Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to share source code and technical overlap with the defunct REvil group, suggesting its operators had prior access to REvil's codebase, conducting double-extortion attacks against corporate networks.
Objectives
Executive Summary
Ransom Cartel is a ransomware‑as‑a‑service (RaaS) operation that emerged in December 2021 and appears to leverage code shared with the defunct REvil group. It conducts double‑extortion attacks, encrypting victim data while exfiltrating sensitive information to pressure organizations into paying ransom for decryption and non‑disclosure.
Goals & Targeting
Ransom Cartel’s strategic objective is financial profit through ransomware extortion, amplified by double‑extortion tactics that increase leverage over victims. The group targets any organization that can generate sizable ransom payouts, with a preference for sectors that store valuable proprietary or personal data, such as healthcare, finance, manufacturing, and professional services. Geographic targeting is opportunistic, focusing on regions where law enforcement response is perceived as slower or where ransom payments are more likely. Typical victims are mid‑size to large enterprises with inadequate network segmentation, weak credential hygiene, and limited backup resilience, making them vulnerable to both encryption and data‑leak threats.
Enhanced Description
Ransom Cartel is a medium‑sophistication criminal outfit that provides ransomware capabilities to affiliates through a ransomware‑as‑a‑service model. First observed in December 2021, Unit 42 analysis indicates that the group reuses source code and tooling originally developed by the REvil (Sodinokibi) ransomware, suggesting that its operators have direct access to or have inherited REvil's development assets. The service offers affiliates a turnkey solution that includes encryption modules, data exfiltration scripts, and ransom note templates, enabling rapid deployment against corporate networks. The group’s primary attack methodology is double‑extortion: after compromising a victim’s environment, they encrypt critical files and simultaneously exfiltrate sensitive data to a leak site or dark‑web forum. This dual pressure tactic increases the likelihood of ransom payment, as victims face both operational downtime and potential data exposure. Ransom Cartel’s affiliates typically gain initial access via phishing, compromised remote desktop protocols (RDP), or exploiting unpatched vulnerabilities in publicly exposed services. Operationally, the cartel employs a modular architecture that allows affiliates to customize payloads, choose encryption algorithms, and configure C2 channels. The ransomware payloads are often delivered as PowerShell or Windows executable dropper files, which then stage additional tools such as credential‑dumpers (e.g., Mimikatz) and file‑transfer utilities (e.g., Rclone) to facilitate data theft. The group also uses bullet‑proof hosting and fast‑flux DNS techniques to obscure its command‑and‑control infrastructure. Ransom Cartel’s business model mirrors other RaaS operations: affiliates receive a share of the ransom proceeds, while the core developers retain a percentage for ongoing development and support. This model incentivizes rapid adoption and broad targeting across multiple industries, making the group a persistent threat to organizations lacking robust cyber hygiene and incident response capabilities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ransom Cartel operates an affiliate‑driven campaign model, releasing new ransomware builds and updates on a regular cadence to maintain effectiveness against evolving defenses. Campaigns typically begin with phishing emails or compromised RDP credentials, followed by rapid lateral movement and credential harvesting. Once foothold is achieved, the ransomware encrypts files while simultaneously exfiltrating data to cloud storage services or dedicated leak sites. The group frequently publishes stolen data on dark‑web forums to increase pressure on victims. Operational tempo is high, with multiple concurrent attacks across diverse industries, and the group leverages bullet‑proof hosting to maintain resilient C2 infrastructure. Notable incidents attributed to Ransom Cartel include attacks on European manufacturing firms and North American healthcare providers in 2022‑2023, where ransom demands exceeded several million dollars.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core attributes of Ransom Cartel (RaaS model, REvil code reuse, double‑extortion tactics) is high, based on multiple Unit 42 analyses and observed campaign artifacts. However, gaps remain regarding specific targeted sectors, geographic focus, and the full inventory of tools used by affiliates, as public reporting is limited. Continuous monitoring of threat feeds and victim disclosures is recommended to refine these details.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics