Ransomware Group Rebranding After Law Enforcement Action
Law enforcement takedowns scatter ransomware groups into new operations, not eliminate them.

Ransomware groups don't die. They molt. Law enforcement takes down the infrastructure, seizes the domains, freezes the crypto wallets. And then, a few months later, the same operators are back online under a new name, running the same playbook, hitting the same kinds of targets. The instinct after a big takedown is relief. The data says that instinct is wrong.
Between July 2024 and June 2025, Malwarebytes tracked 41 new ransomware groups. More than 60 groups were active simultaneously. That's a first-ever record. In the first half of 2025 alone, 89 ransomware gangs carried out over 4,000 attacks. That's roughly a 40% jump over the same period the year before. The number of active groups has approximately doubled over three years. Law enforcement has never been more active. Ransomware has never been more prolific. Together, those two facts tell the whole story.
Disruptions are dispersants. Understanding the difference marks a security team that's actually prepared.
What Ransomware Groups Pack When They Leave Town
Here's the thing about infrastructure seizures. They're loud, they're great for press releases, and they genuinely cause short-term pain for the groups targeted. Arresting the operators is the point, and seizures rarely achieve it.
What survives a takedown:
- The people. Experienced operators, coders, and negotiators walk away free the vast majority of the time.
- The relationships. Affiliates know who to call. Those relationships don't disappear when a domain gets seized.
- The playbook. Negotiation scripts, ransom note templates, target selection criteria. All of it lives in someone's head and in encrypted files law enforcement never touched.
- Sometimes the code. Source code either travels with the operators or gets sold on the market, where it becomes someone else's starting point.
Ransomware-as-a-service is a franchise model, and affiliates are franchise operators. They care about two things: does the tooling work, and does leadership pay out reliably. Brand allegiance in ransomware is purely transactional. Which means when the brand goes away, affiliates shop around fast.
The mechanics of a rebrand are actually pretty simple. New name, new leak site, same trusted contacts, recycled or lightly tweaked tools. The "new" group is operationally the same as the old one. Transitions typically happen within two to six months of a predecessor's shutdown. Fast enough to keep momentum. Fast enough to retain affiliate confidence before those affiliates drift somewhere else permanently.
Two structural patterns show up repeatedly in the data. The first is the single-successor rebrand: one group dissolves and reconstitutes as one new group. The second is the splinter model: one group collapses and its people scatter into several smaller successor groups. Both patterns are worth knowing, because they produce different threat landscapes afterward.
The DarkSide–BlackMatter–BlackCat–RansomHub Chain Is the Textbook Case
This lineage is worth knowing cold, because it's the clearest illustration of how serial rebranding actually works.
DarkSide launched in August 2020. It shut down in May 2021 after the Colonial Pipeline attack brought the full weight of U.S. law enforcement attention down on it. Within weeks. Not months. Weeks. The group returned as BlackMatter.
BlackMatter ran until November 2021, when a decryptor was developed and servers were seized. The group reconstituted again as ALPHV/BlackCat. By September 2023, the FBI reported BlackCat had compromised over 1,000 victims and collected nearly $300 million in ransom. The FBI disrupted BlackCat in December 2023, seizing its leak site and obtaining decryption keys for around 500 affected victims.
The group's response to that disruption is genuinely remarkable in how brazen it was. BlackCat's operators pulled an exit scam. UnitedHealth had paid a $22 million ransom. The operators took the full amount and abandoned their own affiliates. Just walked away with the money and left everyone else holding the bag.
Former BlackCat affiliates migrated primarily to RansomHub, which emerged in February 2024, and to Cicada3301, which surfaced in May 2024. Cicada3301's malware shares a Rust codebase and specific virtual-machine-halting methods with BlackCat's code. That's a meaningful signal, though not confirmed attribution. BlackCat's code was sold on the market, so code similarity could reflect a purchase rather than direct lineage. The honest analyst position is a strong pattern with unconfirmed attribution.
What the chain shows clearly: each rebrand followed enforcement intervention, and the time to restore operations got shorter with each iteration. Practice makes perfect, apparently, even in ransomware.
Conti Didn't Rebrand. It Exploded Into Multiple Groups.
Conti's end was different. A leak took it down, not law enforcement action.
In February 2022, a Ukrainian researcher published a massive cache of Conti's internal chats and source code after the group publicly declared support for Russia's invasion of Ukraine. The leak exposed operations, identities, and internal drama that effectively ended Conti as a unified brand.
What followed was the splinter model in action. Conti's experienced operators didn't reconstitute as one new group. They scattered into at least three distinct successor operations: Black Basta, BlackByte, and Karakurt. Each inherited experienced people rather than a shared brand. Blockchain forensics confirmed the Conti-Black Basta connection. That matters, because it's a more reliable attribution method than malware similarity alone. Black Basta collected at least $107 million in ransom payments traceable on-chain from its emergence in 2022 through late 2023.
The logic of the splinter model makes sense from an operational security perspective. Smaller, leader-controlled cells are harder to surveil. They present a lower profile than the centralised, hundreds-of-people operation Conti had become. Conti got taken down in part because it had grown so large it became visible. Breaking into smaller cells is a direct lesson learned from that.
Black Basta itself collapsed by early 2025. Its last victim was posted in January 2025. Internal chat logs leaked in February. Its affiliates have since been observed moving to Cactus and Akira, and the cycle starts again.
One more case worth noting here: Royal became BlackSuit, following the single-successor pattern. CISA identified BlackSuit as Royal's direct successor. Operation Checkmate in July 2025 dismantled servers, seized domains, and confiscated over a million dollars in cryptocurrency. And already, some reporting places BlackSuit in the early stages of yet another rebrand. The wheel keeps turning.
The Hive–Hunters International–World Leaks Case Shows That Code Is a Commodity
This one adds a genuinely important wrinkle to the picture.
Hive was disrupted by law enforcement in early 2023. About nine months later, Hunters International emerged with Hive's code and remaining infrastructure. But here's what makes this case different from the others: Hunters International purchased Hive's capability and modified its encryption, operating under distinct leadership. The lineage is one of purchased capability rather than operator continuity.
By November 2024, Hunters International announced its own closure, citing law enforcement pressure and unfavorable operational odds (which is a surprisingly candid statement from a criminal enterprise). World Leaks emerged shortly after and is assessed as a likely rebrand.
What this chain illustrates is that ransomware tooling has commodity value that is completely independent of its original operators. Source code can be sold. It can be adapted. It can be re-deployed by entirely different people who have no connection to whoever wrote the original version.
That creates a real attribution problem. When code is sold rather than carried by the same operators, the usual signals get weaker. Affiliate crossover patterns, negotiation style, ransom note language — those signals assume continuity of personnel, which breaks down entirely when a group has simply purchased a toolkit from someone else. Defenders who rely solely on malware fingerprints may misidentify a new entrant as a known threat or, worse, miss a genuinely new actor because their tooling looks familiar.
LockBit's Story Is Still Unresolved, and That's the Point
LockBit is the most prolific ransomware-as-a-service operation on record. Thousands of claimed victims since 2019. Consistently at the top of every attribution list for years.
Operation Cronos in February 2024 was one of the most significant law enforcement actions in ransomware history. Thirty-four servers seized. Around 14,000 accounts closed. About 200 cryptocurrency accounts frozen. Five indictments. Arrests in Poland and Ukraine. The operation also included a psychological element that was a deliberate departure from infrastructure-focused enforcement: law enforcement used the threat of exposing the identity of LockBit's lead operator (known as LockBitSupp) to erode affiliate trust and damage the brand's credibility.
That psychological pressure was smart. It was also not enough.
LockBit's core operators were not arrested. The group attempted to rebuild. It continued posting victims. As of mid-2025, no confirmed successor group had been publicly identified. But given the operator's track record and the pattern every prior case has established, reconstitution is the expected outcome, full stop.
LockBit shows you the ceiling of infrastructure-focused enforcement. Reputational damage matters. Affiliate erosion matters. But both effects are temporary when the people running the operation are still free. The operators are the persistence mechanism; infrastructure is simply replaced around them.
Track the Operators, the Affiliates, and the Code. Not the Names.
Globally claimed victims rose from roughly 5,400 annually in 2023 to over 8,000 in 2025, according to Emsisoft. Forty-five newly observed groups pushed the active count to a record 85 distinct extortion operations. The rebranding cycle is the primary driver of ransomware's growth.
The operationally useful signals are the ones that persist across rebrands, and tracking group names obscures that.
What's actually worth monitoring:
- TTPs. Negotiation tactics, ransom note structure, encryption implementation. These change slowly even when names change fast.
- Affiliate behavior patterns. Which affiliates are moving, and where are they landing? That tells you which groups are gaining capability and credibility.
- Infrastructure choices. Bulletproof hosting preferences, cryptocurrency mixing patterns. These reflect operator habits, not brand decisions.
- Code characteristics. Useful, but with appropriate caveats. Code can be sold. Similarity is a signal that stops short of proof.
- Blockchain forensics. Consistently more reliable than brand tracking for establishing continuity. The Conti-Black Basta link was confirmed on-chain, not through malware similarity alone.
Treat the two-to-six month window after a major takedown as a period of elevated risk, not reduced risk. Affiliates are actively shopping for a new home. New groups are forming around their demand. That window is when the next threat is taking shape.
The most important thing intelligence teams can do right now: watch which groups are absorbing displaced affiliates after each disruption. That group is the next prioritized threat. The name they're using this week is irrelevant.


