# Where Ransomware Crews Gather: A Defender's Map of the Underground > A defensive threat-intelligence explainer on the venue types that power the ransomware economy - forums, RaaS portals, initial-access brokers, leak sites - and how defenders and law enforcement monitor and disrupt them. Source: https://playciso.com/blog/where-ransomware-crews-gather-defenders-map · Published: 2026-09-10 · Publisher: PlayCISO (https://playciso.com) --- Ransomware is often pictured as a single hooded figure at a keyboard. The reality is closer to a marketplace: a loosely coupled economy of specialists who never meet, coordinating through a small set of recurring venue types. For defenders and threat-intelligence teams, understanding those venues - what each one is for, and how it is monitored and disrupted - is more useful than memorizing the name of this month's crew. This is a defender's map of where the ransomware economy transacts, written the way a reputable security firm would publish it: no addresses, no access instructions. Just the shape of the terrain. ## The economy behind the extortion Modern ransomware is a supply chain. The developer who writes the encryptor is rarely the person who breaks into your network, who in turn is rarely the person who negotiates the ransom or launders the proceeds. This specialization is what makes the ecosystem resilient: knock out one participant and the others simply source the same service from a competitor. The venues below exist because a supply chain needs places to advertise, vet counterparties, hold funds in escrow, and apply pressure. Each venue solves a specific coordination problem for the criminals - and each leaves a specific set of signals for the people watching. ## Dark-web and criminal forums The oldest venue type is the criminal forum - reputation-based message boards where actors post advertisements, recruit, sell tooling and stolen data, and resolve disputes. Forums matter because they are where trust is manufactured. Vendor feedback, deposit systems and moderator arbitration let strangers transact despite having every incentive to cheat each other. Historically reported and now-defunct examples that have been seized or shuttered by law enforcement - RaidForums and its successor BreachForums, among others - illustrate the pattern: a marketplace grows, becomes central to data-trading, and eventually draws a coordinated takedown. When one falls, the community fragments and reconstitutes elsewhere, which is itself a monitorable event. For defenders, forums are less a place to visit than a source of finished intelligence. Threat-intel vendors track them so that customers do not have to, surfacing when a company's data appears for sale or when a sector is being discussed as a target. ## Invite-only messaging channels As forums drew law-enforcement heat, much day-to-day coordination migrated to encrypted and semi-private messaging - closed Telegram-style channels and peer-to-peer tools such as Tox. These venues trade discoverability for control: membership is vetted, conversations are ephemeral, and the barrier to infiltration is higher. Some groups also run public-facing channels for bravado and victim-shaming, blurring the line between operations and marketing. The intelligence value is real but harder to obtain, and this is precisely the territory best left to specialized teams and law enforcement rather than to an in-house SOC improvising access. ## Ransomware-as-a-service affiliate portals Ransomware-as-a-service (RaaS) is the business model that turned extortion into an industry. A core group maintains the malware, the payment infrastructure and the leak site, then recruits affiliates who carry out intrusions in exchange for a revenue share. Affiliates log into a portal - effectively a criminal SaaS dashboard - to generate payloads, track victims and manage negotiations. RaaS is why the same strain of ransomware can appear in wildly different intrusions: the affiliates, not the operators, choose the targets. The affiliate model is also a fault line defenders and police exploit. Affiliates are numerous, unevenly disciplined, and motivated by money rather than loyalty. Law-enforcement pressure on a RaaS brand - most visibly the multinational action against LockBit known as Operation Cronos, which seized infrastructure, recovered decryption keys and named affiliates - works partly by poisoning the trust between operators and their affiliates. Once affiliates fear that the platform is compromised or that operators are cooperating with investigators, recruitment and retention suffer. ## Initial-access brokers If RaaS is the factory, initial-access brokers (IABs) are the raw-materials suppliers. An IAB compromises organizations and sells the foothold - valid VPN or RDP credentials, an active web-shell, or access to an already-infected machine - to buyers who will monetize it, often ransomware affiliates. This specialization is the single most important trend for a CISO to internalize, because it compresses timelines. The gap between an unpatched edge appliance or a phished credential and a full encryption event can now be measured in days, because the intrusion and the extortion are performed by different parties working in parallel. - IAB listings reveal how access is priced, which industries and geographies are in demand, and sometimes enough detail (sector, revenue band, access type) to infer whether an organization is being advertised. - Because the initial access is frequently mundane - stolen credentials, exposed remote services, known-vulnerable perimeter devices - IAB activity is one of the most actionable intelligence categories a defender has. Reduce the exposures IABs sell, and you raise the cost of the entire chain. ## Data-leak sites and double extortion The data-leak site is the ransomware economy's pressure mechanism. Under double extortion, attackers exfiltrate data before encrypting, then threaten to publish it on a dedicated site with a countdown timer and sample files. This defeats the classic defense of good backups: even a victim who can restore may still pay to prevent publication. Leak sites operated by groups whose infrastructure has since been seized or exposed - the Conti and LockBit leak sites among the most-reported - showed how professionalized this shaming has become, complete with victim directories and press-style announcements. For defenders, leak sites are a paradoxical gift. They are advertisements the criminals cannot help but publish, and they reveal targeting trends, confirm breaches victims have not yet disclosed, and occasionally surface a regulatory-disclosure obligation before the victim's own responders have finished scoping the incident. Monitoring them - through vendors, not through do-it-yourself access - is now a standard threat-intelligence function. ## Escrow, middlemen and the money layer Underpinning all of this is a settlement layer: escrow services and middlemen who hold funds while a deal completes, and laundering infrastructure that converts extortion proceeds into usable money. Marketplaces that combined trading with laundering, such as the Hydra market taken down in a joint German-US action, showed how central the money layer is. Follow-the-money analysis by blockchain-intelligence firms has repeatedly turned anonymous-seeming payments into attribution, sanctions designations and, occasionally, recovered funds. Disrupting cash-out is high-leverage, because every specialist in the chain ultimately needs to get paid. ## What this means for defenders The map above is only useful if it changes what your team does on Monday. A few concrete takeaways: - Consume intelligence, do not chase access. For nearly all organizations the right posture is to buy or share finished threat intelligence and information-sharing feeds, and to leave undercover monitoring of forums and closed channels to specialists and law enforcement. Direct access carries legal and safety risk and rarely pays off. - Shrink the attack surface IABs sell. The initial access that fuels ransomware is overwhelmingly ordinary: exposed RDP and VPN, unpatched perimeter devices, and reused or stolen credentials. Enforce phishing-resistant MFA, retire internet-facing management interfaces, patch edge appliances on an aggressive clock, and monitor for your credentials appearing in breach and combo-list data. - Treat IAB and leak-site telemetry as early warning. Rising broker demand for your sector, or a peer appearing on a leak site, is a signal to raise readiness - not a curiosity. Feed it into tabletop exercises and detection tuning. - Plan for double extortion, not just encryption. Because leak sites defeat the backups-alone strategy, your incident and disclosure plans must assume data theft. Know your regulatory clocks, and rehearse the communications and legal workflow before a countdown timer is running. - Support disruption; it compounds. Takedowns like Operation Cronos, the Hydra seizure and the RaidForums action do not permanently end criminal commerce, but they impose cost, erode trust between specialists, and generate indicators defenders can operationalize. Reporting incidents to authorities and sharing indicators feeds that machinery. The ransomware underground is not a single dark room; it is a marketplace with recurring venue types, each serving a function and each leaving a trace. Defenders win not by finding the room, but by understanding the economy well enough to raise its costs - hardening the exposures it sells, reading the signals it broadcasts, and backing the disruption that makes the whole enterprise less profitable. ## Frequently asked questions **Is the ransomware ecosystem run by a few big gangs or many specialists?** It is a division of labor, not a handful of monolithic gangs. Distinct specialists - malware developers, initial-access brokers, affiliates who run intrusions, negotiators, launderers and bulletproof-hosting providers - trade with each other across forums, affiliate portals and messaging channels. Ransomware-as-a-service turned what used to be one crew's whole workflow into an outsourced supply chain, which is why disrupting a single actor rarely ends the activity. **Should my security team try to access dark-web forums directly?** For almost every organization, no. Direct access carries legal, operational-security and safety risks, and most defenders do not need it. The practical path is to consume finished intelligence from reputable vendors and information-sharing communities, and to focus internal effort on the exposures those venues reveal - leaked credentials, brokered access to your sector, and your own name appearing on a leak site. Leave undercover access to specialized teams and law enforcement. **What is an initial-access broker and why should a CISO care?** An initial-access broker (IAB) is a criminal specialist who breaks into organizations and sells that foothold - valid VPN or RDP credentials, a web-shell, or access to a compromised device - to whoever will pay, frequently a ransomware affiliate. IABs matter because they compress the time between a phishing click or an unpatched edge device and a full ransomware event. Watching how access is priced and advertised is an early-warning signal that your sector, or your company, is being targeted. **Why do ransomware groups run public data-leak sites at all?** Leak sites are the enforcement arm of double extortion. By publishing a countdown and samples of stolen data, the group pressures the victim to pay even when backups make decryption unnecessary. For defenders those same sites are an intelligence source: they reveal which sectors are being hit, confirm breaches victims have not yet disclosed, and sometimes surface regulatory-disclosure obligations before the victim's own incident response has caught up. **Do law-enforcement takedowns actually work if crews just rebrand?** Rebranding happens, but takedowns still impose real cost. Operations against marketplaces, forums and ransomware infrastructure have seized servers, recovered decryption keys, exposed affiliates and eroded the trust that criminal commerce depends on. Each disruption forces re-tooling, burns reputations built over years, and produces indicators and intelligence defenders can act on. The goal is sustained friction, not a single permanent knockout.