New Threat Coalition Emerges
In a troubling development for cybersecurity defenders, three leading ransomware groups — LockBit, Qilin, and DragonForce — have publicly announced a strategic alliance. The partnership is poised to reshape the ransomware ecosystem by enabling these actors to pool resources, share tactics and infrastructure, and amplify the scale and sophistication of future attacks. According to threat intelligence firm ReliaQuest, this coalition may mark a pivotal moment in the evolution of financially motivated cybercrime.
Key Details of the Alliance
- Shared capabilities and infrastructure
The alliance is designed to allow each group access to the others’ techniques, infrastructure, and resources, strengthening their collective operational capacity.
ReliaQuest notes that the union emerges amid LockBit’s resurgence; the group had suffered significant setbacks after law enforcement disrupted its network and detained members in 2024. - LockBit’s comeback and reputation rebuilding
Following a major takedown in early 2024 under “Operation Cronos,” LockBit had lost both infrastructure and credibility with its affiliates.
With this new alliance, it aims to regain prominence and restore affiliate trust — potentially catalyzing a resurgence in attacks, particularly targeting critical infrastructure. - Qilin’s rising prominence
Qilin has emerged as one of the most active ransomware groups in recent months, having claimed over 200 victims in the third quarter of 2025 alone.
ZeroFox reports that Qilin has been disproportionately targeting organizations in North America, citing both geopolitical motivations and the expanding attack surface in that region. - Technological advances and attack breadth
The timing of the partnership coincides with the launch of LockBit 5.0, which extends the group’s reach to systems running Windows, Linux, and ESXi.
Experts warn that the combined arsenal of the allied groups could lead to more potent multi-platform attacks and potentially greater complexity in decryptor negotiation. - Threat expansion and sector targeting
While U.S., Germany, U.K., Canada, and Italy remain frequent targets, cybercriminals are increasingly striking nontraditional geographies like Egypt, Thailand, and Colombia.
In Q3 2025 alone, there were at least 1,429 ransomware and digital extortion (R&DE) incidents globally.
Groups such as Qilin, Akira, INC Ransom, Play, and SafePay are now responsible for nearly 47 percent of all attacks across Q2 and Q3 of 2025.
Background: Ransomware Alliances and the Stakes
Ransomware-as-a-Service (RaaS) models have already enabled nontechnical actors to orchestrate attacks by leasing access from developer groups. What’s different in this new alliance is the merging of powerful developer tiers, not just affiliates, signaling a deeper level of coordination.
LockBit, before its takedown, was one of the most prolific groups worldwide, targeting over 2,500 victims and collecting more than USD 500 million in ransom payments in its prime.
The 2024 takedown forced a fragmentation of its operations, but this alliance might very well accelerate its reemergence as a top-tier threat.
Meanwhile, Qilin’s aggressive operations over the past year — especially targeting high-value North American entities — have placed it in the spotlight as a rising contender.
DragonForce’s involvement rounds out a trio that now spans multiple geographies, infrastructures, and attack vectors.
ReliaQuest, in its Q3 2025 ransomware report, warns that if the alliance succeeds in restoring affiliate confidence in LockBit, we could witness a substantial uptick in attacks — especially within sectors considered previously low-risk.
This alliance also emerges amid signs that other threat actors are retooling: for example, “Scattered Spider,” known for social engineering attacks, is reportedly preparing to launch an English-language RaaS program dubbed “ShinySp1d3r.”
Expert Insights & Risks Ahead
Though the primary public information comes via ReliaQuest and ZeroFox reports, cybersecurity analysts widely caution that combining operatives in this way brings serious implications:
- Increased operational sophistication — Pooling intelligence, encryption tooling, and exploit kits may elevate the technical barrier for defenders.
- Greater scale and reach — Expanded infrastructure and affiliate networks could allow attacks to spread faster and across new geographies.
- Target broadening — Higher risk for sectors once deemed “safe zones,” such as small manufacturing, education, or regional government agencies.
- Law enforcement pressure — Coordinated action by global agencies could escalate, but taking down intertwined systems is also more complex operationally.
If the alliance can remain stable and cooperative (which historically has been a challenge for criminal groups), it might persist as a formidable adversary for years.
Conclusion: A Turning Point in Ransomware Warfare
The public formation of this alliance between LockBit, Qilin, and DragonForce marks a potentially significant inflection in ransomware history. It signals not just a tactical partnership, but an ethos shift: threat actors are aligning at higher levels, no longer simply competing or operating in silos. For defenders, the window for complacency narrows — organizations must elevate their threat awareness, continuously harden systems, and invest in intelligence-driven defenses.
As this coalition begins to flex its shared capabilities, the stakes for critical infrastructure, corporations, and government entities alike will rise sharply. The world of ransomware may be entering a new era — one where the line between individual groups becomes blurred and collective power defines dominance.
Please subscribe to the Newsletter so that you do not miss any critical update
