Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Ransomware’s Escalation: Double Extortion Targeting Multinationals & Governments

  1. Home   »  
  2. Ransomware’s Escalation: Double Extortion Targeting Multinationals & Governments

Ransomware’s Escalation: Double Extortion Targeting Multinationals & Governments

September 19, 2025September 22, 2026 admincybersecurity

Ransomware is no longer mainly an encryption problem. The groups that matter in 2025 steal data first and encrypt second, so a victim with perfect backups still faces a public leak, regulatory notifications and lawsuits. That is double extortion, and it has become the default business model rather than an advanced tactic.

Two groups illustrate where it is heading. Qilin, an established ransomware-as-a-service operation, became the most active ransomware brand in mid-2025 as affiliates left disrupted rivals. Kawa4096, a newcomer that surfaced in June 2025, went straight after US and Japanese multinationals with a playbook borrowed from bigger names. Large companies and state and local governments are the targets of choice because they hold the most sensitive data and suffer the most from downtime. This article explains how these operations work and what actually reduces your exposure.

How double extortion works

A modern ransomware intrusion follows a predictable sequence. Attackers gain access through phishing, stolen credentials or an unpatched internet-facing system. They escalate privileges, often with credential-dumping tools such as Mimikatz, and move laterally until they control directory services and file shares. Then, before anything is encrypted, they quietly copy out contracts, HR files, customer records and anything else that will embarrass the victim or trigger legal obligations.

Only after the data is safely in their hands do they detonate the encryptor, delete volume shadow copies and leave a ransom note. The note typically points to a Tor-based leak site where the victim’s name appears with a countdown. Pay, and the data is supposedly deleted. Refuse, and it is published or sold.

The pressure therefore comes from two directions at once: operations are down, and a clock is running on disclosure. Restoring from backup solves the first problem and does nothing about the second. That is why immutable backups, while essential, are no longer a complete ransomware strategy.

Qilin: a mature affiliate business

Qilin first appeared in 2022 under the name Agenda and was rebuilt around a Rust-based encryptor, which makes it portable across Windows, Linux and VMware ESXi environments. It runs as ransomware-as-a-service: the core team maintains the malware, leak site and negotiation infrastructure, while affiliates carry out intrusions in exchange for a share of each payment.

Its most damaging known attack hit Synnovis, a pathology provider to NHS hospitals in London, in June 2024. Blood testing was disrupted for weeks, thousands of appointments and procedures were postponed, and patient data was leaked. In 2025, as law enforcement actions and internal collapses scattered affiliates from groups such as LockBit and RansomHub, Qilin absorbed many of them. Several threat intelligence firms ranked it the most active ransomware group from June 2025 onward.

Qilin also invests in pressure. In mid-2025 it advertised a “Call Lawyer” feature that offers affiliates legal advice during negotiations, framing the regulatory consequences of a leak to push victims toward paying. The message is that the extortion is not just about files; it is about the victim’s legal exposure.

Kawa4096: a new brand borrowing credibility

Kawa4096 shows how quickly a new operation can become dangerous. Researchers at LevelBlue SpiderLabs and AhnLab documented the group after it appeared in June 2025 and listed at least 11 victims within weeks, concentrated in the United States and Japan. Its leak site copies the terminal-style look of the Akira group, and its ransom note closely resembles Qilin’s. Imitating recognized brands is a deliberate tactic: a victim who believes they are dealing with an established group is more likely to believe the threat is real.

Technically, the Kawa4096 encryptor is built for speed. It encrypts local and shared network drives using multithreading, deletes shadow copies through vssadmin and WMI, and relaunches itself with an “encrypt everything” flag when run without arguments. None of this is novel, which is the point. Commodity techniques assembled competently are enough to hurt a multinational that has not closed the basic gaps.

Why multinationals and governments are in the crosshairs

Large organizations are attractive for reasons that go beyond deep pockets. Multinationals operate across many jurisdictions, so a single leak can trigger breach notification duties in several countries at once, which raises the cost of refusing to pay. Their networks are sprawling, with acquired subsidiaries, regional IT teams and inconsistent controls that give attackers a weak entry point into a strong parent. Japanese firms with US subsidiaries, and US firms with Asian operations, have seen attackers enter through the less-defended side.

State and local governments face a different squeeze. They run services residents cannot do without, such as courts, 911 dispatch, utilities and permitting, often on legacy systems with limited security staff. Downtime is politically visible, and the data they hold (tax records, social services files, law enforcement material) is sensitive. For both groups, the consequences of a leak are:

  • Reputational damage: customers, citizens and partners lose trust once their data appears on a leak site.
  • Compliance and legal risk: exposed personal data, health information or intellectual property triggers notification requirements, regulatory scrutiny and class actions.
  • Operational paralysis: encrypted systems can halt production, billing or public services for weeks, and full recovery can take months.

Defending against double extortion

Because the attack has two halves, the defense must too: make encryption survivable, and make exfiltration hard and visible. In practical order:

  1. Close the common entry points. Require phishing-resistant MFA on email, VPN and remote access, remove exposed RDP, and patch internet-facing appliances within days. Stolen credentials and unpatched edge devices account for most initial access.
  2. Keep immutable, tested backups. Store at least one copy offline or in immutable storage, include hypervisors and identity systems, and time a full restore. This addresses encryption, not the leak.
  3. Deploy EDR or XDR with someone watching. Behavior-based detection catches credential dumping, shadow copy deletion and mass file changes, but only if alerts are triaged around the clock.
  4. Watch for data leaving. Monitor outbound volume, unfamiliar cloud storage destinations and tools such as rclone. Exfiltration usually takes hours or days, which is your window to catch it.
  5. Segment and apply zero trust. Separate subsidiaries, backups and critical servers, and verify every user and device so a single compromised laptop cannot reach everything.
  6. Reduce what can be stolen. Data you no longer keep cannot be leaked. Retention policies and encryption of sensitive records at rest shrink the extortion leverage.
  7. Train staff and rehearse the response. Teach employees to recognize phishing and social engineering, and run a tabletop exercise that includes the leak scenario: legal counsel, regulators, communications and the decision on whether to engage with the attacker.

The trade-off is investment in areas that do not show immediate return, such as data minimization and exfiltration monitoring. The alternative is discovering during an incident that backups solved only half the problem. Our cybersecurity and compliance services help map these controls to the notification and reporting obligations a leak would trigger. For the broader history of how ransomware got here, see Ransomware Is Evolving, and So Are the Stakes, and for one of the affiliate crews that has worked with these operations, Scattered Spider Isn’t Gone.

Update (September 2026): The pattern held. In late September 2025 a Qilin attack disrupted order and shipping systems at Japanese brewer Asahi Group Holdings, a textbook example of a multinational hit by both downtime and data theft. The defensive priorities above remain the same.

Frequently asked questions

If we have good backups, do we still need to worry about ransomware?

Yes. Backups let you recover from encryption, but in a double extortion attack the data has already been stolen. You still face leak threats, notification obligations and potential litigation, so you need controls that prevent and detect exfiltration as well.

Does paying the ransom stop the data from being leaked?

There is no guarantee. You are relying on a criminal’s promise to delete data, and stolen data has resurfaced after payment in past cases. Payment can also create legal problems if the group is sanctioned. Any decision should involve legal counsel and, where appropriate, law enforcement.

Are smaller organizations safe if these groups target multinationals?

No. Headline attacks focus on large targets, but affiliates hit whatever they can access, and smaller suppliers are often the path into larger customers. The same controls apply at any size.

Preparing for double extortion

Delana Technologies helps organizations close the gaps double extortion exploits: identity and access controls, backup resilience, exfiltration monitoring and a tested incident response plan that covers the leak as well as the lockout. To assess your ransomware readiness, call 239.414.5126 or contact us.


Sources: LevelBlue SpiderLabs, “KAWA4096’s Ransomware Tide: Rising Threat With Borrowed Styles” (2025); AhnLab ASEC analysis of Kawa4096 (2025); Barracuda Networks, “Qilin ransomware is growing” (July 2025); The Hacker News reporting on Qilin’s “Call Lawyer” feature (June 2025); public reporting on the Synnovis attack (June 2024) and the Asahi Group attack (September–October 2025).

Post navigation

Previous: The Silent Threat: Proxy Botnets Are Hijacking VPS Servers for Covert Attacks
Next: Critical Zero-Days: Legacy Software & Widely-Used Platforms Under Siege

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC