Inside the Shadows Tracking RaaS Groups, Cyber Threats
John Dilgen (Cyber Threat Intelligence Analyst · Reliquest)
Recon Village @ DEF CON 33 · Day 1 · Recon Village
Overview
Ransomware-as-a-Service (RaaS) groups represent one of the most persistent and costly threats in the modern cybersecurity landscape. John Dilgen, a Cyber Threat Intelligence (CTI) Analyst at Reliquest, delivered a compelling talk at Recon Village, "Inside the Shadows: Tracking RaaS Groups, Cyber Threats," shedding light on the intricate world of these prolific cybercriminal enterprises. The presentation underscored the staggering financial impact of ransomware, estimated at $124 billion annually in the United States alone, and highlighted the critical need for organizations to understand the evolving tactics, techniques, and procedures (TTPs) of these adversaries.

Key moments
- 0:00 Introduction to RaaS tracking and ransomware's impact
- 2:00 Overview of dark web and intelligence data sources
- 2:40 Extracting insights from RaaS internal communication leaks
- 3:10 Introduction to Black Basta RaaS group and TTPs
- 4:00 Details on Black Basta chat logs and reasons for leak
- 5:30 Identifying Black Basta's leader and key members
- 7:00 Black Basta's defined organizational roles and structure
Inside the Shadows Tracking RaaS Groups, Cyber Threats
Speakers: John Dilgen, Cyber Threat Intelligence Analyst, Reliquest
Conference: Recon Village
YouTube: https://www.youtube.com/watch?v=esKyHO5jPU
Overview
Ransomware-as-a-Service (RaaS) groups represent one of the most persistent and costly threats in the modern cybersecurity landscape. John Dilgen, a Cyber Threat Intelligence (CTI) Analyst at Reliquest, delivered a compelling talk at Recon Village, "Inside the Shadows: Tracking RaaS Groups, Cyber Threats," shedding light on the intricate world of these prolific cybercriminal enterprises. The presentation underscored the staggering financial impact of ransomware, estimated at $124 billion annually in the United States alone, and highlighted the critical need for organizations to understand the evolving tactics, techniques, and procedures (TTPs) of these adversaries.
Dilgen's research, conducted by the Reliquest team, delved into various data collection sources, from dark web forums and data leak sites to internal communication leaks and incident telemetry. The core objective was to demonstrate how granular intelligence about RaaS groups can be operationalized to build a robust, proactive defense. By meticulously analyzing the inner workings of groups like Black Basta, LockBit, and Dragon Force, the talk provided a unique perspective on their organizational structures, recruitment strategies, inter-group collaborations, and the dynamic evolution of their attack methodologies.
The talk emphasized that effective defense against RaaS is not merely about reactive incident response but about anticipating and understanding the adversary. It challenged the common "tunnel vision" approach in CTI, advocating for a broader view that accounts for affiliate movement, group rebranding, and the diverse TTPs employed. Dilgen's insights offered actionable intelligence for defenders, from identifying specific social engineering lures to implementing advanced threat hunting techniques and hardening help desk verification procedures against sophisticated impersonation attacks.
Background
▶ Watch: Introduction to RaaS tracking and ransomware's impact (0:00)
The proliferation of RaaS models has democratized ransomware attacks, allowing individuals with varying technical skills to participate in highly profitable cybercriminal operations. This ecosystem thrives on the dark web, where RaaS operators advertise their services, recruit affiliates, and exfiltrate data from compromised organizations. The fundamental problem for defenders lies in gaining sufficient visibility into these clandestine operations to develop effective countermeasures.
Historically, intelligence gathering on RaaS groups has been challenging due to their anonymity, use of encrypted communications, and transient nature. However, certain events have provided invaluable insights. Data leak sites, hosted on Tor (onion sites), serve as public extortion platforms where RaaS groups list their victims and threaten to publish stolen data. Cybercriminal forums are crucial for recruitment, tool sharing, and technical discussions. Beyond these public-facing aspects, internal communication leaks – often from disgruntled members or law enforcement actions – have become goldmines for CTI analysts, revealing aliases, organizational structures, and detailed TTPs. Finally, post-incident attack analysis pieces, whether internal or external, provide crucial telemetry on Indicators of Compromise (IoCs) and TTPs observed in real-world attacks.
Prior work in the field has often focused on attributing specific attacks to particular groups or tracking the evolution of ransomware strains. However, Dilgen's talk expanded on this by emphasizing the fluidity of the RaaS landscape. Groups disband and rebrand, affiliates migrate between different operations, and TTPs are constantly adapted, shared, and refined. This dynamic environment necessitates a comprehensive approach to intelligence that goes beyond static attribution, focusing instead on understanding the underlying criminal infrastructure, shared capabilities, and human elements driving these threats. The talk built upon the understanding that RaaS groups, despite their illicit nature, often mirror legitimate businesses in their organizational complexity and operational efficiency.
Key Findings
▶ Watch: Extracting insights from RaaS internal communication leaks (2:40)
The Reliquest research unveiled several critical findings regarding RaaS operations and the broader cyber threat landscape:
- Communication Leaks as a Strategic Intelligence Source: Internal chat logs, such as those from Black Basta (February 2025) and its predecessor Conti, provide unparalleled insight into group structure, TTPs, and inter-group dynamics. These leaks often occur due to internal disagreements, such as Black Basta members' unhappiness with targeting Russian banks, mirroring Conti's split over the Russia-Ukraine war.
- Sophisticated Organizational Structures: RaaS groups like Black Basta operate with a defined, almost corporate-like structure, including roles such as intrusion specialists, managers, ransomware developers, botnet operators, infrastructure management, and even R&D departments focused on EDR evasion. This level of organization allows for efficient, scalable operations.
- Inter-Group Collaboration and Affiliate Mobility: The research highlighted significant collaboration and affiliate movement across RaaS groups. For example, Black Basta’s leader, Trump, communicated extensively with Quackbot's leader, Cortez, likely for malware integration. Furthermore, Black Basta senior member Tinkerer simultaneously worked as an affiliate for Black Suit (aka Royal Ransomware). This fluidity means TTPs are not exclusive to one group and can quickly propagate, underscoring the need for "defense in depth" rather than "tunnel vision" on specific threat actors.
- Diverse and Evolving TTPs: Black Basta's arsenal included a wide range of tools for reconnaissance (ZoomInfo, Shodan, Intelligence X), initial access (email spam bomb, Teams phishing, brute forcing, purchasing pre-compromised credentials), malware (ICE ID, Pikabot, Quackbot), and exfiltration (RC clone, Win SCP, FileZilla, Curl). This adaptability allows them to maneuver against defenses and change tactics mid-attack or across campaigns.
- Impact of Law Enforcement Actions: The February 2024 takedown of LockBit's infrastructure initially showed minimal immediate impact, with a subsequent surge in activity in May (nearly 150 organizations named). However, LockBit's volume consistently fell thereafter, suggesting a lasting effect, though the exact cause (infrastructure loss vs. affiliate flight) remains unclear. Even a teased LockBit 4.0 release in December 2024 failed to restore their previous market dominance.
- Aggressive Recruitment and Brand Warfare: Dragon Force, first observed in December 2023, employs a unique cartel model allowing other groups to use their infrastructure with their own branding. They engage in aggressive, verbose recruiting campaigns, emphasizing workflow automation and offering comprehensive software (e.g., for ESSI NAS, BDSD). Notably, Dragon Force actively defaced data leak sites of rivals like RansomHub (a top group in Q4 2024) and Blacklock, attempting to poach affiliates and leak sensitive information (e.g., Blacklock's ETC password file and chat logs). These tactics led to a significant spike in Dragon Force's activity in April, demonstrating their success in attracting new affiliates.
- Continuous TTP Evolution in Social Engineering: Investigations into email spam bomb and Teams phishing incidents revealed a rapid evolution of social engineering TTPs. From simple Teams/VoIP phishing in April 2024 to QR code-based phishing (October 2024), Teams meetings with actor control (January 2025), and increasingly sophisticated persistence mechanisms like QEMU hypervisor (February 2025), type live hijacking (March 2025), and SSH tunneling (April 2025), threat actors are constantly refining their methods. The use of Microsoft.com domains to establish legitimacy and impersonate IT support is a recurring theme.
- Help Desk as a Critical Vulnerability: The Scattered Spider kill chain demonstrated the extreme danger of insufficient help desk verification. By impersonating a CFO, threat actors successfully manipulated the help desk into resetting credentials and MFA, ultimately compromising Octa and Thycotic identity management tenants, dumping credentials, exfiltrating data, and deploying the RansomHub encryptor.
Technical Deep Dive
▶ Watch: Introduction to Black Basta RaaS group and TTPs (3:10)
The technical depth of RaaS operations, as revealed by Dilgen, spans sophisticated reconnaissance, multi-stage initial access, diverse malware deployment, and advanced persistence techniques.
Black Basta's Operational Playbook:
Black Basta, a prominent RaaS group, showcased a highly adaptable operational playbook:
- Reconnaissance: They utilized legitimate tools to gather intelligence. ZoomInfo was employed to research victim organizations' revenue data, likely to gauge potential ransom payment capacity. Shodan was used to identify exposed ports and services, revealing publicly available technologies and potential vulnerabilities. Intelligence X assisted in looking up company and employee details, crucial for crafting targeted social engineering campaigns.
- Initial Access: Their signature method was the email spam bomb, flooding a target's inbox with hundreds of emails to render it unusable. This created an opening for Teams phishing, where attackers, posing as IT help desk, would contact the overwhelmed user to execute malicious code or join a remote session. Beyond this, they engaged in generic brute forcing and frequently purchased pre-compromised credentials from initial access brokers on the dark web.
- Malware Deployment: Black Basta leveraged a variety of malware loaders and Trojans, including ICE ID, Pikabot, and Quackbot, to establish persistence and facilitate further malicious activity.
- Exfiltration: For data exfiltration, they relied on common tools like RC clone, Win SCP, FileZilla, and Curl, demonstrating a preference for readily available and often legitimate utilities to blend in with normal network traffic.
Dark Web Intelligence and TTP Recreation:
The dark web provided a window into the tools and services that underpin RaaS operations:
- Email Spam Bomb as a Service: Dilgen highlighted services offering email spam bombs for as little as $9 per bomb or $500 for lifetime access. These services claimed capabilities of sending up to 100,000 emails per day, underscoring the low cost and high volume of this initial access vector.
- Forum Activity: Black Basta's leaked chat logs contained nearly 100 links to cybercriminal forums, primarily XSS (which was later taken down) and Exploit. These forums served as knowledge-sharing platforms.
- Identifying Affiliates: By tracking user profiles linked in Black Basta's chats, Reliquest identified potential initial access affiliates. For instance, a user named "IT workers" sought access to partner.microsoft.com accounts and remote access Trojan (RAT) source code, later focusing on attacker-in-the-middle (AiTM) campaigns for Google account token capture. Another user, "code seller," specialized in search engine optimization (SEO) poisoning to drive traffic to malicious sites and sought help to build an encryptor for the SmokeLoader malware. These findings illustrate the specialization within the RaaS ecosystem.
Evolution of TTPs in Real-World Incidents:
Reliquest's incident analysis revealed a rapid and continuous evolution of TTPs, even after Black Basta's purported disbandment:
- April 2024: Initial incidents involved email spam bombs combined with Teams phishing or Voice over IP (VoIP) phishing.
- October 2024: TTPs advanced to using Teams chats with embedded QR codes for phishing.
- January 2025: Attackers shifted to initiating Teams meetings and gaining control of the host. The source of phishing consistently originated from easily spun-up Microsoft.com domains, lending legitimacy to social engineering attempts. DLL sideloading emerged as a method for lateral movement and privilege escalation.
- February 2025: Persistence techniques evolved to include the use of the QEMU hypervisor.
- March 2025: Further persistence was achieved via type live hijacking, with Telegram beaconing used for C2 (command and control) communications.
- April 2025: The latest evolution incorporated SSH tunneling for C2 and data exfiltration.
This timeline clearly shows that initial access TTPs (like the email spam bomb) persist and are adopted by other groups (e.g., 3:00 AM Ransomware and FIN7), while post-exploitation TTPs continuously mature.
Scattered Spider Kill Chain – The Human Element:
The investigation into a Scattered Spider attack on a manufacturing sector customer highlighted the critical role of human vulnerabilities:
- VIP Impersonation: The threat actor called the help desk, impersonating the organization's CFO.
- Credential Reset: The help desk, failing to follow strict verification procedures, reset the CFO's credentials, granting the attacker initial access.
- MFA Bypass: Confronted with MFA, the attacker made a second call, convincing the help desk to reset the CFO's MFA, allowing them to pair their own device.
- Reconnaissance & Escalation: The attacker performed reconnaissance, realizing the CFO's account lacked access to sensitive data. They identified a domain admin account.
- Domain Admin Compromise: A third impersonation call to the help desk led to the domain admin's credentials being reset.
- Identity System Compromise: Octa and Thycotic (identity management tenants) were compromised.
- Post-Exploitation: Credentials were dumped, sensitive data was exfiltrated, and the RansomHub encryptor was deployed.
This kill chain exemplifies how social engineering, combined with lax security procedures, can lead to complete organizational compromise, even against sophisticated technical controls.
Demo / Proof of Concept
▶ Watch: Identifying Black Basta's leader and key members (5:30)
The talk did not include a live demonstration or a proof of concept. Instead, John Dilgen's presentation was a comprehensive analysis based on extensive threat intelligence research and incident investigations conducted by the Reliquest team. The insights shared were derived from real-world data, including leaked chat logs, dark web forum monitoring, and detailed post-incident forensic analysis, rather than a simulated attack or tool showcase.
Defensive Implications
▶ Watch: Black Basta's defined organizational roles and structure (7:00)
The detailed intelligence on RaaS groups and their evolving TTPs provides a critical foundation for building a proactive and resilient defense. Defenders must move beyond reactive measures and implement strategies that address the full lifecycle of a ransomware attack, from initial access to data exfiltration and encryption.
- Implement Strict Help Desk Verification Procedures: This is paramount. Organizations must enforce two-way verification – users must be able to verify they are speaking with the legitimate help desk (to counter phishing attempts like Black Basta's IT impersonation), and the help desk must stringently verify the identity of callers (to prevent VIP impersonation as seen with Scattered Spider). This includes multi-factor authentication for help desk access and verification processes.
- Audit Help Desk Processes Regularly: Help desk verification procedures should be a priority target in red team testing. This is especially crucial for organizations utilizing third-party help desks, as these can be a significant weak point, as highlighted by recent Scattered Spider attacks in the UK. Regular audits ensure adherence to protocols and identify vulnerabilities.
- Comprehensive User Education on Social Engineering: Users must be continuously educated about the latest social engineering tactics, particularly Teams phishing, vishing (voice phishing), and the email spam bomb. Education should include specific instructions on what to do when targeted by an email spam bomb, emphasizing not to respond to unsolicited IT support requests or click suspicious links. Organizations with clear documentation on handling such incidents have successfully stopped attacks in their tracks.
- Disable Unauthorized Remote Monitoring and Management (RMM) Tools: Proactively disable or restrict the use of unauthorized RMM tools through Group Policy Objects (GPOs) or application control mechanisms. Threat actors frequently abuse legitimate RMM tools for persistence and remote access.
- Enhance Threat Hunting and Detection Capabilities: Based on the observed TTPs, specific threat hunts and detections can be developed:
- Microsoft Teams Log Monitoring: Create detections for
chat createdevents where thechat name includes help desk or it. This can flag suspicious impersonation attempts. - File Download/Execution Monitoring: Monitor proxy logs or Windows event logs for
file downloadorfile executedevents where thefile name contains filter or anti-spam. These filenames are common lures used by attackers posing as IT support to deliver malicious payloads after an email spam bomb. - Behavioral Detections: Focus on detecting anomalous behavior, such as rapid changes in user MFA settings, new device enrollments for highly privileged accounts, or unusual RDP/VPN connections.
- Adopt a "Defense in Depth" Strategy: Given the diverse TTPs, constant evolution, and affiliate movement across RaaS groups, a holistic defense is critical. Avoid "tunnel vision" on specific threat actor groups or their attributed TTPs. Instead, implement layered security controls that can mitigate a broad spectrum of attack vectors and adapt to new threats. This includes strong network segmentation, endpoint detection and response (EDR), identity and access management (IAM), and robust backup and recovery solutions.
- Monitor Dark Web and Communication Channels: Leverage threat intelligence to monitor cybercriminal forums and data leak sites. Understanding the tools being advertised (e.g., email spam bomb as a service), recruitment drives, and inter-group drama provides early warnings of emerging TTPs and potential shifts in the threat landscape.
Key Takeaways
- RaaS is a Highly Organized and Adaptive Threat: Ransomware-as-a-Service groups operate with sophisticated organizational structures, often mirroring legitimate businesses, and constantly adapt their TTPs to bypass defenses.
- Intelligence from Leaks and Forums is Gold: Internal communication leaks (like Black Basta's) and dark web forum activity offer invaluable, granular intelligence on group members, TTPs, collaborations, and affiliate movements.
- Affiliate Mobility Drives TTP Proliferation: Affiliates frequently move between RaaS groups, leading to the rapid sharing and adoption of successful TTPs across the cybercriminal ecosystem, necessitating a broad, defense-in-depth approach.
- Social Engineering Remains a Primary Attack Vector: Sophisticated social engineering techniques, including email spam bombs, Teams phishing, and VIP impersonation targeting help desks, are consistently effective initial access methods.
- Proactive Defense Requires Continuous TTP Tracking: Understanding the chronological evolution of attack TTPs (e.g., from simple Teams phishing to QEMU persistence and SSH tunneling) is crucial for building effective detections and hardening defenses.
- Help Desk Security and User Education are Critical: Implementing strict help desk verification, conducting regular red team audits, and providing comprehensive user education on social engineering are fundamental to preventing initial compromise.
About the Speaker(s)
John Dilgen is a Cyber Threat Intelligence Analyst at Reliquest. He specializes in tracking ransomware-as-a-service groups and analyzing evolving cyber threats. Dilgen regularly contributes to Reliquest's threat research and is a frequent guest on their "Shadow Talk" podcast, where he and other team members deep dive into various cybersecurity threats and intelligence findings. His work focuses on leveraging diverse data sources to build proactive defenses against sophisticated cyber adversaries.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent threat intel survey on RaaS groups with some genuine operational detail — the Black Basta TTP timeline and Scattered Spider kill chain are legitimately useful for defenders. But this is aggregation work, not original research, and it sits comfortably in the 'well-organized blog post' tier rather than the 'conference session that changes how you think' tier.
Heather Calloway (CISO) — SOLID
Dilgen delivers competent, well-sourced threat intelligence on RaaS ecosystems — the TTP timeline, affiliate mobility analysis, and Scattered Spider kill chain are genuinely useful for CTI teams and SOC leads. But the talk stays in analyst territory and never makes the governance leap: who owns the institutional failures this research exposes, and what should an executive or board actually change as a result.