2025

    Now It’s Claude’s World: How Anthropic Overtook OpenAI in the Enterprise AI Race

    August 4, 2025

    50+ Model Context Protocol (MCP) Servers Worth Exploring

    June 8, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.