Securotrop is a Qilin-affiliated ransomware group from early 2025 targeting US industrial sectors.
Analyst brief
Securotrop is a ransomware group established in early 2025, operating within the Qilin affiliate network with an independent public identity. They exclusively target commercial entities in the United States across manufacturing, energy & utilities, technology, and transportation sectors, deliberately avoiding healthcare and government organizations. While specific TTPs are not detailed, they likely employ double-extortion tactics common to Ransomware-as-a-Service (RaaS) operations like Qilin. Defenders should focus on network segmentation, verified backups, and anomaly detection, particularly in the listed sectors.
securotrop
activecrime
Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while maintaining an independent public identity, focusing exclusively on commercial targets and deliberately avoiding healthcare and government entities, with approximately 32 documented victims.
Securotrop targets commercial entities in the United States across manufacturing, energy & utilities, technology, and transportation sectors.
What is Securotrop's distinctive operational tactic?+
Securotrop deliberately avoids healthcare and government organizations, focusing exclusively on commercial targets. As they operate within the Qilin affiliate network, they employ double-extortion tactics typical of RaaS operations.