Pentera Expands Ransomware Testing to Cover Qilin, Play, and BlackCat
Event summary
- Pentera has added granular testing for Qilin, Play, and BlackCat ransomware families to its platform.
- Qilin is the most active ransomware group in 2025 with nearly 1,000 victims and 342 attacks in Q1 2026.
- Play tripled its victim count to 900 by May 2025 and saw a 64% increase in Q1 2026 attacks.
- BlackCat (ALPHV) is responsible for over 1,000 breaches and nearly $300M in ransom payments.
The big picture
Ransomware remains the primary driver of cybercrime, present in 48% of all breaches according to Verizon's 2026 DBIR. Leading groups like Qilin, Play, and BlackCat are increasingly difficult to detect as they sidestep traditional security controls. Pentera's expansion of ransomware testing capabilities aims to address this growing threat by enabling organizations to validate their defenses against real attack scenarios.
What we're watching
- Ransomware Evolution
- How the continuous evolution of ransomware families like Qilin, Play, and BlackCat will challenge traditional security controls.
- Security Validation
- Whether Pentera's expanded testing capabilities can effectively reduce exposure to these evasion-capable ransomware operations.
- Market Adoption
- The pace at which enterprises will adopt continuous threat exposure management (CTEM) practices to stay ahead of sophisticated ransomware threats.
Related topics
