DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Some lower-tier ransomware gangs have formed a new RaaS alliance — or have they? (1)

Posted on October 28, 2025October 28, 2025 by Dissent

Calling all of the groups ‘lower-tier’ may have been inaccurate. Please be sure to read the update at the bottom of this post.

We’ve seen a few announcements this year heralding cartels or alliances in the ransomware ecosystem. Two such announcements involved DragonForce, but as SuspectFile reported, there was no evidence of a cartel, and at least one of the named groups flat-out denied joining one.

Today, there’s another alliance announcement. The Stormous group announced:

Important Announcement Regarding Our Operations

In our fifth edition (V5), we are announcing a strategic alliance that unites six RaaS groups, including their extended networks, affiliated personnel, malware toolkits, and operational infrastructure. This collaboration is designed to create a robust and scalable cyber network, with the primary goal of expanding attack surfaces, enhancing lateral movement capabilities, and optimizing the efficiency of ransomware campaigns.

Groups:

  • Nova Ransomware
  • DevMan Ransomware
  • CoinBase Cartel
  • RADAR Ransomware
  • Desolator Ransomware
  • Kryptos Ransomware

Firstly, that would be uniting seven groups, not six (Stormous may have forgotten to count themselves). But do these groups even know that they have formed a cartel or an alliance? A check of five of the six other entities’ sites uncovered no statement on any of them about any new alliance or cartel. One of the six sites was not online and could not be checked.

So they formed an alliance but none of the allies have announced it other than Stormous? We will see in the days to come whether any of the other named entities confirm,

“Paging SuspectFile to Aisle 4 for verification.”

Update:  DataBreaches was contacted by a spokesperson for Devman. They were unhappy with the characterization of their group as “low-tier,” which was somewhat subjective since DataBreaches did not have actual income reports for all of the groups.  As they describe themselves, in terms of money earney/income, they consider themselves medium-tier. DataBreaches took the opportunity to ask whether they agreed with what Stormous claimed about an alliance being formed. They agreed, and described it as an alliance, and not any “cartel.” When DataBreaches asked how they would benefit from the alliance, they responded, “Good to have friends.”


Related:

  • The Alliance That Wasn’t: A Critical Analysis of ReliaQuest’s Q3 2025 Ransomware Report
  • When the victimizers become the victims.... RansomHub the victim of a takeover?
  • From bad to worse: Doctor Alliance hacked again by same threat actor (2)
  • Under Pressure: Exploring the effect of legal and criminal threats on security researchers and journalists
  • A chat with DarkSide
Category: Commentaries and AnalysesMalware

Post navigation

← Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
Alan Turing institute launches new mission to protect UK from cyber-attacks →

1 thought on “Some lower-tier ransomware gangs have formed a new RaaS alliance — or have they? (1)”

  1. Stormous says:
    October 31, 2025 at 7:24 am

    Stormous made poor choices to create the current environment. Allegations were made in haste , likely the result of myopic scapegoating, a forthcoming inquiry will show.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • 45,000 malicious IP addresses taken down in international cyber operation
  • The Broken Records: tracing the human cost of the 2022 British MoD leak
  • Telus Digital confirms breach after ShinyHunters claims 1 petabyte data theft
  • China’s CERT warns OpenClaw can inflict nasty wounds
  • Bell Ambulance data breach impacted over 238,000 people
  • Lotte Card fined 9.6 billion won for leaking users’ social registration numbers
  • Handala claims responsibility for attack on medical device maker Stryker
  • Police Scotland fined £66k for extracting and sharing mobile phone data
  • The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life
  • Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • New data shows increase in FBI searches of Americans’ data last year
  • CalPrivacy Fines PlayOn Sports $1.1 Million for CCPA Violations Involving Student Privacy
  • 17 States Sues Trump Administration Over Unlawful Data Demands Targeting Colleges
  • Privacy watchdogs sound alarm over US bid to get travellers’ social media
  • Petition filed over misuse of protesters’ data by Kenyan government and telcos

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: Dissent.73

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.