Inside the New Faces of Digital Extortion: How DragonForce and Anubis Are Reinventing Ransomware

Listen to this Post

Featured Image
As cybersecurity experts and law enforcement authorities ramp up their efforts to dismantle cybercrime networks, ransomware gangs are proving they’re anything but stagnant. A new report by Secureworks’ Counter Threat Unit (CTU) reveals how two well-known ransomware groups—DragonForce and Anubis—are evolving faster than expected, adopting fresh business models that enhance their reach, reduce operational effort, and maximize revenue.

These threat actors are no longer just shadowy hackers demanding cryptocurrency in exchange for data decryption keys. Instead, they are running structured, scalable operations more akin to legitimate startups—with affiliate programs, customer support, and marketing strategies. This report provides a deep dive into how these groups are adapting their methods to stay ahead of the curve, and what that means for the global cybersecurity landscape.

Evolution of Ransomware Business Models – A New Era of Digital Crime

DragonForce’s RaaS to Cybercrime Cartel Transformation

  • DragonForce first emerged in August 2023 as a traditional ransomware-as-a-service (RaaS) platform.
  • By early 2024, it gained momentum through increased visibility on underground forums.
  • As of March 2025, the group recorded 136 victim disclosures.
  • On March 19, 2025, DragonForce rebranded itself as a cartel—shifting to a distributed affiliate model.
  • This model allows affiliates to build their own ransomware brands while using DragonForce’s infrastructure.

– The infrastructure includes:

– Admin and client panels

– File encryption tools

– Negotiation utilities

– A Tor-based leak site

– Storage systems and full support

  • Affiliates can use either DragonForce’s malware or plug in their own.
  • The strategy aims to lower entry barriers for cybercriminals of all skill levels.
  • While lucrative, this shared ecosystem increases the risk of exposure if one affiliate is compromised.

Anubis’s Tiered Affiliate Strategy and Aggressive Extortion

  • In February 2025, Anubis launched a three-option affiliate model:

1. Traditional RaaS with 80% ransom cut.

  1. Data ransom model with 60% commission, focusing only on data theft and exposure.
  2. Access monetization where affiliates with existing system access earn 50% for facilitating extortion.

– The “data ransom” method uses investigative-style writeups hosted on secure Tor sites.
– Victims can view this data and negotiate—but face public exposure and regulatory pressure if they don’t comply.
– Anubis escalates its threats by warning victims’ clients and regulators like:

– UK Information Commissioner’s Office

– U.S. Department of Health and Human Services

– European Data Protection Board

  • The “access monetization” strategy includes data analysis tools to boost leverage.
  • Anubis avoids attacking schools, governments, and non-profits—but leaves healthcare open, making hospitals a prime target.
  • SecureWorks emphasizes how both DragonForce and Anubis exemplify the increasing sophistication and adaptability of modern ransomware operations.

What Undercode Say:

Ransomware operations are no longer chaotic, one-man jobs executed in the shadows—they are morphing into structured, resilient organizations with refined business logic. DragonForce and Anubis represent a disturbing evolution in the cybercrime ecosystem, and their affiliate-focused designs echo the agility and modularity seen in the tech startup world.

DragonForce’s cartel approach introduces a decentralized hierarchy that mimics a franchise system. By offering technical services and infrastructure while allowing brand autonomy, the group successfully reduces operational friction for its partners. This model is appealing to amateurs and professionals alike. Think of it as the Shopify of ransomware—lowering the technical barrier to entry, while DragonForce profits from every “store” that opens up.

The downside, however, is shared risk. If one affiliate’s identity or methods are uncovered, it could unravel the entire network. Yet, this risk seems acceptable to DragonForce, possibly because the volume of affiliate activity outweighs occasional fallout.

Anubis takes a slightly different path—its three-tier system focuses on customization and coercive leverage. The “data ransom” tactic, in particular, is chilling. It’s no longer about just locking files and asking for money; now, it’s about carefully timed public shaming backed by regulatory threats. This multi-pronged pressure forces victims to think beyond their immediate IT issues and consider long-term reputational and legal consequences.

Moreover, by integrating tools for analyzing stolen data and facilitating better extortion strategies, Anubis empowers its affiliates with a professional toolkit, further legitimizing the business-like structure of its operations.

The most alarming element? Healthcare is not off-limits. While some ethical lines are drawn—such as avoiding schools and nonprofits—the omission of healthcare signals a calculated decision. The sensitive nature of medical data and tight regulatory requirements make healthcare institutions uniquely vulnerable and likely to pay quickly.

Ultimately, what we’re witnessing is a shift in how digital threats are packaged and delivered. These operations are becoming productized, outsourced, and distributed—making detection and prevention exponentially harder. Security teams can no longer afford to view ransomware as a single-entry threat; it’s now a supply-chain issue within the cybercrime world.

Fact Checker Results:

  • Verified: DragonForce rebranded as a cartel with affiliate brand autonomy in March 2025.
  • Confirmed: Anubis uses a three-pronged affiliate model with enhanced extortion methods.
  • Authentic: SecureWorks CTU’s findings align with patterns observed in underground cybercrime forums.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.medium.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram