Zestix
Zestix emerged as a distinct entity in late 2024-early 2025, but its activities link to Sentap operations that have been ongoing since 2021.
Zestix emerged as a distinct entity in late 2024-early 2025, but its activities link to Sentap operations that have been ongoing since 2021.
BlackShrantac ransomware group is a new and sparsely documented threat actor, believed to have emerged in 2025. Indicators suggest it is part of the ongoing wave of short-lived or rebranded ransomware operations that often appear as law-enforcement pressure disrupts established groups.
BlackShrantac follows the now-standard double extortion model, encrypting victim systems while threatening to leak stolen data if the victim does not meet ransom demands. To that end, targets appear to be small to mid-sized organizations. Attacks focus on maximizing operational disruption rather than long-term persistence.
Warlock is a newly emerged, highly aggressive Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-2025. It is known for its rapid expansion and use of sophisticated tactics, often targeting high-profile entities globally.
Warlock affiliates have been closely linked to exploiting zero-day vulnerabilities in public-facing enterprise applications, most notably the “ToolShell” exploit chain in unpatched Microsoft SharePoint servers, which allows for initial compromise and remote code execution.
Warlock activity has been tied to the China-based threat actor tracked by Microsoft as Storm-2603 (also known as GOLD SALEM).
Research indicates Warlock payload may be a modified variant of other well-known ransomware, such as LockBit 3.0 or a rebrand of a payload named Anylock, which is common in the fluid RaaS ecosystem.
[developing]
Blue Locker ransomware demonstrates sophisticated technical capabilities, utilizing a combination of AES and RSA encryption algorithms while deliberately avoiding system-critical files to maintain persistence.
Blue Locker operates through a PowerShell-based loader that disables security defenses, escalates privileges, and appends “.blue” or “.bulock16” extensions to encrypted files.
The malware’s advanced evasion techniques include obfuscation of target strings, such as disguising “Chrome.exe” as Chinese characters to bypass detection systems.
The Anubis group is a Ransomware-as-a-Service (RaaS) operation that emerged in late 2024 and gained significant visibility in 2025. Anubis attracts affiliates with flexible revenue splits. They also run a separate data extortion program for criminals who have already stolen data.
Anubis is notable for combining traditional file encryption with an optional file-wiping feature (activated via a /WIPEMODE parameter). This feature permanently erases file contents, making recovery impossible, even after a ransom is paid. This is an unusual and destructive tactic for a financially motivated group, serving to increase pressure on victims to pay for data not to be leaked, even if files cannot be decrypted.
Initial Access is typically achieved through spear-phishing emails containing malicious links or attachments, crafted to look like trusted communications.