Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Ransomware

The new mid-tier RaaS contenders: Qilin, Medusa, Embargo

Ransomnews Research TeamBy Ransomnews Research TeamMay 3, 2026No Comments3 Mins Read994 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Three stylised sport-team-style banners hanging in a row with abstract emblems for mid-tier ransomware operators
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The post-LockBit ransomware market hasn’t produced a single dominant operator. Instead it produced a long mid-tier of operators each claiming dozens to low-hundreds of victims per quarter. Three of them, Qilin, Medusa, and Embargo, have stable affiliate bases, working tooling, and recognisable victim patterns. Here’s the comparative profile.

Qilin

Qilin (also known as Agenda) emerged in mid-2022 and has matured into one of the most operationally consistent operators on the leaderboard. Their encryptor is cross-platform with mature ESXi support, and they’ve built a reputation among affiliates for paying out reliably. The 2025 attacks against Synnovis (UK pathology services, with downstream impact on multiple London hospitals) drew sustained press attention.

Affiliate split is competitive (80-85% to the affiliate). Initial-access patterns include phishing, credential abuse, and edge-appliance exploits. Victim sectors skew toward manufacturing and healthcare, with notable activity against the European mid-market.

Medusa

Medusa (the ransomware operator, not to be confused with the Medusa botnet) has been claiming victims since 2021 but accelerated significantly in 2024-2025. The operator’s distinguishing trait is aggressive press engagement, they regularly comment on victim incidents publicly and have used media outreach as a pressure tactic. CISA published a joint advisory in 2025 specifically on Medusa TTPs.

The encryptor is competent rather than novel. Affiliate operations focus on opportunistic targeting, they appear to take whatever access their affiliates bring rather than pursuing specific verticals. Education, public sector, and small-to-mid enterprise dominate the claim list.

Embargo

Embargo is the newest of the three, emerging in mid-2024 and building claim count steadily through 2025-2026. The operator runs a Rust-based encryptor (an increasingly common choice for new operators after the post-Conti BlackBasta shifted to Rust). Their leak site has unusually professional victim-management UX, suggesting either an experienced team or substantial vendor-provided tooling.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Embargo has been notable for negotiation discipline, they appear to honour deletion attestations more reliably than most newer operators, which is partly why their affiliate base has grown despite the crowded market.

What the mid-tier rise means

Three implications for defenders.

Operator-specific TTP modelling is less useful. When LockBit dominated the market, learning LockBit’s playbook covered most of the threat. With a fragmented mid-tier, you have to model TTPs at the technique level rather than the operator level. MITRE ATT&CK mapping matters more than ever; threat-actor-specific playbooks matter less.

Takedowns hurt the ecosystem less. A successful disruption of Medusa would shift maybe 10% of activity to other operators. The market has become structurally resistant to law-enforcement disruption.

The defensive priority list is operator-agnostic. Edge-appliance patching, identity hygiene, MFA hardening, EDR coverage, segmentation, and offline backups protect against all three of these and most of their peers. Whatever the next mid-tier brand is in 2027, the same controls protect against them too.

The forecast

Expect at least one of these three to fade and at least one new mid-tier operator to emerge by year-end. The rotation is constant. The ecosystem’s volume isn’t going down, it’s redistributing across more operators of similar size. That’s the structural state of ransomware in 2026.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleLapsus$ revival rumors in 2026: what we know and what we don’t
Next Article Lumma vs RedLine vs Vidar in 2026: market share by infections
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Interlock: the drive-by ransomware crew CISA flagged

July 20, 2026

SafePay: the centralised crew that skipped affiliates

July 20, 2026

INC Ransom: the RaaS that wins by mastering the basics

July 20, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.