Qilin Dominates Ransomware Market Amid Growing Cybercrime Consolidation

2026-07-03T14:52:17Z18aab5a36546671b8be4edf2fb5e9181e74ff20c832e75ac7882193b1626c594
djinn-stealereuropolfileless-malwareindustrialized-attacksinfostealerinterpol-impersonation','ousaban','banking-trojan','macos','macomillenium-ratmirainetnutoperation-endgameoracle-peoplesoftphishingpopa-botnetproxy-networkpurelog-stealerqilinransomwareransomware-as-a-servicermmsimplehelptaskweaverteampcptelegram-ratveil#dropzero-day

What happened

A cluster of high-impact developments signals consolidation and professionalization of cybercrime: Qilin has emerged as the dominant RaaS actor and a partnership with TeamPCP warns of more 'industrialized' ransomware operations. Multiple exploited zero-days and supply-chain vectors are being actively abused — notably Oracle PeopleSoft intrusions affecting NAIC and Nissan — while a critical SimpleHelp RMM flaw was weaponized to deliver TaskWeaver and Djinn Stealer. Law-enforcement actions (FBI/Google takedown of the NetNut proxy/Popa botnet; Europol’s Operation Endgame against StealC/Amadey) co

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
18aab5a36546671b8be4edf2fb5e9181e74ff20c832e75ac7882193b1626c594
Enrichment time
2026-07-03T14:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.