logo

After LockBit, ALPHV Takedowns, RaaS Startups Go on a Recruiting Drive

ID: 5b0defc3-dbb5-5eba-88c2-7e3552d3cb42

STIX ID: report--5b0defc3-dbb5-5eba-88c2-7e3552d3cb42

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-03-20

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

This report analyzes how recent takedowns and disruptions of high-profile RaaS groups (LockBit, ALPHV/BlackCat) have damaged their credibility with affiliates, leading to a shift toward smaller ransomware-as-a-service startups that advertise better profit splits, trust mechanisms (affiliates controlling wallets), and services. It cites specific incidents—an alleged ALPHV exit scam involving a $22M affiliate payout and law enforcement messaging that undermined LockBit's reputation—and profiles emerging groups (Cloak, Medusa, RansomHub) recruiting disaffected affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.