Ransomware Gangs Innovate With New Affiliate Models
ID: 7b1b86f4-46ed-5bc2-a89d-b1b70b78403e
STIX ID: report--7b1b86f4-46ed-5bc2-a89d-b1b70b78403e
Feed Name: Dark Reading
Date Published: 2025-04-23
Date Updated: 2026-05-05
Author: Alexander Culafi, Senior News Writer, Dark Reading
This report describes Secureworks' analysis of two ransomware-as-a-service operators — DragonForce and Anubis — who have expanded affiliate models to include an "infrastructure-only" option and data-ransom/access-monetization services, enabling affiliates to brand or monetize access and increasing the scale and sophistication of extortion operations; the research emphasizes the business-like evolution of ransomware groups and recommends proactive defensive measures such as patching, phishing-resistant MFA, robust backups, and tested incident response plans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
