DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Some lower-tier ransomware gangs have formed a new RaaS alliance — or have they? (1)

Posted on October 28, 2025October 28, 2025 by Dissent

Calling all of the groups ‘lower-tier’ may have been inaccurate. Please be sure to read the update at the bottom of this post.

We’ve seen a few announcements this year heralding cartels or alliances in the ransomware ecosystem. Two such announcements involved DragonForce, but as SuspectFile reported, there was no evidence of a cartel, and at least one of the named groups flat-out denied joining one.

Today, there’s another alliance announcement. The Stormous group announced:

Important Announcement Regarding Our Operations

In our fifth edition (V5), we are announcing a strategic alliance that unites six RaaS groups, including their extended networks, affiliated personnel, malware toolkits, and operational infrastructure. This collaboration is designed to create a robust and scalable cyber network, with the primary goal of expanding attack surfaces, enhancing lateral movement capabilities, and optimizing the efficiency of ransomware campaigns.

Groups:

  • Nova Ransomware
  • DevMan Ransomware
  • CoinBase Cartel
  • RADAR Ransomware
  • Desolator Ransomware
  • Kryptos Ransomware

Firstly, that would be uniting seven groups, not six (Stormous may have forgotten to count themselves). But do these groups even know that they have formed a cartel or an alliance? A check of five of the six other entities’ sites uncovered no statement on any of them about any new alliance or cartel. One of the six sites was not online and could not be checked.

So they formed an alliance but none of the allies have announced it other than Stormous? We will see in the days to come whether any of the other named entities confirm,

“Paging SuspectFile to Aisle 4 for verification.”

Update:  DataBreaches was contacted by a spokesperson for Devman. They were unhappy with the characterization of their group as “low-tier,” which was somewhat subjective since DataBreaches did not have actual income reports for all of the groups.  As they describe themselves, in terms of money earney/income, they consider themselves medium-tier. DataBreaches took the opportunity to ask whether they agreed with what Stormous claimed about an alliance being formed. They agreed, and described it as an alliance, and not any “cartel.” When DataBreaches asked how they would benefit from the alliance, they responded, “Good to have friends.”


Related:

  • The Alliance That Wasn’t: A Critical Analysis of ReliaQuest’s Q3 2025 Ransomware Report
  • When the victimizers become the victims.... RansomHub the victim of a takeover?
Category: Commentaries and AnalysesMalware

Post navigation

← Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
Alan Turing institute launches new mission to protect UK from cyber-attacks →

1 thought on “Some lower-tier ransomware gangs have formed a new RaaS alliance — or have they? (1)”

  1. Stormous says:
    October 31, 2025 at 7:24 am

    Stormous made poor choices to create the current environment. Allegations were made in haste , likely the result of myopic scapegoating, a forthcoming inquiry will show.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.