Cisco Talos warns about attacks from the Russian-speaking RaaS group Qilin
Articles by the same author:
1
3
The cybersecurity firm Cisco Talos published, on October 26, 2025, a report on the Russian-speaking ransomware gang Qilin, one of the most active cybercriminal organizations in the world. Operating on a Ransomware-as-a-Service (RaaS) model with a network of affiliates, the group has claimed several hundred attacks in 2025 targeting large companies, local governments, and hospitals.
In October 2025 alone, Qilin added 185 victims to its leak site. The RaaS group has claimed responsibility for recent breaches against Japan’s beverage giant Asahi, the city of Sugar Land in Texas, a county in North Carolina, and several power companies in Texas. Half of these attacks targeted the United States, but France, Canada, South Korea, and Spain also appear among its regular victims.
Active since 2022, Qilin has significantly increased its ransom demands in 2025. In February, the gang demanded 4 million dollars after crippling the municipal court of Cleveland. The following month, it asked for 10 million dollars following the attack on Kuala Lumpur International Airport in Malaysia.