Ransom Cartel is a ransomware-as-a-service group linked to REvil source code, known for double-extortion tactics.
Analyst brief
Ransom Cartel is a ransomware-as-a-service crime group that surfaced in December 2021, with technical overlap linked to the REvil group's source code. It targets corporate networks using double-extortion tactics, encrypting data and threatening to leak it publicly. Its key TTPs include ransomware deployment, data exfiltration, and likely the use of legacy REvil tools. Defenders should focus on network segmentation, offline backups, and monitoring for known REvil IOCs.
ransomcartel
crime
Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to share source code and technical overlap with the defunct REvil group, suggesting its operators had prior access to REvil's codebase, conducting double-extortion attacks against corporate networks.