The Observatory / Document Library / Framework Case Studies
EDP Corpus · Document 12

Framework Case Studies

RANSOMWARE ECOSYSTEM

DISRUPTION FRAMEWORK

Corpus documentDoc 12

Historical Case Studies: KPI Framework Applied

Version 1.1 | June 2026 | Working Document | v1.1: WAIS values superseded by Doc 13 back-test; Black Basta outcomes resolved

Developed by Reno

PURPOSE AND HOW TO USE THIS DOCUMENT

This document applies the Ransomware Ecosystem Disruption Measurement Framework retrospectively to five significant real-world operations and events. The purpose is threefold.

IMPORTANT SCOPE NOTE All analysis in this document draws exclusively on open-source reporting, public law enforcement disclosures, and blockchain forensics published by firms including Chainalysis and TRM Labs. No classified or law enforcement-sensitive material is incorporated. Confidence labels reflect the quality of available open-source evidence, not the totality of what may be known through other channels.

Each case study is structured identically: background, ecosystem role, framework layer analysis (macro/meso/micro), WAIS score where applicable, strife indicators observed, and key lessons for future operations.

Cases are presented in chronological order. The Conti case is the most thoroughly documented and serves as the primary calibration reference for the WAIS scoring system.

CASE STUDY 1 | CONTI COLLAPSE (2022)

Type: Internal Collapse triggered by External Leak | Date: February 2022 (leak) through mid-2022 (dissolution)

Background

Conti was among the most prolific and operationally sophisticated ransomware groups in documented history. Operating as a closed hierarchical RaaS with employed operators rather than independent affiliates, Conti was responsible for hundreds of confirmed attacks including multiple critical infrastructure incidents. At peak operation the group functioned as a structured criminal enterprise with departments, salaries, HR processes, and management hierarchy.

In February 2022, following Conti leadership's public statement of support for Russia's invasion of Ukraine, a disgruntled Ukrainian-affiliated member leaked approximately 60,000 internal chat messages, source code, and operational files. The leak exposed the group's internal structure, financial flows, personnel, infrastructure, and protection relationships in unprecedented detail.

Ecosystem Role at Time of Collapse

DimensionAssessment
Node CriticalityTier 1. Conti represented a non-substitutable brand at scale. Its closed operator model, established affiliate relationships, and infrastructure investment made it among the highest-replacement-difficulty actors in the ecosystem.
Revenue ShareEstimated 20-25% of total ransomware ecosystem revenue at peak operation, based on Chainalysis blockchain analysis of attributed wallet clusters.
Protection Layer StatusActive krysha relationship assessed. Internal chat logs surfaced in the leak referenced FSB contacts and protection payments. Relationship status post-leak: assessed as Strained then Broken as exposure became public.
Operational ModelClosed hierarchical group with employed operators. Approximately 100 personnel across technical, administrative, and operational functions based on leaked HR materials.

Framework Layer Analysis

Macro Layer Effects

Meso Layer Effects

NodeObserved Effect
Node 07: Underground Trust InfrastructureSevere disruption. The leak exposed financial records, personnel identity, and internal dispute resolution processes. Forum trust in Conti-linked actors collapsed. Multiple former members reported being unable to establish new working relationships due to exposure risk.
Node 01: OTC BrokersPartial disruption. Blockchain analysis identified several OTC nodes serving Conti. Post-collapse, fund flows through those nodes dropped. Some brokers subsequently served successor brands.
Node 04: IAB MarketsModerate disruption. Conti's internal access sourcing model partially displaced IAB demand. Post-collapse, former Conti affiliates re-entered IAB markets as buyers, increasing demand temporarily.
Node 09: Mule NetworksLimited observable disruption. Laundering infrastructure for Conti proceeds largely persisted through successor relationships.

Micro Layer: Strife Event Log Entry

FieldContent
Event TypeLEAK
Source ReliabilityCONFIRMED (60,000+ messages independently verified by multiple security researchers and journalists)
Actors InvolvedConti core leadership, approximately 100 operational personnel. FSB contact references surfaced. Specific officer identities not confirmed in open source.
Ecosystem Effect AssessmentBrand collapse within 90 days. Leadership vacuum filled by splinter brands. Trust breakdown across former affiliate and partner network. Protection relationship assessed as severed.
Causal Link to Pressure ActionsThe leak was triggered by Conti leadership's political statement (Ukraine support declaration), not by a Western pressure action. External cause, but the cascading effects are consistent with what targeted exposure operations aim to produce.
Follow-On Indicators ObservedBlack Basta emerged within 60 days of Conti dissolution, staffed by confirmed former Conti operators. Royal, Quantum, and BlackByte similarly incorporated former Conti personnel. Conti infrastructure was partially reused in successor operations before being abandoned.

Strife Proxy Metrics Observed

MetricObserved ValueSignal
Affiliate Defection RateNear-total dissolution within 90 daysMaximum signal. Full fragmentation.
New RaaS Brand Emergence5+ confirmed successor brands within 90 daysHighest fragmentation rate in documented ecosystem history.
Forum Dispute VolumeSignificant spike in Exploit/XSS dispute threads involving Conti-linked handles in Q1-Q2 2022Trust breakdown confirmed across multiple forum sources.
Exit Scam FrequencyNot applicable. Dissolution was involuntary, not admin-driven wallet exit.N/A
Recruitment Term ShiftsSuccessor brands offered improved affiliate splits (80/20 vs Conti's 70/30) in recruitment advertisingInternal pressure to attract displaced Conti affiliates confirmed.
WAIS-D EVENT SCORE (Doc 13): ex-ante 9 of 9 (Node Criticality 3 / Intelligence Yield 3 / Trust Cascade 3); outcome Reconstitution Impact 3, brand dissolved. Not WAIS-eligible: no arrest. Supersedes prior in-text WAIS value per Doc 13 back-test, 2026-06-12. Node Criticality: 3/3 Non-substitutable core team. Tier 1 actor. Cooperation Output: N/A No arrest. Not applicable. Trust Cascade Effect: 3/3 Broad cascade. Full ecosystem-level trust disruption documented. Reconstitution Impact: 3/3 Brand failed to reconstitute. Successor brands operating at fraction of prior capacity individually. Note: WAIS is an arrest-scoring instrument. This case is scored on available dimensions to calibrate the Trust Cascade and Reconstitution Impact descriptors. Node Criticality and Cooperation Output require an arrest event to score fully.

Key Lessons for Framework Application

CASE STUDY 2 | QAKBOT TAKEDOWN: OPERATION DUCK HUNT (August 2023)

Type: Law Enforcement Takedown (Sinkhole and Infrastructure Seizure) | Date: August 2023

Background

QakBot (also known as Qbot and Pinkslipbot) was one of the most widely deployed malware loader ecosystems in operation, with an infection history spanning over 15 years. By 2023 it had become a primary delivery mechanism for ransomware payloads, having delivered Black Basta, Conti successor variants, and multiple other RaaS operations to victim networks at scale.

Operation Duck Hunt, executed by the FBI in coordination with international partners in August 2023, sinkholed QakBot's C2 infrastructure and pushed a removal tool to approximately 700,000 infected hosts. The operation represented the reference model for botnet/loader disruption and is cited explicitly in the framework's Node 05 playbook.

Ecosystem Role at Time of Takedown

DimensionAssessment
NodeNode 05: Botnet/Loaders. Primary delivery mechanism for ransomware payloads at mass scale.
Infected Host CountApproximately 700,000 confirmed at time of sinkhole, per FBI disclosure.
RaaS CustomersBlack Basta, Royal, and multiple other active RaaS groups confirmed as primary customers of QakBot-delivered access.
Replace DifficultyHIGH. QakBot represented 15+ years of infrastructure investment: spam networks, crypter relationships, C2 hierarchies, and affiliate distribution agreements.
Protection LayerNo confirmed Russian state protection relationship. QakBot operators assessed as criminal service providers without direct FSB krysha.

Framework Layer Analysis

Macro Layer Effects

Meso Layer Effects

NodeObserved Effect
Node 05: Botnet/LoadersFull disruption at time of sinkhole. 700,000 infected hosts severed from C2. Distribution infrastructure dismantled simultaneously. This is a CONFIRMED high-impact node-level disruption.
Node 03: BPHPartial compounding effect. QakBot C2 servers had used a mix of BPH and legitimate VPS. BPH pressure was not applied simultaneously, limiting sustained disruption.
Node 04: IAB MarketsTemporary price spike in IAB listings observed in 30-60 day window post-takedown as ransomware affiliates sought alternative access sources. Consistent with framework prediction.
ReconstitutionQakBot operators began rebuilding infrastructure within approximately 6 months. By mid-2024, QakBot-attributed activity was observed at reduced but significant scale. Full reconstitution to prior capacity not confirmed.

Reconstitution Tracking (Node 05 Reference Model)

TimeframeStatusDetail
0-30 daysFull disruptionAll C2 connectivity severed. 700,000 hosts cleaned via sinkhole removal tool. No observed QakBot-attributed activity.
31-90 daysRebuilding detectedNew QakBot infrastructure identified by security researchers. Smaller scale, new C2 architecture, modified malware variants.
90-180 daysPartial reconstitutionQakBot activity at estimated 30-40% of prior volume. Ransomware customer relationships partially restored.
180+ daysOngoing reduced capacityQakBot not restored to pre-takedown operational scale as of available reporting. Successor loaders (Pikabot, DanaBot variants) filled partial gap. Update 2026: DOJ indicted operator Rustam Gallyamov on 22 May 2025 with more than 24 million USD in forfeiture actions; QakBot did not rebuild and actors pivoted to social-engineering campaigns, resolving the reconstitution question toward durable degradation.
WAIS-D EVENT SCORE (Doc 13): ex-ante 6 of 9 (Node Criticality 3 / Intelligence Yield 2 / Trust Cascade 1); outcome Reconstitution Impact 2, partial reconstitution. Not WAIS-eligible: no arrests at time of action. Supersedes prior in-text WAIS value per Doc 13 back-test, 2026-06-12. Node Criticality: 3/3 Non-substitutable at scale. 15+ year infrastructure, mass delivery capacity. Cooperation Output: 2/3 Infrastructure seizure yielded significant technical intelligence. No confirmed arrests of operators with full cooperation. Trust Cascade Effect: 2/3 Localized disruption to QakBot customer groups. No broad ecosystem-level trust cascade observed. Reconstitution Impact: 2/3 Partial reconstitution at reduced capacity within 90-180 days. Did not reach prior operational scale. The +2 coordination bonus does not apply as this was a single-operation action rather than a multi-arrest coordinated takedown.

Key Lessons for Framework Application

CASE STUDY 3 | LOCKBIT: OPERATION CRONOS (February 2024)

Type: Coordinated Law Enforcement Takedown with Arrests | Date: February 2024

Background

LockBit was the dominant RaaS franchise in the ecosystem at the time of Operation Cronos, accounting for an estimated 25-30% of all publicly claimed ransomware attacks in 2023 based on leak site data. It operated as a franchise model with a large affiliate roster, aggressive recruitment, and the highest public profile of any active group.

Operation Cronos, coordinated by the NCA with FBI, Europol, and multiple national law enforcement agencies, seized LockBit's infrastructure, took control of its leak site (publishing law enforcement content in place of victim data), arrested two LockBit-affiliated operators, and unsealed indictments against additional members including the identified administrator LockBitSupp.

Ecosystem Role at Time of Takedown

DimensionAssessment
Market PositionDominant. Estimated 25-30% of ecosystem attack volume by leak site count in 2023.
Affiliate ModelOpen franchise. Large affiliate roster with reported 100+ active affiliates at peak. Lower trust requirements than closed models.
Replace DifficultyMEDIUM-HIGH. The franchise model made the brand more substitutable than a closed group, but the infrastructure investment and affiliate network made full reconstitution non-trivial.
Protection LayerAssessed as having some protection layer relationships based on operational longevity and Russia-based operation, but lower confidence than Tier 1 actors. LockBitSupp publicly stated Russian affiliation while claiming independence.

Framework Layer Analysis

Macro Layer Effects

Meso Layer Effects

NodeObserved Effect
Node 06: Leak Site HostingFull temporary disruption. Law enforcement seizure and reuse of the leak site for operational messaging was a high-impact trust cascade action beyond simple takedown.
Node 07: Underground Trust InfrastructureSignificant disruption. Law enforcement's publication of affiliate identities, decryption keys, and internal data on the seized site created affiliate-level trust breakdown. Affiliates could not be certain what data had been compromised.
Node 04: IAB MarketsModerate disruption. LockBit affiliate purchasing patterns showed temporary reduction. Former LockBit affiliates migrated to competing franchises within 60-90 days.
Node 01: OTC BrokersLimited observable effect. LockBit's financial rails were not simultaneously disrupted.

WAIS Scoring: LockBit Operator Arrests

Two arrests were made in connection with Operation Cronos. These are scored individually.

Arrest 1: LockBit-affiliated operator, third-country arrest

WAIS (strict, per arrest, scored 2026-06-12 in Doc 13): Cronos arrests 9 MODERATE each (including coordination bonus); Panev follow-on arrest 7 MODERATE. WAIS-D event score: ex-ante 8 of 9; outcome Reconstitution Impact 2. PENDING status resolved. Node Criticality: 2/3 Mid-tier operator. Not core team. Cooperation Output: PENDING Debrief status not confirmed in open source. Trust Cascade Effect: 2/3 Localized disruption. Combined with simultaneous infrastructure action, cascade effect was elevated. Reconstitution Impact: 2/3 Partial. LockBit reconstituted under same name at reduced capacity. +2 coordination bonus applies to the operation as a whole given simultaneous infrastructure seizure.

Takedown/Relaunch Cycle Analysis

MetricValueFramework Signal
Time to relaunchApproximately 5 daysFast relaunch. High resilience. Reconstitution capacity was largely intact.
Post-relaunch posting volume (30 days)Approximately 40% of pre-operation baselinePartial degradation confirmed. Affiliate roster shrank measurably.
Post-relaunch posting volume (90 days)Approximately 65-70% of pre-operation baselinePartial reconstitution. Framework Reconstitution Impact score: 2 (partial at 31-90 days, reduced capacity). Update 2026: LockBit never regained dominance; affiliates migrated to RansomHub then Qilin, Khoroshev remains indicted and at large, and LockBit 5.0 launched in late 2025 as an active but smaller operation, so the 2024 relaunch should not be read as the endpoint.
Competitor absorption of affiliatesRansomHub emerged as primary beneficiary, rapidly growing affiliate roster post-CronosEcosystem capacity preserved but redistributed. No net reduction in ecosystem attack volume.

Key Lessons for Framework Application

CASE STUDY 4 | BLACKCAT/ALPHV: LAW ENFORCEMENT ACTION AND EXIT SCAM (December 2023, March 2024)

Type: Law Enforcement Disruption followed by Suspected Exit Scam | Dates: December 2023 (DOJ action), March 2024 (exit scam)

Background

BlackCat/ALPHV was a technically sophisticated RaaS group operating since late 2021, known for its Rust-based malware, triple extortion model (encryption, leak, and DDoS), and high-profile attacks including Change Healthcare. The DOJ disrupted BlackCat infrastructure in December 2023, obtaining a decryption key and seizing the leak site.

BlackCat regained control of the leak site briefly before the FBI re-seized it. In March 2024, following the Change Healthcare payment (reported at approximately 22 million USD), BlackCat administrators disappeared with the ransom proceeds in what was widely assessed as an exit scam against their own affiliates, with the likely intent of rebranding.

Why This Case Is Analytically Valuable

FRAMEWORK APPLICATION NOTE This case demonstrates two distinct event types occurring in sequence: a law enforcement disruption followed by an exit scam. The framework treats these as separate events in the strife event log. The law enforcement action scores as a takedown/disruption. The exit scam scores as an EXIT SCAM event type in the Layer 2 strife event log. The interaction between the two is the analytically interesting element: the law enforcement action likely accelerated the exit scam by increasing pressure on the administrators and reducing their confidence in continued operations.

Framework Layer Analysis

Event 1: DOJ Infrastructure Disruption (December 2023)

NodeEffect
Node 06: Leak Site HostingTemporary seizure. BlackCat regained control within days, demonstrating resilience of the hosting infrastructure. Takedown/Relaunch Cycle: approximately 48-72 hours. Low reconstitution cost.
Node 07: Underground TrustModerate disruption. The seizure and re-seizure back-and-forth created uncertainty among affiliates about the reliability of the operation.
MacroLimited immediate effect. BlackCat continued operations including the Change Healthcare attack post-disruption.

Event 2: Exit Scam (March 2024)

FieldContent
Event TypeEXIT SCAM
Source ReliabilityCREDIBLE. Blockchain analysis by multiple firms confirmed the Change Healthcare payment wallet and traced funds to BlackCat administrator wallets. Affiliates publicly complained on underground forums confirming non-payment.
Ecosystem EffectAffiliate trust destruction. Public affiliate complaints on Exploit and XSS confirmed non-payment of affiliate shares from Change Healthcare ransom. Brand collapsed within days of exit scam confirmation.
Causal Link to Prior PressureCREDIBLE inference. The sequence (law enforcement disruption followed by large payment followed by exit scam) is consistent with administrators taking a final large payment under pressure and exiting before reconstitution became necessary.
Follow-On IndicatorsRansomHub rapidly emerged absorbing former BlackCat affiliates. Multiple former BlackCat personnel confirmed in RansomHub operations within 60 days. Update 2026: RansomHub itself went dark on 1 April 2025 and displaced affiliates dispersed heavily to Qilin (an approximately 56 percent victim-count jump), a second-generation churn worth capturing in the framework.

Combined Effect Assessment

The two events together produced a higher ecosystem effect than either would have alone. The law enforcement disruption created instability; the exit scam destroyed the remaining trust. This is the compounding effect the framework is designed to produce through deliberate pressure: each action raises the cost of continued operation and lowers the benefit of loyalty to the brand.

Key Lessons for Framework Application

CASE STUDY 5 | BLACK BASTA LEAKS (February 2025)

Type: Internal Leak (Ongoing Event) | Date: February 2025

Background

Black Basta emerged in April 2022 as one of the most significant post-Conti successor groups, widely assessed to include former Conti operators. It operated as a closed hierarchical group with high operational security and targeted high-value victims. In February 2025, a large volume of internal Black Basta chat logs was leaked publicly, attributed to an internal dispute.

The leak exposed internal communications, operational processes, victim negotiation transcripts, and personnel information. The full downstream effects were still developing at the time this document was prepared.

Framework Layer Analysis

ANALYTICAL STATUS NOTE STATUS RESOLVED (v1.1, June 2026). This case was scored as an ongoing event when this document was prepared. Outcomes are now resolved: Black Basta posted its last victim in January 2025 and was inactive by March 2025. Members are assessed to have migrated to the existing Cactus operation rather than forming a successor brand. Leader Oleg Nefedov (Tramp) was added to the EU Most Wanted list and an Interpol Red Notice in January 2026. Final scoring in Doc 13: WAIS-D ex-ante 9 of 9, outcome Reconstitution Impact 3. The original PENDING workflow demonstrated here remains the correct model for live events.

Strife Event Log Entry

FieldContent
Event TypeLEAK
Source ReliabilityCONFIRMED. Chat logs independently verified by multiple security research organizations.
Actors InvolvedBlack Basta core operators and administrators. Conti lineage personnel confirmed. Specific individuals identifiable from logs.
Immediate Ecosystem EffectSignificant trust disruption within Black Basta affiliate and partner network. Internal disputes visible in the leaked logs themselves, indicating pre-existing strife that the leak accelerated. Victim negotiation transcripts exposed, undermining future negotiation credibility.
Causal Link to Pressure ActionsLeak attributed to internal dispute, not a Western pressure action. However, the underlying strife may reflect accumulated pressure on the group including law enforcement attention, financial friction from sanctions on associated infrastructure, and OPSEC costs.
Follow-On Indicators to Monitor (PENDING)Black Basta operational tempo post-leak. Affiliate defection rate. New brand emergence by identified personnel. Protection relationship status changes for any assessed krysha connections. Update 2026: Black Basta is assessed to have ceased operations in early 2025; on 15 January 2026 Ukrainian and German authorities raided suspected members and alleged leader Oleg Nefedov was identified, added to Europol Most Wanted under an Interpol Red Notice, and assessed to be sheltering in Russia. These PENDING fields are now answerable.

Comparison to Conti Leak

DimensionConti (2022)Black Basta (2025)
Scale of leak60,000+ messages, source code, financial recordsInternal chat logs, negotiation transcripts, operational data
TriggerPolitical statement (Ukraine support)Internal financial dispute, assessed
Pre-existing strifeModerate: political tension over Ukraine affiliationHigh: financial disputes visible within leaked content itself
90-day dissolutionYes. Brand collapsed within 90 days.Yes. Last victim Jan 2025; inactive by Mar 2025 (resolved Jun 2026).
Successor emergence5+ successor brands within 60 daysNo successor brand. Members assessed migrated to Cactus (resolved Jun 2026).
Protection layer effectAssessed as Strained to Broken post-leakPENDING as of the original assessment. Updated July 2026: protection outcome assessed as intact for alleged leader Nefedov (sheltering in Russia, no domestic action); the February 2025 leak strained operational trust but not state protection.

Key Lessons for Framework Application

SUMMARY: FRAMEWORK SCORING ACROSS ALL FIVE CASES

CasePrimary Event TypeWAIS (if applicable)Trust CascadeReconstitutionMacro Effect
Conti (2022)Internal LeakN/A strict; WAIS-D ex-ante 9 (Doc 13)3/3 Broad cascade3/3 Brand dissolvedHigh: ecosystem-wide fragmentation
QakBot (2023)Infrastructure TakedownN/A strict; WAIS-D ex-ante 6 (Doc 13)2/3 Localized2/3 Partial at 90-180 daysLimited: no macro payment effect
LockBit (2024)Coordinated Takedown plus ArrestsScored: 9 / 9 / 7 MODERATE (Doc 13)2-3/3 with coordination bonus2/3 Partial at 90 daysModerate: affiliate redistribution
BlackCat (2023-24)Takedown plus Exit ScamN/A strict; WAIS-D ex-ante 6 for Dec 2023 action (Doc 13); exit scam excluded from scoring3/3 Exit scam destroyed residual trust3/3 Brand dissolvedModerate: RansomHub absorbed capacity
Black Basta (2025)Internal Leak (resolved Jun 2026)N/A3/3 Broad cascade (resolved Jun 2026)3/3 Brand dissolved (inactive by Mar 2025)Moderate: no successor brand; members assessed migrated to Cactus (resolved Jun 2026, Doc 13)
CALIBRATION TAKEAWAY High ecosystem impact (macro-level observable effects) requires at minimum two of the following three conditions to be present simultaneously: trust cascade at broad level (3/3), brand dissolution (reconstitution 3/3), and coordinated financial rail pressure. No case in this review produced sustained macro-level payment volume reduction from a single operation alone. Compounding pressure across multiple nodes and multiple timeframes is the necessary condition for macro-level movement.

RANSOMWARE ECOSYSTEM DISRUPTION FRAMEWORK: HISTORICAL CASE STUDIES v0.1 — March 2026

Working Document — Handle Per Originating Agency Protocols — Open Source Analysis Only

Ecosystem Dependency Project. This page is the full text of a corpus framework document, converted from the original for reading on the web. Content is unchanged. Figures and assessments carry the confidence language of the source document.