Ransomware groups are increasingly operating like structured criminal businesses, outsourcing key functions to specialists and launching formal affiliate programs across underground forums. Researchers and reporting describe growing demand for initial access brokers and dedicated negotiators who handle ransom talks, pressure tactics, and extortion messaging, while forums such as RAMP emerged to support ransomware recruitment after other Russian-speaking sites restricted such advertising. New and revived operations have continued to market themselves aggressively, including Eclipse Ransomware with a managed affiliate model, Tor-based negotiation portals, leak-site support, and revenue-sharing terms, as well as earlier examples such as REvil-linked infrastructure reappearing to recruit affiliates and Maze partnering with other gangs through shared leak platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
40 events from the most recent confirmed update back to the earliest known activity.
GLOBAL, also called GLOBAL GROUP, emerged in June 2025 as a ransomware-as-a-service operation. Researchers later linked it to Mamona and BlackLock through operational security mistakes and shared artifacts.
On February 11, 2025, the Telegram user @ExploitWhispers leaked internal Black Basta ransomware chat logs. The leak exposed the group's internal operations, infrastructure, member roles, and attack methodologies.
The analyzed CashRansom.exe sample carried a timestamp of 2024-05-12 03:48:15, indicating the malware was still under active development at that time. Researchers later assessed it as a pre-release RaaS sample with weak obfuscation and flawed cryptography.
B. Riley Financial disclosed in an April 8 SEC filing that an unauthorized threat actor accessed certain Targus file systems on April 5, 2024. Targus shut down systems to contain the incident and engaged external experts for recovery.
On March 29, 2024, Red Ransomware launched its dark web data leak site titled 'Wall of Shame.' The site was used to publish victim data and extortion notices.
The profile states that Red Ransomware released the data of 11 victims simultaneously on March 5, 2024. The mass disclosure was one of the group's first major public extortion actions.
Red Ransomware surfaced publicly in March 2024 as a newly discovered ransomware group. The operation was also referred to as Red CryptoApp.
A ransom note dated February 18, 2024 was cited as evidence that Red Ransomware was already targeting victims by mid-February. This supports the assessment that the group began operating between February and March 2024.
EclecticIQ identified a previously undocumented PHP-based brute-forcing framework named BRUTED that Black Basta members had used since 2023. The tool automated internet scanning and credential-stuffing against edge devices and remote-access platforms to obtain initial access.
MalwareHunterTeam observed a new leak site between April 5 and April 10, 2022, when it contained no content. A few days later, the site was populated with mostly historical REvil victims and a small number of apparent new victims.
In mid-January 2022, Russia announced that it had shut down REvil and arrested 14 individuals after identifying all members of the operation. Russian official Oleg Khramov said the investigation began after the United States shared the name 'Puzyrevsky' and an IP address.
MalwareHunterTeam reported in January 2022 that a ransomware gang named Ransom Cartel had launched in December 2021 and was related to REvil's encryptor. The report suggested continued reuse of REvil tooling after the group's disruption.
In November 2021, while under FBI control, REvil's data leak and payment sites displayed a page titled 'REvil is bad' and a login form. Those pages were first visible through Tor gateways and later at the .onion addresses themselves.
KELA monitored RAMP until July 27, 2021, when access to the forum became restricted after a spam extortion incident and administrative cleanup. The disruption led the admin to restrict access and plan a relaunch on a new engine.
On July 12, 2021, KELA observed that the former Babuk leak site had been converted into the new Russian-speaking cybercrime forum RAMP. The forum was positioned as a venue welcoming ransomware operators, affiliates, and related services after restrictions elsewhere.
A new Russian-speaking forum, RAMP, launched in July 2021 to serve ransomware operators and affiliates after ransomware advertising was restricted on forums such as XSS and Exploit. Its structure included sections for affiliate programs, access brokers, and tools.
The latest Ranion version cited by Fortinet, version 1.21, was released in July 2021. Fortinet said this reflected accelerated development with frequent updates during 2021.
On July 1, 2021, Babuk announced a new leak site and said the operation would continue under the name Babuk 2.0. The group said the old ransomware version had leaked while a new version was being used in ongoing attacks.
Over a US holiday weekend in July 2021, zero-day vulnerabilities in Kaseya VSA were used to compromise endpoints and expose organizations to ransomware infection. About 1,500 businesses were affected at least by the need to shut down VSA deployments until a patch was ready.
On June 27, 2021, a Babuk ransomware builder was uploaded to VirusTotal. The leaked builder could be used to create custom ransomware variants and generate decrypters.
On June 1, 2021, the Babuk domain displayed a page titled 'Payload.bin' identifying itself as a leaks site. The site listed only one victim, CD Projekt Red.
A Babuk representative stated on May 15, 2021, that the group's ransomware-as-a-service affiliate program was closed. This signaled a change in the operation's public business model.
Babuk claimed in April 2021 that it had compromised Washington DC's Metropolitan Police Department and stolen 250 GB of unencrypted files. The claim was one of the group's most visible public victim disclosures.
Babuk publicly recruited affiliates on the Russian-speaking forums XSS and Exploit starting in March 2021. This reflected the group's active ransomware-as-a-service expansion.
In mid-October 2020, REvil figurehead UNKN was observed as the only bidder in a hacker-forum auction for the KPOT 2.0 source code, paying the $6,500 asking price. Researchers assessed REvil likely intended to further develop and operationalize the stealer in targeted intrusions.
Incident responders and security firms reported that by August to September 2020, multiple ransomware gangs were calling victims to pressure them into paying instead of restoring from backups. Researchers linked the tactic to groups including Sekhmet, Maze, Conti, and Ryuk, and said the calls appeared to use shared scripts, suggesting possible outsourced support.
In August 2019, REvil attacked multiple local administrations in Texas and demanded a collective ransom of $2.5 million. The incident helped establish the group's profile in large-scale extortion.
REvil began in April 2019 as a continuation of the GandCrab ransomware operation. It went on to become one of the most prominent ransomware groups.
KPOT was first spotted in 2018 as an information-stealing trojan capable of harvesting credentials and other sensitive data. It later became relevant to REvil after the gang acquired its source code.
Daniel Smith of Radware Security publicly described Ranion as ransomware-as-a-service in February 2017. Fortinet later cited this as evidence that the operation had been active since at least that month.
In early August 2016, Check Point researchers analyzed Cerber's decryptor and discovered a server-side integrity flaw in the decryption workflow. The weakness allowed a paid signature from one infection to be reused to recover decryption material for another infection.
At the end of July 2016, Trend Micro released a partially working decryptor for the first version of Cerber. This was one of the earliest public defensive responses to the ransomware family.
Cerber was first mentioned in March 2016 on Russian underground forums, where it was offered for rent through an affiliate program. This marked the emergence of Cerber as a ransomware-as-a-service operation.
A threat actor using the handle EclipseSupport promoted a new ransomware-as-a-service operation called Eclipse Ransomware on cybercrime forums. The platform was advertised as a multi-platform family targeting Windows, Linux, NAS, VMware ESXi, and Nutanix environments.
SentinelOne said the FONIX ransomware-as-a-service operation first drew attention in July of the referenced year. The operation was notable for its email-only affiliate model and limited observed infections.
REvil's original Tor leak and payment infrastructure came back online after months of inactivity and redirected to a newly launched ransomware operation. The new site advertised affiliate recruitment, promised an 80/20 revenue split, and appeared to include two new victims such as Oil India.
KELA researchers published a study describing how ransomware operations had evolved into specialized, corporate-like ecosystems. The study highlighted outsourced negotiators, growing demand for initial access brokers, and rising prices for privileged network access.
DarkSide said on its dark web portal that it might tip off corrupt traders so they could short a victim's stock before the victim was publicly named. Recorded Future described this as the first ransomware group to formalize stock-market manipulation as part of extortion.
Ragnar Locker became the second ransomware operation reported to cooperate with Maze by using Maze's data leak platform for extortion. The move expanded Maze's cartel-style collaboration model beyond its earlier partnership with LockBit.
After validating the flaw, Check Point created the Cerber Decryption Service to automate recovery for victims at scale. The service processed large numbers of requests until the attackers fixed the issue within 24 hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemorado.io
Open sourceblog.eclecticiq.com
Open sourcetehtris.com
Open sourcezdnet.com
Open sourcebleepingcomputer.com
Open sourcevirusbulletin.com
Open sourceke-la.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.