HomeAtlasDashboardChartsReal valueResearchPersonsCatalogsBlockchainBubble MapGlobeQuantumAILeadershipLensesMethodologyGlossarySource ↗
Independent research & opinion. Gradings are automated / LLM-assisted and may contain errors or hallucinations; nothing here is a statement of fact, financial advice, or an accusation of wrongdoing by any party. Claims about identifiable people or organizations reflect public records + good-faith interpretation; intent is not inferred from association. Methodology & disclaimer.

Ransomware & eCrime catalog: the crews, their signature attacks, and the crypto rails

Batch 2 of the threat-actor catalog - financially-motivated criminal groups (mostly Russia-based / Russia-tolerated) running Ransomware-as-a-Service and big-game hunting. Distinct from state APTs (espionage) and commercial spyware.

The crews and their marquee attacks

The rails and the counter-force

Ransomware runs on crypto rails - paid in Bitcoin (increasingly mixers/Monero), then laundered. Chainalysis/TRM trace the flows, enabling seizures (Colonial clawback) and the annual payment tallies; OFAC designations (Evil Corp) make paying certain crews a sanctions violation, reshaping the ransom/insurance calculus.

Honest limits

RaaS is a franchise: the operator (brand) and the affiliate (who actually breaks in) are separable, so attributing an intrusion to a brand really means attributing it to whoever used the kit. Brands rebrand and exit-scam (Conti->Black Basta/Royal; DarkSide->BlackMatter; ALPHV faked its own death), blurring continuity. "Russia-based" is well-established but often an inference from geography + non-prosecution. Amounts are as-disclosed/reported.

Sources: DOJ (Colonial clawback; REvil; LockBit Operation Cronos); OFAC (Evil Corp 2019); NCA; company disclosures (UnitedHealth/Change Healthcare, MGM, Caesars, JBS); Chainalysis; the 2022 Conti Leaks. Cross-refs: Russia, Bitcoin, OFAC, DOJ, FBI, UnitedHealth, EDR_Killer/BYOVD (#240), Malware_Lineage.

← Research index · structured data: spec-ransomware-ecrime-catalog.json · spec-ransomware-ecrime-catalog.md