DISCOVERY DATE: April 2025
KEY GROUPS: DragonForce, Anubis
OPERATION TYPE: Ransomware-as-a-Service (RaaS) Evolution
TRENDS OBSERVED: Decentralization, Affiliate Empowerment, Regulatory Extortion
TACTICAL SHIFT: From Unified Malware to Modular Cybercrime Brands
STATUS: Active Ecosystem Diversification
FROM GANG TO CARTEL — THE RISE OF MODULAR EXTORTION NETWORKS
The digital underworld isn’t just adapting — it’s franchising.
Two rising ransomware factions, DragonForce and Anubis, are spearheading a new era of cybercrime economics, experimenting with decentralized affiliate programs and innovative monetization techniques to increase market penetration, maximize anonymity, and scale profits.
Where once threat groups operated with tightly controlled teams and single encryption payloads, we’re now seeing a corporate-style decentralization — empowering lower-tier hackers to spin off their own operations using shared infrastructure, rebranded tooling, and layered extortion playbooks.
DRAGONFORCE GOES FULL CARTEL
Originally launched in August 2023 as a typical RaaS operation, DragonForce has rebranded itself into a cybercrime cartel — an umbrella infrastructure allowing affiliates to operate semi-independently while benefiting from back-end resources such as:
- Prebuilt command & control systems
- Operational support services
- Secure dark web forums
- Victim negotiation templates
- Cryptocurrency anonymization layers
The twist? Affiliates don’t have to use DragonForce’s malware. They’re free to deploy their own custom payloads, injecting new variants into the ransomware ecosystem while piggybacking on DragonForce’s hardened backend.
“Even skilled threat actors now prefer convenience,” noted Secureworks. “Why build your own infrastructure when you can rent a battle-tested one?”
But with decentralization comes risk. If one affiliate is exposed, it could unravel the infrastructure and tactics of dozens more.
ANUBIS: THE A-LA-CARTE EXTORTION SERVICE
First observed in December 2024, Anubis is marketing itself with a menu of monetization options:
- Classic Encryption: 80% profit share
- Data-Only Extortion: 60% profit share
- Access-as-a-Service (AaaS): 50% cut for initial access sales
But the real standout is their psychological warfare model. Anubis deploys multi-layered pressure campaigns:
- Threatening to expose data on social media
- Notifying customers of the victims directly
- Filing fraud and breach reports with regulatory agencies on the victim’s behalf
This regulatory weaponization is a bold escalation, reminiscent of AlphV/BlackCat’s reported attempt to file a breach notice with the U.S. Securities and Exchange Commission (SEC) — effectively weaponizing compliance laws against victims.
Anubis isn’t just stealing. They’re hijacking the systems meant to protect the public and turning them into extortion levers.
LOCKBIT DOWN, EXPERIMENTATION UP
The shift comes after the takedown of LockBit — once the market-dominant ransomware cartel — by international law enforcement in late 2024. Its removal left a vacuum and a fractured network of displaced affiliates looking for new homes.
“We’re seeing experimentation now, where previously LockBit’s success kept others in check,” said Rafe Pilling of Secureworks’ Counter Threat Unit. “This is the Wild West of ransomware again — modular, brandable, and scalable.”
THE GOVERNMENT RESPONSE: STRATEGIC CHAOS
Law enforcement agencies like the FBI and Britain’s NCA have shifted from reactive investigation to disruption warfare, aiming to destabilize ransomware crews before they can become monoliths again. These “strategic chaos” operations aim to:
- Fracture leadership structures
- Disrupt dark web trust networks
- Erode affiliate loyalty
- Prevent brand consolidation (as seen with LockBit, Conti, and REvil)
Former ODNI cyber director Laura Galante confirmed that the playbook now focuses on creating persistent disruption cycles, making it harder for any one group to mature.
“If you keep them scattered, you keep them weak,” Galante noted. “It’s about slowing the growth curve, not stopping the ecosystem — yet.”
THE NUMBERS STILL STAGGERING
While ransomware payment volumes have dropped — according to Chainalysis, 2024 saw a measurable decline in cryptocurrency ransom flows — the threat remains volatile. Extortion groups are retooling, innovating, and recruiting faster than most companies are patching.
“It’s fragile progress,” said Chainalysis’ Jackie Burns Koven. “One exploit, one new cartel, and we’re back to square one.”
In short: fewer profits doesn’t mean fewer attackers. It means smarter ones.
THE TRJ TAKE: RANSOMWARE ISN’T DYING. IT’S JUST MUTATING.
What we’re witnessing isn’t the fall of ransomware — it’s the franchising of cybercrime.
In the same way Amazon redefined logistics and Uber redefined transport, ransomware groups are now redefining crime-as-a-service. They’re modularizing everything — payloads, infrastructure, monetization, pressure tactics, even regulatory manipulation.
What’s next? Ransomware DAOs? Fully AI-run extortion chains? We’re closer than most realize.
And if corporations, governments, and critical infrastructure continue to treat this as a “hacker problem” instead of a criminal economy problem, we’re going to lose the digital battlefield.

🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed.
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified
Help us bring real change! Corporate lobbying has corrupted our system for too long, and it’s time to take action. Please sign and share this petition—your support is crucial in restoring accountability to our government. Every signature counts! Thank you!
https://www.ipetitions.com/petition/restore-our-republic-end-lobbying

Support truth, health, and preparedness by shopping the Alex Jones Store through our link. Every purchase helps sustain independent voices and earns us a 10% share to fuel our mission. Shop now and make a difference!
https://thealexjonesstore.com?sca_ref=7730615.EU54Mw6oyLATer7a


