The biggest mistake in understanding ransomware is treating it as a single actor problem. "LockBit attacked us" is wrong in the same way "FedEx attacked us" is wrong when FedEx delivers a bomb. LockBit provides the platform. The affiliate conducted the intrusion. The initial access broker sold the entry point. The infostealer operator harvested the credentials months earlier. Disrupting one link doesn't stop the chain.
→ Credential logs sold in bulk on dark web markets and Telegram
→ Initial Access Broker (IAB) buys logs, tests credentials, packages working VPN/RDP access
→ Affiliate buys access from IAB, conducts the intrusion (recon, cred escalation, lateral movement, data theft)
→ RaaS platform (LockBit, BlackCat, Cl0p, Play, DragonForce) provides the encryptor, leak site, negotiation infrastructure
→ Ransom payment split: typically 70-80% affiliate, 20-30% RaaS operator
Affiliates move between platforms. When BlackCat/ALPHV exit-scammed in March 2024, their affiliates moved to RansomHub. When RansomHub ceased operations in March 2025, affiliates moved to DragonForce and Devman. The same intrusion playbook, the same affiliate operators, just a different ransomware binary at the end. Attributing to the RaaS brand is like attributing a crime to the getaway car manufacturer.
Conti's DNA is everywhere. Devman, Akira, BlackSuit, INC Ransom, Royal, and others all trace lineage to the Conti ecosystem that fragmented in 2022. Many "new" groups in 2025 are the same operators under new brands, using the same tradecraft and drawing from the same affiliate pool.
IABs serve multiple ransomware operations simultaneously. Dragos identified TAT24-87 operating as a highly active IAB whose access was subsequently used by BlackBasta, BlackSuit, 3AM, and EncryptHub. One access provider, four ransomware brands. The access is the product, not the ransomware.
Despite 119 tracked ransomware groups, the affiliate intrusion pattern is remarkably consistent:
Initial access: Valid credentials from infostealers or IABs (82% of detections malware-free per CrowdStrike 2026 GTR). Authenticate to VPN, Citrix, RDP. Alternative: exploit edge device CVE (FortiGate, Ivanti, Palo Alto). Rarely phishing alone anymore.
Post-access (minutes to hours): Discovery (whoami, systeminfo, net group). LSASS dump or Kerberoasting for credential escalation. PsExec, WMI, or RDP to domain controller.
Pre-deployment (hours to days): Disable or uninstall EDR/AV (BYOVD, Safe Mode boot, service manipulation). Delete shadow copies. Kill backup agent services. Exfiltrate data via Rclone to cloud storage for double extortion.
Deployment: GPO scheduled task, PsExec push, or direct ESXi encryption. Often executed overnight or on weekends. ESXi targeting is growing specifically because guest-level EDR can't see hypervisor-level encryption.
LockBit: Disrupted by Operation Cronos (February 2024), rebuilt, disrupted again. Still active but diminished. Historically the most prolific RaaS by victim count.
Cl0p: Specializes in mass exploitation of file transfer appliances (MOVEit, GoAnywhere, Cleo MFT, CrushFTP). Steals data at scale without deploying ransomware encryptors. Pure extortion.
Play: Consistent mid-tier operator. Targets MSPs for one-to-many access.
DragonForce: Current Scattered Spider partner. Claimed control of RansomHub infrastructure after RansomHub went dark in March 2025. Rising.
Akira: Conti lineage. Targets VPN appliances (especially Cisco ASA) for initial access. Known to target small and mid-size organizations.
Fog: Documented targeting OT-adjacent ESXi hypervisors hosting SCADA VMs (Dragos 2026). Causes operational disruption without touching ICS protocols.
Devman / BlackSuit / INC Ransom: Conti successor ecosystem. Similar tradecraft, different branding.
Defend against the affiliate playbook, not the brand. Every triage playbook in this collection addresses a piece of the ransomware kill chain: Infostealer (where the credentials come from), Compromised Credentials (how they authenticate), Edge Device (the alternative initial access), C2 Beacon (post-access implant), Data Exfiltration (the pre-encryption theft), and Ransomware Detected (the end state). The RaaS brand on the ransom note tells you almost nothing actionable. The affiliate's tradecraft tells you everything.
The most effective controls are boring. MFA on VPN (blocks infostealer credential reuse). Credential hygiene (unique passwords, no browser-saved corporate creds on personal devices). Endpoint hardening (block PsExec, restrict PowerShell, monitor LSASS access). Backup isolation (offline or immutable, not on the same domain). Patch edge devices (close the alternative entry). These stop the affiliate playbook at multiple points regardless of which RaaS brand they're affiliated with.
Ransomware Detected (the end state of the RaaS pipeline)
Infostealer Infection (the upstream credential source)
Compromised Credentials (how affiliates authenticate)
Edge Device Compromised (the alternative initial access)
Scattered Spider (the most prominent affiliate collective)