Key Takeaways

  • Michael DeBolt argued at Black Hat USA 2026 that defenders should track ransomware operators and behaviors rather than group brands.
  • Ransomware-as-a-Service models let affiliates, developers, and infrastructure providers regroup quickly after disruption.
  • Enterprises can build more durable threat hunts by mapping recurring techniques through MITRE ATT&CK and NIST CSF.

Ransomware groups can close a leak site, abandon a name, and emerge under a different identity without substantially changing the people or methods behind the operation. At Black Hat USA 2026, Intel 471 Chief Intelligence Officer Michael DeBolt argued that enterprise defenders should focus less on those shifting brands and more on the operators, relationships, and recurring behaviors underneath them.

The distinction matters because ransomware branding is relatively disposable. A recognizable name can become a liability after a law enforcement action, public dispute, failed attack, or embarrassing infrastructure compromise. Replacing it with a fresh logo and leak site may create the appearance of a new threat, even when developers, affiliates, access brokers, and laundering channels remain connected to an earlier operation.

DeBolt’s recommendation is to construct threat hunts around observable behavior. Operators often carry preferred techniques into their next campaign, including familiar approaches to initial access, credential theft, lateral movement, data exfiltration, and extortion. Those patterns may survive longer than domains, malware hashes, cryptocurrency wallets, or public-facing identities.

That approach is consistent with the broader threat picture. The ENISA Threat Landscape 2023 identified ransomware as one of Europe’s leading cyber threats and discussed the prominence of families including LockBit, Conti, and ALPHV/BlackCat. Such labels remain useful for organizing intelligence, but they can also obscure the movement of personnel and capabilities between operations.

Ransomware-as-a-Service makes those boundaries even fuzzier. Core operators can maintain malware, payment systems, negotiation processes, and leak infrastructure while affiliates conduct intrusions. Affiliates, in turn, can move between programs. CISA reported in 2023 that LockBit was the most widely deployed ransomware variant globally in 2022 and remained highly prolific in 2023. Its affiliate model illustrates why dismantling one public brand may not remove the surrounding labor pool.

Cybercrime increasingly resembles a commercial ecosystem, albeit an illicit one. Initial-access brokers sell footholds. Hosting providers support infrastructure. Marketplaces connect buyers and sellers. Developers update tooling, while negotiators and money-laundering services handle later stages. The “deep and dark web” label can make this environment sound mysterious and shapeless. DeBolt’s framing instead treats it as a structured market whose participants develop reputations and repeat recognizable activities.

The Rhysida operation offers another example of how this structure works. A joint CISA and MS-ISAC advisory described Rhysida as a Ransomware-as-a-Service operation using a targets-of-opportunity model and revenue sharing between core operators and affiliates. Its targeting across education, healthcare, manufacturing, IT, and government demonstrates how a shared criminal platform can support campaigns spanning very different industries.

To adapt, intelligence programs can preserve links between aliases rather than treating every new name as a clean slate. Analysts can compare infrastructure, malware development choices, recruitment language, victimology, working hours, negotiation styles, and affiliate relationships. Attribution will still contain uncertainty, but confidence levels can be documented rather than hidden behind a single group label.

Additionally, detection engineering can map repeated tactics and techniques to MITRE ATT&CK. A hunt for credential dumping, remote-service abuse, unusual administrative tooling, or staged exfiltration remains useful even after an operator changes malware. NIST CSF 2.0 can provide the broader governance structure, connecting threat intelligence with protective controls, detection, response, and recovery planning.

There is a practical caution here. Behavioral overlap does not automatically prove that two ransomware brands share the same operators. Common tools and copied playbooks are widespread. Intel 471’s operator-centered model is therefore less about declaring perfect attribution and more about building defensive hypotheses that survive branding changes.

For CISOs, the business implication is straightforward: a group’s disappearance should not automatically be counted as risk reduction. The durable unit of analysis is often the ecosystem behind the name. Tracking that ecosystem can help enterprises retain useful intelligence, prioritize recurring attack paths, and avoid starting from zero whenever ransomware operators unveil another identity.