Module 07: Ransomware Groups and RaaS Variants
Franchise core that develops tooling, manages admin panels, and oversees affiliate recruitment. Node: Op in the EDP Dependency Map, assessed HIGH tier with MEDIUM replace difficulty.
HIGH TierNode: Op / M07Download PDF
Position in Ecosystem: Node: Op, RaaS Operator Open the full ecosystem map ↗
Operators rent the same abuse-resistant backbone their panels, C2, and leak infrastructure run on: OFAC tied Media Land to hosting for LockBit, Black Basta, Play, BlackSuit, and Evil Corp, five operator brands on one supplier, and Zservers served as LockBit primary host (Confirmed). Provider-level action therefore radiates across every brand renting from it, an efficiency no action against a single rebrandable operator can match (Analyst inference).Bulletproof HostingUpstream dependencyRaaS brands recruit affiliates and signal reliability through forum reputation and dispute-management systems.Underground ForumsUpstream dependencyRaaS operations use crypters and packers as force multipliers to preserve tooling effectiveness during deployment.Crypters & PackersUpstream dependencyExploit-sourced access can feed RaaS operators directly when speed or target value justifies bypassing markets.Exploit BrokersUpstream dependencyIABs are the main commercial transfer point moving validated footholds to ransomware operators.Initial Access BrokersUpstream dependencyExposure kills brands without enforcement action: the Black Basta chat leak ended the brand with zero LE involvement (defunct 18 months, no successor), the Conti leaks broke reconstitution by destroying trust rather than capacity, and The Gentlemen admin exposure opened a documented pressure window (events Confirmed; edge framing Analyst inference).Exposure / Doxxing ActorsUpstream dependencyOperators use the same anonymization layer for panel administration and infrastructure management; attribution of specific operator-side usage is thinner than the affiliate-side customer records, so the edge is secondary.VPN / Anonymity ProvidersUpstream (partial)Higher-end operators sometimes use fresh log access directly, bypassing the brokerage layer.Stealers & Log MarketsUpstream (partial)ACTIVE PROTECTION: FSB maintains direct krysha relationships with protected RaaS operators — transactional shielding, recruitment, and legal backstop. Direct pressure reliably converts tolerance into hardened protection and should be avoided unless actor elimination is the explicit goal.FSB ProtectionState protection / toleranceREVENUE SPLIT + STAGING: Victim payment lands at a collection wallet (the ransom address). Funds are swept automatically into a staging/treasury wallet that consolidates multiple victim payments before splitting. From treasury: 70-80% is peeled to the affiliate payout wallet, 20-30% to the operator fee wallet. Each payment generates two parallel financial flows entering the laundering stack through separate wallets. The collection-to-treasury-to-payout sequence is the on-chain signature of a mature RaaS operation. Disrupting the split mechanism (escrow wallets, admin infrastructure) is structurally more damaging than targeting either party individually.RaaS AffiliatesPrimary dependencyRaaS depends on leak-site operations to turn compromise into double-extortion payment pressure.Leak Site OperationsPrimary dependencyOPERATOR SHARE (20-30%): After the treasury-to-payout split, the operator fee wallet holds the admin share. Proceeds enter mixers as the first obfuscation step. Operator wallets are higher-value and more consistently structured than affiliate wallets — the fan-in pattern (multiple ransom addresses consolidating into one treasury) is a durable on-chain fingerprint. Tracing the admin share is the higher-priority financial intelligence target.Crypto MixersPrimary dependencyOperators may manage negotiations directly or through delegated specialists depending on brand maturity.Negotiation ServicesPartial dependencySome operators maintain direct OTC relationships for high-value cash-out, bypassing parts of the laundering stack.OTC Crypto BrokersPartial dependencyFranchise core that develops tooling, manages admin panels, and oversees affiliate recruitment.RAAS OPERATORNode: Op / M07HIGH TIER / REPLACE: MEDIUM
Primary dependency Partial dependency State protection / dual use First-degree connections as assessed in the current ecosystem map (v3.0). Hover any node for the dependency note. Left side: what this node draws on or is protected by. Right side: what depends on it.
CURRENCY NOTE (June 2026): Several passages in this module describe RansomHub as the dominant active brand. RansomHub infrastructure went dark on April 1, 2025; affiliates dispersed primarily to Qilin and DragonForce, and Qilin has held the highest claimed-victim volume since mid-2025. Read RansomHub references as historical unless marked otherwise. Full reassessment due at the next module revision.
FieldValue
Module Number07
Module NameRansomware Groups and RaaS Variants
EDP Node ReferenceCross-cutting — no single node; assessed on arrival (see Section 8 for Dependency Map update recommendation)
Ecosystem LayerCore Operator / Central Monetization Layer
Upstream ConnectionsNode 04 (IAB Markets), Node 10 (Credential/Stealer Markets), Node 11 (Crypters/Packers), Node 03 (Bulletproof Hosting), Node 07 (Underground Forums)
Downstream ConnectionsNode 06 (Leak-Site Hosting), Node 01 (OTC Brokers), Node 02 (High-Risk Exchanges), Node 08 (Mixing/Obfuscation), Node 09 (Mule Networks)
Research DateApril 2026
Primary ResearcherReno
Source Tools UsedPerplexity AI; Chainalysis 2025 Crypto Crime Report; Secureworks State of the Threat; Coveware Quarterly Reports; Corvus/Travelers Q4 2024; Vectra AI; ReliaQuest; KnowBe4; IBM; Arctic Wolf

SECTION 1 — WHAT IT IS

1.5 Structural Variants — Five Archetypes

The ransomware group landscape comprises five identifiable structural archetypes, each with distinct risk and disruption profiles:

Archetype 1 — Classic RaaS Platform Operators: Full-stack programs serving a broad affiliate pool. Operators develop and maintain encryptors, decryptors, and supporting tooling. They host Tor-based leak sites, payment portals, and affiliate dashboards. They define revenue models, enforce targeting rules (e.g., CIS exclusion filters), and provide branding and playbooks. LockBit, ALPHV/BlackCat, and RansomHub are exemplars; all three are defunct or disrupted as of mid-2026. Current archetype exemplars: Qilin, DragonForce.

Archetype 2 — High-End Big-Game Crews: RaaS variants optimized for large-enterprise targets. These groups prioritize victims with high revenue capacity, use advanced initial access methods (zero-day and N-day exploits against edge devices), and employ structured multi-stage extortion including triple extortion (encrypt, exfiltrate, notify customers/regulators). Cl0p, BlackCat in its mature phase, and Black Basta are exemplars.

Archetype 3 — Mass-Market RaaS Kits: Commodity platforms sold via subscription or one-time license to low-skill actors. These prioritize volume over per-victim value. Affiliates rely on phishing, basic IAB access, and opportunistic exploitation rather than bespoke zero-days. Revenue per incident is lower but the affiliate pool is substantially larger.

Archetype 4 — Cartel-Style Coalitions: Post-disruption structures in which multiple groups share leak platforms, payment backends, and negotiation infrastructure under a loosely coordinated umbrella. These absorb displaced affiliates from disrupted major brands and use cartel-like coordination to manage victim negotiations and inter-group conflicts over access.

Archetype 5 — Operator-Affiliate Hybrids (Semi-RaaS): Groups that develop ransomware, run high-value campaigns internally, and selectively recruit a small affiliate cadre for secondary targets. These maintain centralized control over victim selection and negotiation. The Scattered Spider collaboration with ALPHV and later RansomHub is a documented example.

SECTION 2 — KEY ACTORS AND EXAMPLES

2.1 Named Actor Archetypes Table

ArchetypeKey Named GroupsKey TTPsAffiliate ModelConfidence
Classic RaaS PlatformLockBit 3.0, ALPHV/BlackCat, RansomHub (historical); Qilin, DragonForce (current)Full-stack development; Tor-based leak sites and negotiation portals; affiliate dashboards; CIS/RU targeting filters; revenue split modelOpen or semi-open recruitment; 60-80% affiliate shareCONFIRMED
Big-Game RaaS CrewsCl0p, Black Basta, BlackMatter (legacy)0-day/N-day exploit chains against MFT/VPN/edge devices; double and triple extortion; structured negotiation playbooks; multimillion-dollar ransom targetsSelective or closed recruitment; often tight partner circleCONFIRMED
Mass-Market KitsMultiple low-tier groups; frequently unnamed or short-livedTurnkey panels; phishing-dependent access; volume over value; entry-level subscriptions $40-$100/monthOpen subscription; affiliate retains 100% in license modelCONFIRMED
Cartel-Style CoalitionsPost-ALPHV/LockBit fragmentation clusters; INC Ransom; Rhysida (partial)Shared leak platforms; absorb displaced affiliates; coordinated negotiation; common payment backendsShared infrastructure; variable split arrangementsCREDIBLE
Operator-Affiliate HybridsScattered Spider (combined with ALPHV/RansomHub); specialized EDR-bypass crewsInternal campaigns for high-value targets; bespoke tooling; selective external affiliate recruitment; centralized victim selectionInvite-only; highly controlled affiliate circleCREDIBLE

2.2 Notable Documented Examples

LockBit 3.0 / LockBit Black: The most prolific RaaS platform by victim count before its February 2024 disruption by Operation Cronos. LockBit operated an affiliate program with publicly posted revenue splits, a bug-bounty program, and a corporate-style brand. Post-disruption, core developers attempted to relaunch as LockBit 4.0 while affiliates migrated primarily to RansomHub and BlackSuit (both since gone: RansomHub dark April 2025; BlackSuit leak and negotiation sites seized in Operation Checkmate, July 2025; the later affiliate destination is Qilin).

ALPHV/BlackCat: A sophisticated Rust-based RaaS that operated from 2021 to early 2024. Targeted healthcare extensively in its final months. Following a December 2023 FBI disruption and seizure, ALPHV operators conducted an apparent exit scam, withholding a USD $22M affiliate payment related to the Change Healthcare attack before shutting down infrastructure.

RansomHub: Emerged in early 2024 and rapidly absorbed displaced ALPHV and LockBit affiliates. By mid-2024 it was the most active group by victim postings. It operated as a classic affiliate split model and did not conduct intrusions directly, and was notable for posting victims within days of breaches and applying aggressive leak-site pressure. RansomHub went dark on 1 April 2025 (apparent exit-scam pattern); its displaced affiliates dispersed primarily to Qilin and DragonForce. Read the description above as historical.

Cl0p: Persistently exploits mass-vulnerability events in file-transfer and managed-file-transfer products (MOVEit Transfer, GoAnywhere, Accellion FTA). Each campaign generates hundreds of simultaneous victims. Uses a hybrid model with an internal technical team conducting exploitation and an affiliate or partner layer for secondary monetization.

Black Basta: Operated primarily 2022-2025; targeted large enterprises in manufacturing, healthcare, and critical infrastructure. Used Qbot/QakBot loader (pre-takedown) and later Pikabot for initial access. Sophisticated double-extortion model with structured negotiation. Internal chat logs leaked in early 2025 revealed operational details and state-adjacency indications.

2.3 Geographic Concentration

Russia and CIS states remain the dominant hosting environment for major RaaS operator infrastructure and the primary language of top-tier affiliate communities. Key indicators:

2.4 Scale and Volume Table

MetricValuePeriodSourceConfidence
Active double-extortion groups tracked1242025-26 timeframeVectra AICONFIRMED
New ransomware groups formed55 (+67% YoY)2024Corvus/TravelersCONFIRMED
Increase in active double-extortion groups+30% YoYJuly 2023 to June 2024SecureworksCONFIRMED
Groups posting victims in single month40 groups in May 2024May 2024SecureworksCONFIRMED
Leak site victims — quarterly peak1,663 victims in Q4 2024Q4 2024Corvus/TravelersCONFIRMED
Leak site victims — full year7,458-7,960 victims (+53% YoY)2025Vectra AICONFIRMED
US share of global leak-site victims~48%2024-25Vectra AICONFIRMED
Healthcare breach count700+ double-extortion breaches2024-25Vectra AICONFIRMED
Healthcare records exposed>275 million patient records2024-25Vectra AICONFIRMED
Total on-chain ransomware payments~USD $813M2024ChainalysisCONFIRMED
Change from prior yearDown from ~$1.25B in 2023 (~35% decline)2023 vs 2024ChainalysisCONFIRMED
Payment-to-demand ratio~53% gap (victims paid ~47% of demanded amount on average)H2 2024ChainalysisCONFIRMED
Typical payment bandUSD $150,000 to $250,000H2 2024ChainalysisCONFIRMED

2.5 State Adjacency Assessment

Dark Covenant 3.0 screening is applicable to major RaaS operators. The following state-adjacency indicators are present:

Confidence note: CONFIRMED for CIS filter evidence; CREDIBLE for Black Basta state-link reporting; ANALYST INFERENCE for broader FSB protection model as applied to current operators.

SECTION 3 — INFRASTRUCTURE DEPENDENCIES

3.1 Upstream Dependencies

RaaS operators depend on the following upstream nodes from the EDP Dependency Map:

Upstream NodeEDP NodeDependency TypeOperator Function Supported
Initial Access Broker MarketsNode 04CriticalAffiliates purchase network access; operators direct affiliates to IAB markets for victim acquisition; without viable IAB supply, affiliate deployment rates drop.
Credential/Stealer-Log MarketsNode 10HighAffiliates use credential dumps to identify and authenticate into victim networks; operators benefit from abundant, low-cost access material from stealer logs.
Crypter/Packer ServicesNode 11HighOperator payloads require crypter/packer services to evade EDR detection; some operators maintain in-house crypter capability while others outsource.
Bulletproof HostingNode 03CriticalOperator infrastructure (C2, leak sites, payment portals, negotiation panels, affiliate dashboards) depends entirely on BPH providers for uptime and attribution resistance.
Underground Forums and Dark Web MarketsNode 07HighPrimary affiliate recruitment channel; operator reputation management; sourcing of tooling and services; dispute resolution for affiliate conflicts.
Exploit/Vulnerability BrokersEDP Module 06Moderate-High (big-game archetypes)Big-game crews and hybrid operators require 0-day/N-day exploits for edge-device mass exploitation; sourced from exploit brokers or maintained in-house.

3.2 Downstream Outputs

Operator activity drives demand and revenue into the following downstream nodes:

Downstream NodeEDP NodeRelationship
Leak-Site Hosting StackNode 06Operators depend on BPH-hosted Tor leak sites for double-extortion pressure; leak site operational capability is a core operator asset.
OTC Crypto BrokersNode 01Operator and affiliate ransom proceeds exit through OTC brokers; this is the primary cash-out mechanism for large ransom payments.
High-Risk/Non-Compliant ExchangesNode 02Secondary cash-out channel; high-risk exchanges process operator and affiliate funds without KYC/AML compliance.
Mixing/Obfuscation ServicesNode 08Operators route victim payments through mixers and cross-chain bridges before splitting affiliate shares to obscure fund flows.
Mule/Money Laundering NetworksNode 09Final conversion of crypto proceeds to fiat; used by both operators and affiliates for physical cash or asset acquisition.

3.3 Critical Chokepoints

ChokepointWhy CriticalDisruption OwnerBackfire Risk
Decryption key management serversOperators retain exclusive control of keys; seizure renders all deployed ransomware non-monetizable and undermines affiliate confidence in the platform.FVEY LE + IC (covert server access)LOW (infrastructure action)
Payment portal and negotiation infrastructureVictim payments and negotiations flow through operator-controlled Tor portals; disruption prevents revenue collection and pressures victim toward non-payment.FVEY LE + ICLOW
Affiliate dashboard and builder panelAffiliates access tooling and submit victim data through operator-controlled panels; disruption severs operator-affiliate coordination.FVEY LELOW
Leak-site hosting (Node 06)Double-extortion model depends on functional leak sites for victim pressure; takedown degrades extortion leverage.FVEY LE + upstream hosting providersLOW
Crypto payment wallet addressesOperator-controlled wallets receive victim payments; blockchain tracing and designation by OFAC degrades payment processing.Treasury/OFAC + Chainalysis/TRMLOW
Underground forum recruitment channels (Node 07)Affiliate recruitment and operator reputation management; disruption degrades affiliate supply and brand trust.FVEY LE + private sector monitoringLOW

3.4 Technical Infrastructure

3.5 Cross-Module Linkages

EDP ModuleLinkage TypeDescription
Module 01 — StealersInputStealer logs provide credential material that affiliates use for initial access, supplementing or replacing IAB purchases.
Module 02 — LoadersInputLoaders (Qbot, IcedID, Pikabot) serve as the primary delivery mechanism for ransomware payloads deployed by affiliates.
Module 03 — Crypters/PackersInputCrypter services protect ransomware payloads from EDR detection; critical for affiliate operational success rates.
Module 04 — Callers/SpammersIndirect InputCaller/vishing operations (e.g., Scattered Spider) are used by privileged affiliates to manipulate IT helpdesks for credential reset access.
Module 05 — IABsCritical InputIAB markets are the primary source of pre-compromised network access for the majority of RaaS affiliates.
Module 06 — Exploit/Vuln BrokersInput (big-game)Big-game crews source 0-day/N-day exploits for mass exploitation campaigns; Cl0p is the primary exemplar.
Module 08 — Leak Site OperationsOutputOperator-controlled leak sites (hosting, content, posting cadence) are the primary extortion amplifier.
Module 09 — BPHCritical InfrastructureBPH providers host all operator-facing infrastructure; operator capability is ceiling-bounded by BPH resilience.
Module 10 — Underground ForumsMarketForums facilitate affiliate recruitment, reputation management, tooling acquisition, and ecosystem coordination.
Module 11 — Crypto MixersCash-OutMixing services obfuscate payment flows between victim payment and affiliate/operator cash-out.
Module 12 — OTC BrokersCash-OutPrimary mechanism for converting large ransom payments to fiat without triggering exchange compliance systems.
Module 13 — ExchangesCash-OutSecondary mechanism for smaller or more fragmented payment flows.
Module 14 — Mule NetworksCash-OutFinal cash conversion layer; used particularly for mid-tier ransom payments.
Module 15 — Negotiation ServicesAdjacentSome operators use or compete with third-party negotiation services; understanding negotiation dynamics informs payment rail disruption.

SECTION 4 — DISRUPTION LEVERAGE POINTS

4.1 Primary Disruption Levers

RaaS operators are the highest-value disruption target in the ecosystem due to their aggregation function. However, direct operator-level disruption (arrest, indictment, infrastructure seizure) is resource-intensive, and groups reconstitute quickly. The following levers are assessed in order of leverage-to-cost ratio:

LeverMechanismPrimary OwnerBest MethodExpected EffectBackfire Risk
Crypto payment rail disruptionTrace and designate operator-controlled wallet addresses; blockchain analysis to map affiliate payout flows; OFAC designation of RaaS payment infrastructureTreasury/OFAC + Chainalysis/TRM/EllipticDesignation + victim notification to discourage payment; blockchain forensics to pursue through mixer/exchangeIncreased non-payment rate; degraded affiliate revenue; reduced ecosystem profitabilityLOW
Decryption key server seizureCovert or overt access to operator C2/key management infrastructure; publication or provision of decryption keys to victimsFVEY LE + IC (NCA, FBI, Europol)Joint LE operation (Operation Cronos model); decryptor tool publicationNeutralizes deployed ransomware; undermines operator credibility with affiliates; forces rebrandingLOW
Leak-site takedown (Node 06)Seize or disable Tor-based leak site hosting; notify victims directly; disrupt extortion pressure mechanismFVEY LE + upstream BPH providers (Node 03)Joint LE seizure + domain/server disruption; victim rapid notificationReduces extortion leverage; lowers payment rate; damages operator brandLOW
Affiliate trust disruptionPublicize operator malfeasance (exit scams, withheld payments); introduce uncertainty about platform reliability; law-enforcement engagement with known affiliatesFVEY LE + IC + private sectorPublic reporting; seizing affiliate dispute evidence and publicizing; co-opting disgruntled affiliates as sourcesDegrades affiliate recruitment; increases defection from platforms; fragments ecosystemLOW-MEDIUM
Operator individual attribution and indictmentIdentify, indict, and publicize operator identities; disrupt operator ability to operate openly; impose reputational and psychological costsFVEY LE (FBI, NCA, Europol)Grand jury indictment + INTERPOL Red Notice + public unsealingForces operational security increases; may cause operator to cease operations; sets deterrence precedentMEDIUM-HIGH (Dark Covenant 3.0 screening required)
BPH infrastructure disruption (Node 03)Degrade BPH providers hosting operator infrastructure; force migration of leak sites, payment portals, and affiliate panelsFVEY IC + LE + upstream ISPs and registrarsUpstream provider engagement; server seizure; network blockingForces infrastructure migration; degrades uptime; imposes operational costsLOW-MEDIUM

4.2 Compounding Disruption Actions

The following actions compound the primary levers when executed concurrently or in rapid sequence:

SECTION 5 — RESILIENCE AND REPLACE DIFFICULTY

5.1 Replace Difficulty Assessment

LevelAssessmentRationale
Individual operator (developer/admin)MEDIUMCore developers are rare and hard to replace; arrest or indictment of a lead developer degrades platform quality. However, code can be forked, and the ransomware toolkit market allows new operators to build on leaked or purchased source code.
Specific RaaS brand (LockBit, ALPHV)LOW-MEDIUMPost-disruption history shows rapid brand reconstitution or affiliate migration to successor brands within weeks. The brand itself is easily replaced; the affiliates and the code are the durable assets.
Affiliate pool (collective)LOWAffiliates migrate freely between programs; 55 new groups in 2024 absorbed displaced affiliates with minimal disruption to total ecosystem deployment capacity.
Operator capability (function, not brand)MEDIUM-HIGHThe functional capacity to develop, maintain, and operate a competitive RaaS platform requires significant technical expertise; not easily replaced at the top tier. Entry-level kit operators face lower barriers.
Full ecosystem disruption (cross-node)HIGHDisrupting the RaaS layer in isolation without simultaneous pressure on BPH (Node 03), IAB markets (Node 04), and payment rails (Nodes 01, 02, 08) produces cosmetic disruption only; the ecosystem reconstitutes quickly.

5.2 Redundancy and Structural Resilience

5.3 Historical Reconstitution Table

GroupDisruption EventDateReconstitution / Outcome
REvil/SodinokibiServer seizures; FSB arrests following Colonial Pipeline pressureJan 2022FSB arrests dampened operations temporarily; core infrastructure was offline. Partial reconstitution attempts failed. Affiliates migrated to BlackCat, LockBit.
ContiInternal chat leak; reputational collapse; Ukrainian researcher breach2022Conti formally disbanded but core team reconstituted as multiple successor groups (Black Basta, Royal, Silent Ransom, Karakurt, Quantum). Functional replacement within 3-4 months.
HiveFBI covert infiltration; decryptor keys obtained and distributed; infrastructure seizureJan 2023Core Hive operations ceased. No direct reconstitution identified; affiliates dispersed to other programs. Estimated USD $130M in victim payments avoided due to FBI key distribution.
ALPHV/BlackCatFBI infiltration; decryptor publication; DOJ seizureDec 2023Operators conducted apparent exit scam (withheld $22M affiliate payment); infrastructure shut down. RansomHub emerged as primary affiliate absorber within weeks.
LockBit 3.0Operation Cronos: NCA-led multi-country infrastructure seizure; admin deanonymization; decryptors publishedFeb 2024Core infrastructure seized; LockBit admin (LockBitSupp) publicly identified. Operator attempted relaunch as LockBit 4.0 with limited success. Affiliates migrated to RansomHub and BlackSuit. LockBit brand activity significantly reduced but not eliminated.

5.4 Ecosystem Adaptation Patterns

The ransomware ecosystem has demonstrated consistent adaptation patterns in response to law-enforcement pressure:

5.5 Durability Assessment

FactorRatingNotes
Technical barrier to entry (toolkit availability)LOWLeaked source code, commodity builders, and kit markets have reduced technical barriers substantially.
Financial incentive durabilityHIGHEven at $813M in 2024 (down 35%), ransomware remains among the highest-return criminal enterprises per operator.
State protection durabilityHIGHRussia/CIS state tolerance is structurally stable absent major geopolitical shifts; operator community manages risk through CIS filters.
Law-enforcement attrition rateLOW-MEDIUMMajor operations (Cronos, Hive) achieve meaningful disruption at the brand level but ecosystem-level attrition remains low; new groups form faster than LE can disrupt them.
Victim payment behavior trendIMPROVING (for disruption)Non-payment rate is increasing; H2 2024 shows 53% gap between demanded and paid amounts. Declining payment rate degrades ecosystem profitability.
Overall ecosystem durabilityHIGHThe RaaS ecosystem is structurally durable at the function level; individual brands are fragile, but the function reconstitutes rapidly and reliably.

SECTION 6 — INDICATORS AND KPIs

6.1 Health Indicators — Normal vs. Under Pressure

IndicatorNormal / Stable StateUnder Pressure
Active group count60-124 active groups trackedRapid drop in named active groups; fewer new postings across platforms
New victim postings per month600-800+ victims across all groupsSustained drop to <300/month would indicate significant ecosystem disruption
Total on-chain paymentsUSD $800M-$1.25B annuallyDrop below $500M annually with stable victim count would indicate degraded payment collection
Payment-to-demand ratio40-60% of demanded amount paidSustained drop below 30% indicates victim community increasingly refusing to pay
Affiliate recruitment activity on forumsRegular "partner program" postings on XSS, RAMP, and Telegram channelsAbsence of recruitment postings; operators going dark; affiliate disputes increasing
Time to reconstitution post-disruption30-90 days for brand reconstitution or affiliate migrationExtended silence (>180 days) from major brand without successor emergence
Monero vs. Bitcoin payment ratioIncreasing Monero shareContinued Monero migration indicates sustained blockchain-tracing pressure
Healthcare and critical sector targeting rate700+ breaches annually; ~48% US victim shareSignificant decline would indicate effective victim hardening or targeting filter expansion

6.2 Disruption KPIs

KPIBaseline (2024-25)Disruption Target (18-month)Collection Method
Active double-extortion group count124 groups<75 active groupsLeak site monitoring (Secureworks, Corvus, Mandiant)
Monthly leak-site victim postings~650 avg/month (7,800 annualized)<400/month sustainedLeak site aggregator monitoring
Annual on-chain ransom payments~$813M (2024)<$500MChainalysis / TRM annual report
Payment-to-demand ratio~47% of demanded amount paid<30%Coveware quarterly victim survey
Days from disruption to active successor brand30-90 days average (post-Cronos, post-ALPHV)>180 days average across major disruptionsForum and leak-site intelligence
New group formation rate55 new groups in 2024 (+67% YoY)Year-on-year decline in new group formationThreat intelligence provider tracking
OFAC-designated RaaS wallet addressesGrowing designation listDesignation of top-5 active operator wallet clusters within 12 monthsTreasury OFAC public designation list
Decryptor tools publicly releasedInfrequent (Hive 2023, LockBit 2024)Decryptor release within 30 days of each major operator takedownCISA / law-enforcement press releases

6.3 Collection Methods

6.4 Baseline Data

MetricBaseline ValuePeriodSource
Active groups1242025-26Vectra AI
New groups per year55 (+67% YoY)2024Corvus/Travelers
Victims on leak sites (annual)7,458-7,960 (+53% YoY)2025Vectra AI
Victims on leak sites (quarterly peak)1,663 (Q4 2024)Q4 2024Corvus/Travelers
Annual on-chain payments~$813M2024Chainalysis
Prior year payments~$1.25B2023Chainalysis
Typical payment band$150k-$250kH2 2024Chainalysis
Payment-to-demand gap~53%H2 2024Chainalysis
US share of victims~48%2024-25Vectra AI
Healthcare breaches700+2024-25Vectra AI
Patient records exposed>275M2024-25Vectra AI
Affiliate revenue share60-80%Market standardMultiple sources
Operator platform fee20-40%Market standardMultiple sources
Subscription kit price range$40-$100/monthCurrentVectra AI, NMFTA
One-time license price range$500-~$84,000CurrentWikipedia, NMFTA

6.5 Alert Thresholds

Threshold EventTrigger LevelRecommended Action
New high-volume group emergence>100 victims posted within first 60 days of group appearanceImmediate profiling; forum and infrastructure attribution; OFAC wallet cluster identification
Healthcare victim surge>50 healthcare victims in any 30-day period across all groupsSector-specific rapid notification; coordinate with HHS; escalate to CISA
Total payment reversal (increase)Annual on-chain payments exceed $1B againIndicates ecosystem recovery; escalate cross-node disruption pressure (Nodes 01, 02, 08)
Rapid new group formation spike>10 new groups in any 60-day windowIndicates major operator disruption with inadequate affiliate containment; surge forum monitoring
US victim share increaseUS share exceeds 55% of global victimsIndicates targeting shift or filter modifications; escalate IC collection on CIS filter status
Monero payment share increase>50% of victim payments routed through MoneroIndicates degraded blockchain tracing capability; escalate Monero de-anonymization technical efforts

SECTION 7 — SOURCES AND CONFIDENCE

7.1 Primary Sources

Threat Intelligence and Ecosystem Reporting:

Financial Intelligence:

Ecosystem Structure and Technical Analysis:

7.2 Secondary Sources

7.3 Gaps and Uncertainties

7.4 Confidence Notes

Claim / FindingConfidenceBasis
Total 2024 on-chain ransomware payments (~$813M)CONFIRMEDChainalysis 2025 Crypto Crime Report; multiple secondary citations
55 new ransomware groups in 2024 (+67% YoY)CONFIRMEDCorvus/Travelers Q4 2024 report; corroborated by Secureworks
7,458-7,960 leak-site victims in 2025 (+53% YoY)CONFIRMEDVectra AI 2025 reporting; consistent with quarterly trend data
Affiliate revenue split 60-80%; operator take 20-40%CONFIRMEDMultiple sources (IBM, Wikipedia, NMFTA, Coveware); market-standard range
CIS/RU targeting exclusion filters as standard practiceCONFIRMEDMultiple documented instances across LockBit, ALPHV, RansomHub, others
FSB protection/tolerance model for major operatorsCREDIBLEStrong structural inference; REvil selective enforcement 2022 is confirming data point
Black Basta state-adjacency indicators in leaked chatsCREDIBLESingle-source (leaked chat analysis); not independently corroborated
RansomHub operator as Russia-basedANALYST INFERENCECIS filter presence; RU-language operational security; no public indictment
Active GRU/SVR tasking of commercial RaaS groupsNOT SUPPORTED IN OPEN REPORTINGNo open-source evidence; absence of evidence is not evidence of absence

SECTION 8 — ANALYST ASSESSMENT

8.1 Key Takeaway

Ransomware Groups and RaaS Variants are the central aggregation function of the EDP ecosystem — not a discrete node but the mechanism by which every upstream supply chain component is monetized and every downstream cash-out channel is activated. Disrupting individual RaaS brands produces measurable short-term effects but structurally inadequate long-term impact. The 2024 ecosystem delivered 7,460-7,960 publicly named victims and approximately $813M in confirmed payments despite the two most significant law-enforcement operations in the history of the sector (Operation Cronos against LockBit; FBI against ALPHV). This outcome confirms that brand-level disruption without simultaneous pressure on the ecosystem nodes that sustain it — BPH (Node 03), IAB markets (Node 04), underground forums (Node 07), mixing services (Node 08), and OTC cash-out (Node 01) — produces affiliate diaspora, new brand formation, and ecosystem continuation at near-baseline levels.

Two countervailing trends create a narrow leverage window: total payments are declining (-35% from 2023 to 2024) while victim counts are rising (+53% YoY in 2025). This divergence indicates that the victim community is increasingly refusing to pay, which is the single most potent structural threat to operator profitability. Policies, technologies, and practices that increase non-payment rates are the highest-return disruption investment available, because they attack operator revenue without triggering ecosystem reconstitution.

8.2 Priority Recommendations

Recommendation 1 — Prioritize Payment Rail Disruption Over Brand Disruption

The declining payment-to-demand ratio (53% gap in H2 2024) reflects market forces that are more durable than law-enforcement takedowns. OFAC designation of active operator wallet clusters, combined with victim rapid-notification programs and public decryptor availability, sustains and accelerates this trend. Each designation of a payment address cluster creates compliance obligations for every exchange, OTC broker, and mixer downstream. This is Phase A and Phase B EDP playbook work (Nodes 01, 02, 08) executed in direct support of Phase C operator disruption.

Recommendation 2 — Healthcare Sector Requires Dedicated Rapid-Response Architecture

With 700+ double-extortion breaches and over 275 million patient records exposed in 2024-25, healthcare is the highest-impact vertical and a potential policy forcing function. A dedicated healthcare ransomware rapid-response capacity — combining CISA/HHS victim notification, FBI decryptor deployment, and pre-positioned technical assistance — would reduce payment rates in the highest-profile sector and generate deterrence signals to affiliates who disproportionately target it.

Recommendation 3 — Affiliate Diaspora Containment as Post-Takedown Priority

Post-Cronos and post-ALPHV experience demonstrates that affiliate migration to successor brands (primarily RansomHub) occurs within weeks. A systematic post-takedown affiliate monitoring and early-pressure protocol — targeting successor brand infrastructure before it consolidates affiliate trust — would compress the reconstitution window. This requires pre-positioned forum intelligence (Node 07) and rapid wallet cluster identification for emerging brands.

Recommendation 4 — Dark Covenant 3.0 Screening Before Individual Attribution

Any individual attribution action against Russia-based RaaS operators requires prior FSB/MVD protection-relationship screening. Attribution of a protected individual without this screening risks diplomatic friction disproportionate to enforcement value. Infrastructure and financial designation actions (Nodes 01, 02, 03, 06, 08) carry LOW backfire risk and should proceed without this constraint.

8.3 Connection to EDP Disruption Playbook

Module 07 is cross-cutting and activates all three disruption phases. The sequencing logic is:

Module 07 therefore serves as the prioritization rationale for all three phases: because operators aggregate all upstream supply chain functions and direct all downstream cash-out flows, sustained disruption of the operator layer requires concurrent pressure on all phase nodes. A single-phase approach produces temporary brand disruption; a multi-phase approach degrades the economic viability of the function.

8.4 EDP Dependency Map Update Recommendations

RecommendationProposed ChangeTierReplace DifficultyPrimary OwnerBackfireRationale
Add Node 16 — RaaS Operator / Core Group InfrastructureNew dedicated node for the RaaS operator function (developer/operator layer, not the broader affiliate ecosystem)CRITICALHIGHFVEY LE (FBI, NCA, Europol) + IC; OFAC for financial targetingLOW (infrastructure/financial); MEDIUM-HIGH (individual attribution — Dark Covenant screening required)The current map has no node representing the operator function itself. This gap means the map does not capture the primary aggregation and monetization node of the entire ecosystem. All 15 current nodes either feed into or are sustained by the operator layer. Adding Node 16 corrects this structural omission.
Add Node 17 — Affiliate Ecosystem and Recruitment MarketsNew supplemental node for the affiliate layer distinct from individual upstream nodesHIGHLOWFVEY LE + private sector forum monitoringLOWAffiliates are a distinct actor class from operators. Their recruitment, vetting, and lifecycle management constitute a separable function with distinct disruption levers (affiliate trust attacks, forum recruitment disruption). A dedicated node would allow the playbook to address affiliate containment as a post-takedown protocol distinct from operator infrastructure targeting.

Note: The Dependency Map currently contains 15 nodes. These recommendations would expand it to 17. Both new nodes represent functions that are structurally central to the ransomware supply chain but are presently subsumed under the cross-cutting designation applied to Module 07. Analyst assessment confidence for these recommendations: ANALYST INFERENCE — based on cross-module analysis of all 7 completed modules and the EDP dependency mapping framework.

8.5 Follow-On Research Priorities

Research QuestionPriorityRationaleSuggested Source/Method
RansomHub operator attribution: Is RansomHub Russia-based, and what is its FSB protection status? (Question retains value for successor and affiliate tracking despite the April 2025 collapse.)HIGHRansomHub absorbed the largest share of the post-ALPHV/LockBit affiliate diaspora and was the dominant active brand until it went dark in April 2025; Qilin then absorbed the largest share of its displaced affiliates. Attribution is required before individual action can be contemplated.IC collection; blockchain forensics on RansomHub payment wallets; forum persona analysis (Recorded Future, Intel 471)
Affiliate pool composition post-LockBit/ALPHV: How many active affiliates migrated, and to which programs?HIGHAffiliate containment following future takedowns requires knowing the current affiliate pool distribution.Flashpoint/Intel 471 underground monitoring; Coveware victim-side TTP analysis
Healthcare targeting driver: Are specific affiliate archetypes disproportionately targeting healthcare, or is it a platform-level pattern?HIGHIf healthcare over-targeting is driven by specific affiliates rather than operator choice, disruption strategy differs.Coveware TTP data; CISA sector analysis; FBI sector-reporting data
Monero adoption rate trajectory: At what point does Monero dominance materially degrade blockchain-tracing effectiveness?MEDIUMCurrent Chainalysis figures rely on Bitcoin payment visibility; if Monero crosses a threshold share, reported payment totals become systematically understated.Chainalysis/TRM Monero tracing capability briefings; on-chain analysis
Post-fragmentation stabilization: Will the 124-group ecosystem consolidate or continue fragmenting?MEDIUMStabilization into 5-10 dominant brands would change disruption priority; continued fragmentation would favor cross-ecosystem pressure over brand-specific targeting.Corvus/Secureworks quarterly tracking; forum monitoring for consolidation signals
Dark Covenant 3.0 screening for Qilin, Play, and INC Ransom (RansomHub defunct April 2025; BlackSuit disrupted July 2025)HIGHFour of the most active current groups have not been publicly screened for FSB protection relationships; screening is required before individual attribution actions.IC collection; Recorded Future Insikt Group analysis

8.6 Module 07 Assessment Summary

The ransomware group and RaaS operator layer is simultaneously the highest-value disruption target in the EDP ecosystem and the most structurally resilient. Its resilience does not derive from technical sophistication alone but from the structural properties of the RaaS model: separation of development from deployment; a large and mobile affiliate pool; abundant replacement tooling from leaked source code; and sustained state tolerance from the Russian government. Direct brand disruption has produced measurable but temporary effects. The leverage that will produce durable ecosystem degradation lies not in defeating individual brands but in making the operator function economically unviable — through sustained payment rail pressure, victim non-payment normalization, and simultaneous disruption of the upstream supply nodes without which affiliates cannot function effectively.