Even after sustained crackdowns by global law enforcement in 2025, ransomware groups are proving more resilient and resourceful than ever.
DragonForce and Anubis, two rising names in the cybercriminal underworld, are now rolling out fresh affiliate frameworks aimed at broadening their operations and boosting profits. Their latest moves highlight just how quickly the ransomware ecosystem continues to adapt to mounting pressure and shifting digital battlegrounds.

DragonForce first surfaced in August 2023 as a conventional ransomware-as-a-service (RaaS) outfit, making its presence known across underground forums by early 2024.
Fast forward to March 2025, and the group had already amassed 136 victims, each listed on its public leak site.
In a bold move, DragonForce has recently rebranded itself as a “cartel,” unveiling a new distributed structure. This shift empowers affiliates to craft their own unique “brands,” all while utilizing DragonForce’s robust backend infrastructure for operations and support.
Meanwhile, researchers from Secureworks’ Counter Threat Unit (CTU) have been tracking the emergence of Anubis, another rising player in the cybercrime space.
Anubis debuted on dark web forums in late February 2025 but set itself apart with an innovative twist on the traditional affiliate model.
Instead of sticking to basic encryption-based extortion, Anubis introduced three tailored extortion strategies, each paired with different profit-sharing tiers — broadening their playbook and maximizing their reach across a wider range of targets.

Ransomware threat actors continue to evolve, finding new ways to stay profitable even as organizations become more resistant to ransom demands.
Emerging affiliate models reveal just how quickly cybercriminal enterprises are adapting, laying the groundwork for more complex and relentless attack strategies.
Anubis Redefines Extortion with a Tiered Model
Anubis, one of the latest players in the ransomware ecosystem, has introduced a three-pronged approach aimed at attracting a diverse pool of affiliates — each option offering a unique spin on the traditional ransomware-as-a-service (RaaS) model.
- Traditional RaaS: Affiliates encrypt victim data, with an attractive 80% share of ransom proceeds.
- Data-Only Ransom: Forgoing encryption entirely, this model focuses purely on exfiltration and extortion, offering a 60% commission.
- Access Monetization: In a novel twist, affiliates are encouraged to ransom already-compromised networks, taking home 50% of the extorted funds.
Anubis’s “data-only ransom” strategy introduces a more polished and calculated pressure campaign. Instead of blunt-force encryption attacks, Anubis posts detailed “investigative reports” exposing sensitive victim data on password-protected Tor sites. Victims are then invited to review the leaks and negotiate terms privately.
If victims resist, Anubis escalates pressure publicly and strategically — publishing victim names via X (formerly Twitter), alerting customers, and most notably, threatening to notify regulatory bodies such as the UK’s Information Commissioner’s Office, the U.S. Department of Health and Human Services, and the European Data Protection Board.
While reporting breaches to regulators isn’t entirely new, Anubis’s aggressive use of it marks a major escalation.
This mirrors tactics first seen in late 2023, when the GOLD BLAZER threat group reported an ALPHV (BlackCat) attack to the U.S. Securities and Exchange Commission (SEC) after a victim refused to pay — signaling a shift toward weaponizing regulatory pressure as part of ransomware playbooks.




