Cybercrime DB

Morphing Cybercrime Tactics After Platform Takedowns

Criminals rebuild taken-down infrastructure faster than law enforcement can dismantle it.

Contributing Editor · · 11 min read
Cover illustration for “Morphing Cybercrime Tactics After Platform Takedowns”
cybercrime takedowns and seizures · September 18, 2026 · 11 min read · 2,458 words

Cybercrime didn't slow down in 2025. It just got better at healing. Law enforcement ran more coordinated takedowns than in any prior year, and the criminal ecosystem absorbed nearly every one of them within weeks, sometimes days. This piece walks through what actually happened, why the market keeps clearing anyway, and what that means for anyone whose job is to defend against it rather than write press releases about it.

What law enforcement accomplished in 2025, and what the scale of those operations reveals

Ten named operations. SOCRadar confirmed that count across 2025, a density of action nobody had seen before, with Operation Talent in late January, Operation Phobos Aetor in February, the Zservers/LockBit sanctions the day after, the LummaC2 takedown in May, Operation Eastwood in July, the Checkmate action against BlackSuit ransomware later that month, Operation Serengeti 2.0 running from June through August, a Bitcoin seizure tied to the Prince Group in October, Operation Endgame 3.0 in November, and Operation Red Circus closing out the year in December.

Serengeti 2.0 alone claimed a 1,000-person cybercriminal network taken apart, $97.4 million recovered for more than 88,000 victims, and a large amount of malicious infrastructure dismantled in Angola. Those are not small numbers, and they reflect a real shift in strategy behind operations like Endgame, where investigators stopped chasing individual hackers one at a time and started going after the scaffolding, the suppliers, the distribution networks, and the money launderers, all at once, rather than picking off names one by one.

Some of this worked because agencies stopped working alone. Ahead of Operation Secure, which ran across 26 countries between January and April, INTERPOL coordinated with Group-IB, Kaspersky, and Trend Micro to build Cyber Activity Reports before boots ever hit the ground. The result: 79% of the identified suspicious IPs got taken down, along with 41 servers and more than 100 gigabytes of seized data.

None of that is nothing. Takedowns force criminals to rebuild infrastructure and reputation at real cost, they buy victims breathing room during the downtime, and they plant seeds of distrust between RaaS operators and the affiliates who rent their tools. They buy time during downtime, weaken trust between RaaS operators and affiliates, and force operators to spend real money rebuilding infrastructure and reputation. They're just bounded, and bounded in a specific, predictable way that the rest of this piece explains.

The hydraulic dynamic: why pressure in one place creates volume somewhere else

Think of the cybercrime economy like water in a pipe system. Squeeze one section and the pressure doesn't disappear, it just finds the next open valve. Check Point has noted that new ransomware brands tend to rise almost the moment a predecessor collapses. That's not bad luck or coincidence; it's what a hydraulic system does under pressure, every time. It's what a hydraulic system does under pressure, every time.

Without arrests, without agents physically grabbing developers and operators, criminals rebuild fast, which is the limiting condition that makes takedowns leaky by design. Seizing servers removes the current set of servers. It does not remove the customer base, the source code, or the distribution channels that got those servers filled with victims in the first place.

The affiliate model is the load-bearing wall in all of this. Ransomware-as-a-service and phishing-as-a-service both split the operator from the affiliate on purpose, the same way a franchise splits the corporate office from the guy running the drive-through. Shut down the platform and the affiliates don't retire. They go looking for the next franchise willing to take them on.

Three patterns recur once you start looking for them: infrastructure replacement, affiliate migration, and ecosystem fragmentation. Each one leaves a different kind of trail, and each one demands a different response. Knowing which pattern is coming before it appears in the incident logs is the entire difference between defense that reacts and defense that anticipates.

Tycoon2FA: how a 20-day rebuild after seizure of 330 domains illustrates the infrastructure replacement pattern

Tycoon2FA was a subscription phishing kit built to get around multi-factor authentication, and at its peak it was cranking out 30 million phishing emails a month. That volume made it responsible for 62% of all phishing messages Microsoft blocked. A year before its takedown, Barracuda's threat analysts pegged it at 89% of all phishing-as-a-service activity they were tracking, largely because its main rival had already been knocked out months earlier.

The takedown itself landed on March 4, 2026: Microsoft and Europol coordinated across six countries and seized 330 domains in one motion. CrowdStrike's Falcon Complete team clocked the immediate effect: daily campaign volume dropped to about 25% of pre-takedown levels in the immediate aftermath. Real suppression. Short-lived, too.

Twenty days later, Abnormal AI confirmed a new deployment running on freshly registered Russian infrastructure. A content delivery network had replaced Cloudflare for the kill-switch function, the infrastructure was restructured with additional evasion layers, and the anti-analysis traps got meaner, jumping from a 1,000-millisecond debugger delay to just 100 milliseconds. Twenty days, from seizure to full rebuild.

What didn't change is the interesting part. The cryptographic fingerprint stayed identical across the rebuild: same linear congruential generator constants, same layered substitution-and-XOR cipher, same "bltpg" kit parameter buried in the code. That consistency is the operation's real weak point, the one thing that doesn't move even when everything around it does.

Subsequent analysis found that even while the branded Tycoon2FA service absorbed the disruption and rebuilt, variants continued circulating in smaller, harder-to-spot batches. Detection tied to domains and IPs goes stale within days of a seizure like this. Detection built around behavioral and cryptographic fingerprints survives the churn, because the churn itself is designed to change.

LummaC2: how the affiliate-service model made 2,300 domain seizures insufficient within a single day

The FBI put LummaC2's reach at 1.7 million information-stealing attacks. Microsoft separately tracked more than 394,000 infected Windows machines between mid-March and mid-May of 2025. This wasn't a boutique tool. It was embedded across a wide, active affiliate base that had no reason to stop just because headquarters had a bad week.

The takedown ran May 13 through 21, 2025. Microsoft got a court order from a federal jurisdiction. court order and seized 2,300 domains in one sweep, while the DOJ and FBI separately unsealed warrants targeting key administration domains. Multi-agency, coordinated, and about as substantial as a domain-based takedown gets.

The indicator-of-compromise data tells the real story. IoCs cratered to 57 on May 21, right when the operation landed its punch. By the very next day, May 22, they'd shot back up to 287. Spikes on May 28 and May 29 hit 457 and 440 respectively, both well above pre-takedown levels. The seizure didn't win. It barely got a day off.

Structurally, Lumma sells itself as a service to affiliates who run their own independent campaigns and never need visibility into the back end. Taking down the servers removes the current infrastructure. You haven't touched the customer base, the source code, or the distribution channels those affiliates already control on their own.

Jurisdiction did the rest of the work. Shift hosting to a provider in a jurisdiction with limited law enforcement cooperation and the back end sits largely outside what agencies in one major jurisdiction and European agencies can reach, a move ransomware-as-a-service operators have leaned on for years already. Compare that to what actually worked against RedLine, where prosecutors charged the developer, Maxim Rudometov, directly. Charging the person who wrote the code is far more disruptive than seizing a server, because the developer is the one piece nobody can swap out overnight.

The long tail bears this out. ANY.RUN's Q4 2025 threat report recorded a 65% drop in Lumma detections following sustained pressure, which sounds like a win until LummaC2 showed signs of resurgence in 2026 through new loader infrastructure. Displacement, not extinction. As SOCRadar's CISO Ensar Seker put it, "In the past, a coordinated takedown might stall operations for months. But today's cybercriminals operate with backup channels, mirrors, and modular ecosystems that allow them to pivot in days, not weeks."

Diagram: LummaC2: One Day of Suppression, Then a Full Rebound. Visualizes: Show the dramatic spike-and-recovery of LummaC2 indicator-of-compromise (IoC) counts around the May 2025 takedown, using a small timeline of daily data points.

RansomHub's collapse and Qilin's rise: how affiliate migration reshapes the ransomware rankings within a quarter

RansomHub was, by most measures, the most active ransomware group of 2024. It ran cross-platform payloads that hit Windows, Linux, and ESXi alike, and it built a reputation on something rare in this business: reliable affiliate payouts and a polished, transparent operation. In the six months before it vanished, affiliates were posting an average of 75 new victims a month.

Then, late March 2025, the leak site just disappeared. No statement, no explanation. Within days, a rival group called DragonForce posted on the RAMP forum that RansomHub had "decided to move to our infrastructure." Around the same time, DragonForce defaced a competitor called BlackLock's leak site, likely exploiting a known vulnerability, though it's also plausible that was a coordinated false-flag move. Either way, BlackLock's operation ended and DragonForce absorbed what was left. This is a group that grows by eating its rivals rather than recruiting from scratch.

The affiliates RansomHub left behind had to land somewhere, and Check Point's data shows exactly where: Qilin's monthly victim count nearly doubled in Q2 2025, climbing from an average of 35 to almost 70, tracking almost perfectly with the window when RansomHub's affiliates went looking for a new home.

What that migration built is now the dominant ransomware brand around. Qilin posted a substantial incident count across every region in 2025, then 389 leak-site attacks in Q1 2026 alone, a pace running well above the year before. MOXFIVE's tracking puts total victims since Qilin's launch at roughly 1,500, with more than 500 of those landing in 2026 alone.

Cracks showed up on the forums before they showed up in the victim data. On July 31, 2025, an affiliate using the handle "hastalamuerte" claimed Qilin had run an exit scam on them, pocketing $48,000 that should've been theirs. Separately, a user called "Nova" leaked the entire Qilin affiliate panel, login credentials included. Internal unrest went public well before it appeared anywhere near an incident report. As Europol's IOCTA 2026 report frames it, public RaaS affiliate programs have lowered the entry bar so far that almost anyone can launch an attack with a bundled toolkit, which is exactly what makes migration this easy: affiliates always have somewhere else to go.

Three patterns, one lesson: what the adaptation playbook looks like across different cybercrime categories

Lining the three case studies up makes the pattern obvious fast. Tycoon2FA shows infrastructure replacement: an operator with intact source code and an existing billing relationship with affiliates can rebuild on new hosting in a matter of weeks, and the speed of that rebuild tracks directly with how much the original takedown targeted people versus servers. Hit the servers, expect a fast rebuild. Hit the people, expect something slower.

LummaC2 and RansomHub both show affiliate migration. When a platform gets disrupted, its customer base doesn't dissolve, it moves. The affiliate, not the brand, turns out to be the durable unit in this economy.

Tycoon2FA's aftermath also shows the third pattern: ecosystem fragmentation. Barracuda's analysis found that knocking out a dominant platform actually speeds up diversification, as clones and modified variants scatter into smaller, harder-to-attribute campaigns that slip right past detection built for the original kit.

A thread through all three lands on the same conclusion: the parts of a criminal operation that aren't servers, the affiliates, the source code, the reputation, the customer relationships, survive infrastructure seizures just fine. Only arresting the people who build and run these tools actually touches those assets.

The tactics riding on top of this are getting more standardized too. Kaspersky's report flags EDR killers and Bring Your Own Vulnerable Driver techniques as a now-routine pre-execution step, not an opportunistic extra, meaning evasion has become a planned phase of the attack lifecycle rather than an improvisation. And the ransom model itself is shifting: Kaspersky found the share of ransoms actually paid dropped to 28% in 2025, pushing more groups toward pure data theft and exposure threats instead of encryption. Backups don't help against that. It turns ransomware from a business continuity headache into a data security and compliance one.

What defenders who understand these patterns do differently

Domain and address-based detection has a shelf life, and that shelf life gets shorter every time a major takedown happens. Tycoon2FA's rebuild proved that detection anchored to cryptographic and behavioral fingerprints, the LCG constants, the cipher, the kit parameters that don't change even when the hosting does, outlasts the infrastructure churn built to dodge it.

Identity has to move up the priority list too. Tycoon2FA existed to bypass MFA, and the phishing-as-a-service market around it stayed viable even after its dominant platform got seized. Treating identity as a downstream concern, something to shore up after the perimeter, misreads where the actual attack surface sits.

Forum chatter is operational intelligence, not noise to skim past. RansomHub's disappearance and Qilin's affiliate blowup both surfaced on criminal forums before either showed up in victim data. That gap, forum signal to incident report, is where early warning actually lives.

A stranded affiliate base doesn't disappear; it migrates elsewhere, and that migration can be modeled. Qilin's doubling in Q2 2025 wasn't a surprise to anyone paying attention to RansomHub's operational posture beforehand, it was close to predictable. And because ransoms increasingly get paid to prevent exposure rather than to unlock files, incident response plans need a separate track for data theft and exposure threats, backups don't cover that risk, legal and communications teams need to be looped in well before an incident, not during one. Finally, calibrate what a takedown is actually worth: real value, front-loaded, mostly in the friction and distrust it seeds inside criminal communities. Plan for reconstitution within weeks, not months.

Security content that treats each takedown as a standalone victory leaves practitioners underserved

Every takedown gets a press release, and every press release reads like the story's over. Then, a few weeks later, the operational data shows the rebound, and the security teams that built their strategy around "problem solved" get caught flat-footed. They remember exactly which vendor told them it was over.

That's a credibility problem as much as a technical one. Vendors who match their messaging to the law enforcement press cycle, without explaining the hydraulic dynamic underneath it, reveal that they don't actually understand how this ecosystem behaves once the cameras leave.

A technically sharp reader wants an honest read on what happens next. It's an honest read on what happens next: which adaptation pattern is likely, where the detection gaps open up during the transition, and what the migrating affiliate base is probably going to target once it finds its next home. That's the whole job, really, told straight.

Sources

  1. Europol IOCTA 2026 report flags shift to industrialised cybercrime powered by AI, ransomware and data theft - Industrial Cyber
  2. Tycoon2FA Phishing-as-a-Service Platform Persists After Takedown
  3. Reviewing the trends in ransomware attacks in 2026
  4. Cybersecurity Trends: What's in Store for Defenders in 2026?
  5. Top 10 Cybercrime Law Enforcement Operations of 2025
  6. abnormal.ai
  7. thehackernews.com
  8. trendmicro.com

More in cybercrime takedowns and seizures