{"id":1787,"date":"2025-04-25T20:46:11","date_gmt":"2025-04-25T20:46:11","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=1787"},"modified":"2025-04-25T20:46:12","modified_gmt":"2025-04-25T20:46:12","slug":"dragonforce-and-anubis-ransomware-gangs-launch-new-affiliate-packages","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=1787","title":{"rendered":"DragonForce and Anubis Ransomware Gangs Launch New Affiliate Packages"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Secureworks Counter Risk Unit (CTU) researchers have uncovered revolutionary methods deployed by the DragonForce and Anubis ransomware operators in 2025.<\/p>\n<p>These teams are adapting to regulation enforcement pressures with novel affiliate fashions designed to maximise income and develop their attain, showcasing the resilience and ingenuity of recent cybercriminals in underground boards.<\/p>\n<h2 class=\"wp-block-heading\"><strong>DragonForce Pioneers a Distributed Affiliate Branding Mannequin<\/strong><\/h2>\n<p>DragonForce, first recognized in August 2023 as a traditional ransomware-as-a-service (RaaS) operation, has undergone a big transformation by March 2025. <\/p>\n<div class=\"td-a-ad id_inline_ad0 id_ad_content-horiz-center\"><span class=\"td-adspot-title\">&#8211; Commercial &#8211;<\/span><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><br \/>\n<img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgtF4v5Ejzb9hD6O8UG7KJJziqO1ZP5zcUuKXNsyjb4g3FugqSKlBjBKmUNqGCjtqOq8kEb1lM6uZOBXm0lUCSTqXKyP4hz81q77L_k5I4RBy3afKYWuunQXOVo9zA4MFlD75XmYOjxT0sNIO9RR8UZPin1ZBVShx5Xj-5D9SyEp0QgEPoA6vxXp3Q4DInb\/s16000\/Don%E2%80%99t%20miss%20our%20latest%20stories%20on%20Google%20News%20(1).png&#10;\" alt=\"Google News\"\/><\/a><\/div>\n<p>Initially gaining traction after promoting on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/hackers-selling-telegram-insider-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">darkish internet boards<\/a> in February 2024, the group amassed a sufferer depend of 136 on its leak web site as of March 24, 2025. <\/p>\n<p>In a daring transfer introduced on March 19 by way of an underground submit, DragonForce rebranded itself as a \u201ccartel\u201d and shifted to a distributed mannequin. <\/p>\n<p>This new strategy permits associates to ascertain their very own distinctive \u201cmanufacturers\u201d whereas leveraging DragonForce\u2019s sturdy infrastructure, together with administration panels, encryption instruments, ransom negotiation methods, Tor-based leak websites, and assist providers. <\/p>\n<p>In contrast to conventional RaaS schemes, associates should not mandated to make use of DragonForce\u2019s ransomware, providing unprecedented flexibility. <\/p>\n<p>This mannequin lowers the technical limitations for less-skilled menace actors whereas interesting to stylish operators preferring to deploy customized malware with out constructing their very own backend. <\/p>\n<p>Nevertheless, this shared infrastructure introduces a possible vulnerability if one affiliate is compromised, it might expose operational particulars of others, posing dangers to your complete community. <\/p>\n<p>This strategic pivot is poised to broaden <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/dragonforce-attacks-critical-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">DragonForce\u2019s <\/a>affiliate base, probably amplifying its monetary features whereas difficult defenders with a extra numerous menace panorama.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Anubis Introduces Multi-Mode Extortion Ways<\/strong><\/h2>\n<p>Concurrently, the Anubis ransomware group, marketed since late February 2025 on underground platforms, has rolled out a particular extortion framework with three affiliate choices tailor-made to various ability ranges and operational focuses. <\/p>\n<p>Based on Secureworks <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.secureworks.com\/blog\/ransomware-groups-evolve-affiliate-models\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report<\/a>, the primary is a conventional RaaS mannequin with file encryption, providing associates an 80% ransom share.<\/p>\n<p>The second, a \u201cinformation ransom\u201d mode, focuses solely on information theft, offering a 60% reduce by publishing detailed \u201cinvestigative articles\u201d on compromised information to a password-protected Tor web site, pressuring victims by public leak threats and notifications to prospects by way of an X (previously Twitter) account. <\/p>\n<p>Uniquely, Anubis escalates by threatening to report breaches to regulatory our bodies just like the UK\u2019s ICO, the US HHS, and the European EDPB an aggressive tactic echoing previous actions by teams like GOLD BLAZER in 2023 with the SEC. <\/p>\n<p>The third possibility, \u201caccesses monetization,\u201d assists associates in extorting already compromised victims with detailed information analyses for negotiation leverage, providing a 50% ransom share. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjxLKcPhFeS5IQT2ncAS4flWo4BFp0tA8wsBpxn5Nup-zb42kxrbrUI3MWUj3UymD6kxl0zga_5M0FZ5D8Z1sDC3nyquZL-7xptd83oof7AM-czwBYw3g_8yZFVTwZ0A2h1I3qrDPYhcMw6u_kIW15QGN7MpNd_PROL-YBjrdrNvngwOsUkFc_1CUC97QA\/s16000\/Advertisement%20for%20Anubis%20accesses%20monetization%20service.webp\" alt=\"Anubis Ransomware\"\/><figcaption class=\"wp-element-caption\"><em>Commercial for Anubis \u201caccesses monetization\u201d service.<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Notably, Anubis excludes targets in post-Soviet states, BRICS nations, and sectors like training and authorities, however leaves healthcare organizations uncovered, possible resulting from their delicate information and compliance pressures. <\/p>\n<p>This multi-tiered mannequin diversifies Anubis\u2019s attraction, drawing in a spectrum of cybercriminals whereas intensifying sufferer coercion by regulatory threats.<\/p>\n<p>These developments underscore the relentless adaptability of ransomware operators, as DragonForce and Anubis refine their enterprise fashions to evade disruption and maximize affect. <\/p>\n<p>Cybersecurity professionals should anticipate these evolving ways by enhancing detection, incident response, and worldwide cooperation to counter the rising sophistication of such threats.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><strong>Discover this Information Fascinating! Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, &amp;\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Instantaneous Updates!<\/strong><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Secureworks Counter Risk Unit (CTU) researchers have uncovered revolutionary methods deployed by the DragonForce and Anubis ransomware operators in 2025. These teams are adapting to regulation enforcement pressures with novel affiliate fashions designed to maximise income and develop their attain, showcasing the resilience and ingenuity of recent cybercriminals in underground boards. DragonForce Pioneers a Distributed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1789,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1757,1754,1753,1755,1756,1758,500],"class_list":["post-1787","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-affiliate","tag-anubis","tag-dragonforce","tag-gangs","tag-launch","tag-programs","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1787"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1787\/revisions"}],"predecessor-version":[{"id":1788,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1787\/revisions\/1788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/1789"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 11:33:25 UTC -->