Actor Models
How Ransomware Groups Choose Their Targets
Volume Tells Part of the Story. Method Tells the Rest.
The ransomware market was shaped by several operating models running at the same time.
The actor landscape did not move in a straight line. Across the 12-month reporting period, leadership shifted, momentum changed, and different groups surged at different moments. The race view below shows how visible victim volume accumulated month by month, setting up the actor models that follow.
18-Month Cumulative Victim Disclosures by Ransomware Actor, January 2025–June 2026
Victims Claimed by Ransomware Group, April 2025–March 2026
Some actors scaled through volume. Some concentrated around exposed software and patch debt. Some turned single vulnerabilities into broad victim clusters. Others leaned into credentials, regional focus, or fast opportunistic operations. Looking only at victim count misses that difference. The more useful question is not only who disclosed the most victims, but how each actor converted access into leverage.
Five Actor Models Observed in the Dataset:
Volume Operator
Qilin
1,358 victims, average RSI of 0.538, high volume across more than 50 countries, systematic rather than highly selective
Patch Debt Predator
Everest
Average software vulnerability count of 366.8
Mass Exploitation Specialist
Clop
One vulnerability can produce many victims, as seen across MOVEit, Cleo, and Oracle EBS style campaigns
Credential Player
World Leaks
Average credential-related exposure count of 26.9, with a stronger United Kingdom focus
Opportunist
Play
Average RSI of 0.512, heavy United States and Canada concentration, fast and lower profile operations
Victim Count vs. Average Victim RSI by Threat Actor, April 2025–March 202
These models are not rigid categories. A single actor can use more than one access path, and tactics change over time. But the categories help explain why ransomware continued to scale even as individual brands rose, declined, or disappeared. The market ran several playbooks at once.
Qilin: The Volume Operator
Qilin was the clearest volume engine of the reporting period.
The group moved from 250 victims in the previous reporting period to 1,358 victims this year, a 443% increase. That means Qilin was associated with roughly one in every five to six victims observed by Black Kite. Among Qilin's victims, the average RSI was 0.538, which is moderate enough to suggest broad targeting versus only selecting the most visibly vulnerable organizations. The stronger signal was scale. Qilin operated across more than 50 countries, with about half of its victims in the United States and the rest spread across a broad international footprint.
Total Qilin victims recorded this year
Year-over-year increase in Qilin victims
Countries operated across by Qilin
Beyond the count increase, the group’s operational model also helps explain why it became central to the second half acceleration. Public reporting describes Qilin as a franchise style RaaS operation in which affiliates are largely responsible for gaining initial access, while core operators manage payload configuration, negotiations, payments, and leak site operations. That division of labor matters because it lowers the barrier for affiliates while keeping the most sensitive parts of the operation centralized.
The “Call a Lawyer” feature is important for the same reason. It is a signal that ransomware operations are professionalizing the pressure layer around the attack. The legal and regulatory consequences of a breach become part of the negotiation environment. In that sense, Qilin’s growth was as much procedural as technical.
Qilin’s importance, then, is not simply that it ranked first but that it shows what a mature volume operator can look like in a fragmented market: broad geography, high disclosure output, affiliate enabled access, centralized extortion operations, and a pressure model that extends beyond encryption alone.electing the most visibly vulnerable organizations. The stronger signal was scale. Qilin operated across more than 50 countries, with about half of its victims in the United States and the rest spread across a broad international footprint.
Other Models in the Same Market
Everest represented a different pattern. Its victim count was far lower than Qilin’s, but its average software vulnerability count was substantially higher. That makes Everest better understood as a patch debt predator. Rather than pursuing scale, the group consistently appeared around organizations carrying large volumes of unresolved vulnerabilities and elevated technical exposure. In this model, the opportunity comes from accumulated technical debt, not volume.
Clop is best understood as a mass exploitation specialist. Its recurring logic is simple and specific: one exposed enterprise technology can create many downstream victims. MOVEit, Cleo, and Oracle EBS all belong to that pattern. Clop’s model is closer to campaign-based exploitation than broad daily volume. It does not need to post victims every week to matter. When the right platform is exposed, scale can arrive quickly.
This is why Clop remains important even when it is not the year’s highest-volume actor. Its impact comes from concentration: one vulnerability, one platform, one supplier or enterprise application, and many organizations pulled into the same extortion event. Oracle EBS did not appear to reproduce the business impact or payment conversion of earlier Clop campaigns, but it still showed that the mass-exploitation model remains operationally viable. The technical playbook did not disappear; its economic return looked less certain.
World Leaks fit a credential player profile. Its average credential-related exposure was the strongest signal in the model set, and its activity showed a United Kingdom focus. The exposed credential environment around its victims was the defining feature of the group’s profile — not every incident began with credential abuse.
Play remained an opportunist. Its average RSI was lower than many actors, and its victim geography was heavily concentrated in the United States and Canada. The model is less about a single dramatic campaign and more about persistent, fast, practical targeting. Play remained active because its operating model was efficient, not because it dominated the market.
Scattered Spider and ShinyHunters: Impact Density
Not every actor shaped the year through volume.
Scattered Spider and ShinyHunters did not need Qilin-level victim counts to matter. Their impact came from density: fewer incidents, but higher operational, reputational, and board-level consequences.
Scattered Spider showed how far a human-layer attack can go when the attacker understands the process. Help desk impersonation, identity manipulation, and sector clustering turned support workflows into access paths. The advantage was not only technical skill, but fluency in how large organizations verify trust, reset access, and respond under pressure.
ShinyHunters followed a different route to the same outcome. Its relevance came from access paths and timing, especially the BPO-to-Salesforce pattern. The breach and the extortion did not always feel like one event. Access, data exposure, pressure, and public disclosure could unfold across a longer timeline.
Together, they show why ransomware risk cannot be measured only by counting victims.
Qilin explains volume. Scattered Spider and ShinyHunters explain pressure.
LockBit 5.0: A Limited Return
LockBit 5.0 deserves a shorter treatment.
The brand returned, but the data does not support treating it as a full return to previous market power. Black Kite observed 186 victims associated with LockBit 5.0 during the period. Only 19% were in the United States, and the distribution showed a stronger shift toward Latin America than earlier LockBit narratives would suggest.
The December 26 disclosure of 53 victims was significant, but it should be read as a timing and visibility play rather than proof of a broad resurgence. The December 26 timing was deliberate. A high-volume disclosure on a holiday creates concentrated pressure precisely when organizational response is most fragmented. It does not, by itself, show that LockBit regained its former position.
The more accurate conclusion is restrained: LockBit 5.0 showed that the name still carried market value, but the operation did not define the year. In 2026, the larger story was the coexistence of multiple playbooks in a more adaptive ransomware market.
Marked Once, Hunted Twice
Ransomware victim ownership was not always cleanly attached to a single actor brand.
Black Kite observed 130 unique domains that appeared under more than one ransomware actor during the reporting period. In total, those overlaps created 251 shared victim clusters and 376 related events.
The Sankey chart should be read as a visibility pattern across actor brands, not as proof of a single transfer mechanism. Some cases may reflect affiliate movement, shared access, repeated targeting, false claims, or separate actors identifying the same high value target.
Still, the pattern matters. Some organizations reappeared under different actor brands after their first disclosure, suggesting that victim knowledge, access paths, or perceived value persists beyond the initial incident.
Qilin sits near the center of this flow, appearing both as a source and destination in a shared victim movement. That does not prove causality, but it fits the broader profile of a franchise style RaaS operation: a market where affiliates, access, and victim intelligence can move faster than brand loyalty.
How Repeat Victims Move Between Ransomware Groups, April 2025–March 2026
Next: Supply chain incidents changed the threat geometry in 2026.
See how trusted vendor platforms became entry points and what that means for exposure at scale.