The Observatory / Document Library / Playbook Phase A: Nodes 01, 02, 03
EDP Corpus · Document 05

Playbook Phase A: Nodes 01, 02, 03

RANSOMWARE ECOSYSTEM

CRITICAL NODE DISRUPTION PLAYBOOKS

Nodes 01-03: OTC Crypto Brokers | High-Risk Exchanges | Bulletproof Hosting

Corpus documentDoc 05

Priority Tier: CRITICAL, Build First

Developed by Reno

#ActionOwnerMethodBackfire RiskExpected Effect
1Blockchain forensics: trace admin wallet flows through layering to OTC withdrawal pointsChainalysis / TRM / internal ICReactor clustering + exchange KYC pressureLOWAttribution package sufficient for OFAC designation; identifies broker identity candidates
2VASP enhanced due diligence referrals: flag suspicious clusters at withdrawal exchanges for heightened scrutinyTreasury / FVEY financial partnersExchange engagement / compliance referralsLOWRaises friction at conversion points; may freeze funds pre-designation; generates compliance records
3Correspondent banking exposure: surface laundering routes touching Western correspondent banksTreasury / FinCEN / FVEY financial intelSAR referrals / bank compliance engagementLOWCreates compliance pressure on correspondent banks; forces route changes that surface new attribution
4FNS referral: lifestyle inconsistency package surfaced through Rosfinmonitoring pipelineRosfinmonitoring channel / FNSDomestic financial exposure, not cyber chargesLOWCreates domestic Russian exposure; non-attributable to foreign LE; feeds MVD referral pipeline
5CBR 115-FZ friction: flag suspicious domestic transaction patterns associated with broker front accountsCBR via Rosfinmonitoring pipelineSuspicious transaction flagging, non-attributableLOWNon-attributable account freezes or denials; disrupts fiat conversion without prosecution threshold
6OFAC designation: designate primary OTC broker wallet clusters and associated front companies with full attribution packageOFAC + FVEY designation partnersSDN listing + wallet designationLOW-MEDIUMExchange-level freeze globally; correspondent bank compliance action; named actor faces asset freeze
7Secondary designation: designate substitution nodes pre-identified in substitutability assessment, fire simultaneously or within 72 hours of primaryOFAC + FVEY partnersSDN listing, substitute nodesLOW-MEDIUMCloses reconstitution window; prevents immediate migration to pre-positioned alternatives
8Arrest action: pursue third-country arrest where actor travels outside Russia, coordinate with FVEY LE partners on travel patternsFVEY LE (FBI, NCA, RCMP, AFP)Third-country arrest, not extradition request to RussiaMEDIUMPhysical arrest; access to financial records and cooperation opportunities

⚠ Do NOT issue formal extradition requests to Russia. This triggers defensive nationalism and converts broker from criminal liability to protected asset. Pursue third-country arrest opportunities instead.

⚠ Do NOT lead with public attribution before financial actions are in place. Publicity signals to brokers that their records may be compromised, triggering rapid fund movement and account closure.

5. PARTNER LANES

PartnerRoleSpecific Contribution
OFAC / TreasuryPRIMARYSDN designations for broker wallets and front companies; VASP engagement program; FinCEN SAR referrals; correspondent banking pressure
Chainalysis / TRM LabsPRIMARYBlockchain forensics and wallet clustering; exchange KYC pressure; tracing from ransom payment to cash-out; cross-validation of attribution
FVEY Financial PartnersPRIMARYParallel designation actions; financial intelligence sharing; correspondent banking exposure in respective jurisdictions
Rosfinmonitoring / FNSSUPPORTDomestic financial exposure referrals; lifestyle inconsistency surfacing; Egmont Group suspicious transaction reporting
CBR (115-FZ channel)SUPPORTNon-attributable account-level friction; suspicious transaction flagging, no prosecution threshold required
FVEY LE FOsSUPPORTThird-country arrest coordination; travel pattern monitoring; cooperation opportunity exploitation post-arrest
Elliptic / ChainalysisSUPPORTCross-validation of primary forensics; VASP compliance risk scoring; independent attribution verification

6. RECONSTITUTION MONITORING

Define reconstitution triggers before taking action. The substitutability assessment (pre-action requirement) should predict the likely successor node. Monitor for:

Time-to-reconstitution after designation is a primary KPI. Log baseline from historical designations. A declining trend quarter-over-quarter signals compounding pressure is working.

7. KPIs

KPIMeasurement MethodCadenceSignal if Declining
Count of top-20 OTC nodes under active designation or VASP enhanced due diligenceTrack monthly movement in/out of active pressure listMonthlyFinancial exit points narrowing; cash-out cost rising
Share of traced ransom flows passing through designated / flagged rails (%)Chainalysis / TRM quarterly flow analysisQuarterlySanctions and VASP pressure working; laundering cost increasing
Time-to-reconstitution after designation (days)Monitor new wallet cluster activity post-designation; compare to baselinePer eventIncreasing trend = compounding friction is working
Sanctioned wallet activity post-designationChainalysis monitoring alerts on SDN-listed walletsMonthlyContinued activity = compliance gap at exchanges; refer for additional VASP engagement
New OTC broker advertisements on underground forumsIntel 471 / Flashpoint monitoringMonthlyRising supply = substitution occurring; target new nodes
Average asking price per large-volume cash-out transaction (where available)Intel 471 underground market monitoringQuarterlyRising prices = supply pressure working; actors paying more for same service

8. ENGAGEMENT TRIGGERS TO AVOID

Cross-reference: Main Playbook §8 (full trigger reference).

TriggerEffectSubstitute Action
Public attribution before financial actions in placeSignals record compromise; triggers rapid fund movement and account restructuringComplete OFAC designation package before any public naming
Formal extradition request to Russia for brokerTriggers defensive nationalism; converts broker from criminal to protected assetThird-country arrest strategy; travel pattern monitoring
Geopolitical framing in public statementsRussian agencies read as sovereignty violation; reduces any domestic enforcement appetiteLead with Russian-citizen-harm framing: tax fraud, undeclared assets, financial stability
Exposing FNS/Rosfinmonitoring referral channel publiclyBurns the domestic referral pathway; agencies resist when channel is attributed to foreign LENever publicly attribute domestic referral actions to foreign government direction
Designating without substitutability pre-positioningActor migrates immediately to pre-positioned alternative; pressure effect is 30 days maximumDesignate primary and substitute nodes simultaneously or within 72-hour window

EDP MODULE 12 SUPPLEMENTAL FINDINGS: OTC BROKERS

NODE 02 | HIGH-RISK / NON-COMPLIANT EXCHANGES

Priority TierCRITICAL
Node FunctionConversion of cryptocurrency ransom payments to fiat currency. The primary gateway through which mid-to-large ransom volumes enter the financial system. Non-compliant exchanges accept criminal funds with minimal or no KYC/AML controls.
Replace DifficultyHIGH, VASP compliance pressure has materially narrowed the non-compliant exchange landscape. Designating major non-compliant exchanges (Garantex, Bitzlato precedents) forces actors onto remaining alternatives, compounding pressure on those nodes. Each designation raises the friction cost.
Backfire RiskLOW, exchange designations are financial actions that do not implicate individual Russian state relationships. Exchanges are commercial entities, not intelligence assets.
Playbook ReferenceMain Playbook §4.3 (Financial Pressure), §5.3 (Payment Rail Pressure), §10.1 (Ecosystem KPIs)

1. ECOSYSTEM ROLE

High-risk exchanges occupy a structurally different position than OTC brokers. Where OTC brokers handle bespoke, relationship-based large transactions, exchanges provide automated, scalable conversion infrastructure, processing both the volume of mid-tier ransomware payments and the layering transactions that precede OTC cash-out for larger ransoms.

Key distinction: exchanges are not just cash-out endpoints. They are also laundering infrastructure. Ransomware actors use non-compliant exchanges as mixing-adjacent layering tools: moving funds through multiple exchange accounts in different names before final cash-out. This makes exchange-level monitoring and KYC pressure a tracing tool as much as a disruption tool.

The Garantex model (designated April 2022, re-designated and seized March 2025) illustrates the pattern: a Russia-based exchange operating with minimal AML controls, knowingly processing criminal proceeds, with blockchain forensics attribution confirming criminal flows constituted a substantial share of volume. Post-designation, criminal actors migrated to successors, but each migration imposed cost and attribution exposure.

2. STRUCTURAL VULNERABILITIES

2.1 KYC/AML Gaps

2.2 Correspondent and Correspondent-Adjacent Banking

2.3 Cascading Designation Effect

2.4 Supplemental Financial Intelligence (EDP Module 13)

3. PRE-ACTION REQUIREMENTS

Exchange designations require a higher evidentiary standard than wallet designations because they affect all users of the platform, including potentially innocent ones. Ensure blockchain forensics confirm criminal flows as a material share of exchange volume, not just incidental transactions.

4. ACTION SEQUENCE

Ordered low to high backfire risk.

#ActionOwnerMethodBackfire RiskExpected Effect
1Blockchain forensics: confirm criminal volume share and map specific criminal customers by transaction clusterChainalysis / TRM / EllipticReactor analysis; cluster attribution; volume share calculationLOWAttribution package for designation; identification of criminal customer list for follow-on actions
2VASP compliance engagement: approach exchange directly or through regulated intermediaries with AML compliance concerns, some exchanges respond to formal compliance pressure without designationTreasury / FINCEN / FVEY equivalentsCompliance engagement letters; enhanced due diligence referralsLOWMay produce voluntary compliance improvements; if ignored, strengthens designation package
3Correspondent bank notification: alert correspondent banks processing the exchange's USD/EUR settlements of criminal volume concernsFinCEN / Treasury / FVEY financial intelSAR referrals; bank compliance engagementLOWCorrespondent banks sever relationships; exchange loses fiat settlement capacity, highly disruptive without formal designation
4Fiat on/off ramp disruption: engage payment processors, card networks, and banking partners serving the exchange in third-country jurisdictionsFVEY LE / financial partnersCompliance referrals; jurisdiction-specific regulatory pressureLOWSevers fiat connectivity; forces exchange to find alternative banking, each change imposes cost and attribution exposure
5OFAC / FVEY parallel designation: designate exchange with full blockchain forensics package; coordinate simultaneous FVEY partner designations to prevent jurisdiction-shoppingOFAC + FVEY Treasury equivalentsSDN listing; parallel OFSI / EU designationLOW-MEDIUMGlobal exchange-level freeze; compliance action by all regulated VASPs globally; criminal volume forced onto remaining non-compliant alternatives
6Exchange seizure / infrastructure takedown: where jurisdiction exists, coordinate infrastructure seizure to obtain transaction records, yields criminal customer list for follow-on actionsFVEY LE (FBI, NCA, Europol, BKA)Domain seizure; server seizure; operator arrestMEDIUMTransaction record access; operator arrest opportunity; trust destruction across criminal customer base
7Criminal customer follow-on: use seized exchange records to identify and pursue individual criminal customers, ransomware operators, OTC brokers, darknet vendorsFVEY LE FOsRecord analysis; arrest warrants; additional designationsMEDIUMProsecutions and designations from seized data; compounding pressure on individual actors

⚠ Correspondent bank notifications are among the most powerful tools available and carry LOW backfire risk. They are frequently underused. A single notification to a major US correspondent bank processing an exchange's settlements can be more disruptive than a formal designation, with fewer legal and evidentiary requirements.

5. PARTNER LANES

PartnerRoleSpecific Contribution
OFAC / Treasury / FinCENPRIMARYSDN designation; correspondent bank notifications; VASP compliance engagement; FinCEN SAR referral pipeline
FVEY Treasury EquivalentsPRIMARYParallel OFSI / EU / AUSTRAC designations; jurisdiction coordination to prevent shopping; financial intelligence sharing
Chainalysis / TRM / EllipticPRIMARYCriminal volume attribution; customer cluster identification; post-designation migration monitoring; VASP risk scoring
FVEY LE (FBI/NCA/Europol)PRIMARYInfrastructure seizure where jurisdiction exists; operator arrest; seized record exploitation
FVEY Financial IntelSUPPORTBeneficial ownership identification; UBO tracing across jurisdictions; shell company mapping
Private Sector (IR firms)SUPPORTVictim ransom tracing to exchange; coordination of victim notification post-seizure

6. RECONSTITUTION MONITORING

Post-Garantex, criminal volume migrated primarily to EXCH, Huione Guarantee, and a set of smaller Russian-linked OTC operations. Pre-positioning attribution on these nodes before the Garantex designation would have closed the migration window. Apply this lesson: always designate with successor nodes pre-identified.

7. KPIs

KPIMeasurement MethodCadenceSignal if Declining
Share of ecosystem funds forced onto higher-friction rails (%)Chainalysis / TRM quarterly flow analysis; track % through non-designated vs designated railsQuarterlyFinancial laundering cost increasing; pressure is working
Sanctioned wallet / exchange activity post-designationChainalysis monitoring alerts on SDN-listed entitiesMonthlyContinued high activity = compliance gap; refer for additional VASP engagement or seizure action
Time-to-correspondent-bank-severance after notificationTrack from notification date to confirmed account closurePer eventFaster severance = growing institutional awareness; slower = need for escalation
Non-compliant exchange count (active, high-risk)Chainalysis / TRM VASP risk scoring; Flashpoint monitoringMonthlyDeclining count = pressure working; stable or rising = new entrants filling gap
Migration volume to successor exchanges post-designationChainalysis flow analysis 30/60/90 days post-designationPer event + rollingLow migration = effective substitutability pressure; high migration = successor node designation needed

8. ENGAGEMENT TRIGGERS TO AVOID

Cross-reference: Main Playbook §8.

TriggerEffectSubstitute Action
Designating exchange without successor node attribution pre-positionedCriminal volume migrates immediately to successor; 30-day window of unimpeded operationPre-position attribution on top 3 successor candidates before designating primary
Public attribution of exchange as 'Russian government tool'Activates sovereignty protection reflex; reduces any Russian domestic enforcement appetiteFrame as financial crime and harm to Russian financial stability, not geopolitical framing
Engaging exchange compliance team without enforcement backstopExchange may accept engagement as signal that designation is unlikely; continues operationsEnsure OFAC designation package is ready to fire before compliance engagement begins
Delaying seizure action after access is obtainedBurn risk rises; if access is discovered, transaction records are deleted and actors migrateDefine trigger for seizure before monitoring begins; do not allow indefinite monitoring

NODE 03 | BULLETPROOF HOSTING (BPH) PROVIDERS

Priority TierCRITICAL
Node FunctionDurable hosting for command-and-control servers, affiliate panels, leak sites, negotiation portals, and malware distribution infrastructure. BPH providers offer abuse-resistant hosting by maintaining upstream relationships that resist takedown requests, ignoring abuse complaints, and rapidly migrating infrastructure under pressure.
Replace DifficultyHIGH, full-service BPH with abuse-resistant upstream relationships is scarce. Substitution requires criminal trust relationships, technical capability to migrate infrastructure, and time. Generic gray-market VPS (Node 12) is faster to obtain but provides materially less protection.
Backfire RiskLOW-MEDIUM, BPH disruption targets providers, not individual actors. Provider-level actions do not implicate state protection relationships. Actor-level attribution from seized BPH infrastructure may surface state-linked actors (elevated caution required at that point).
Playbook ReferenceMain Playbook §4.3 (Infrastructure Pressure), §6 (Takedown vs. Monitoring), §10.3 (Investment Priority #3)

1. ECOSYSTEM ROLE

BPH is the infrastructure backbone of sustained ransomware operations. Unlike legitimate hosting, BPH providers are operationally complicit: they know the nature of their customers' activities and actively resist external disruption. This complicity means abuse complaints to upstream providers and registrars are ignored at the BPH level, but not necessarily at the BPH provider's own upstream dependencies.

The correct targeting model is not the BPH brand, it is the dependency chain above the BPH brand. Every BPH provider has a registrar, a nameserver provider, an ASN or transit provider, and a payment acceptance method. Each of these upstream dependencies is a leverage point that the BPH provider cannot control and cannot easily replace.

2. STRUCTURAL VULNERABILITIES

2.1 Upstream Dependency Chain

2.2 Infrastructure Fingerprinting

2.3 Payment Acceptance Exposure

2.4 Multi-Tenant Criminal Infrastructure

2.5 Proactive Infrastructure Identification (EDP Module 09)

3. PRE-ACTION REQUIREMENTS

The Investment Priority for BPH is upstream infrastructure dependency mapping, move from BPH brand lists to provider-of-provider leverage. Build the dependency chain BEFORE taking action. Without it, takedown produces only a brand disruption; with it, takedown can permanently degrade the provider.

4. ACTION SEQUENCE

Ordered low to high backfire risk. Infrastructure actions carry low individual backfire risk but should be coordinated across vectors for maximum effect.

#ActionOwnerMethodBackfire RiskExpected Effect
1Infrastructure mapping: build full upstream dependency chain for target BPH (registrar, DNS, ASN, CDN, payment rails)Shadowserver / Censys / internal ICPassive scan data; WHOIS analysis; ASN routing analysisLOWDependency chain map enabling targeted upstream pressure; substitutability assessment
2Registrar and DNS provider notification: submit documented abuse reports with criminal attribution to registrar and nameserver providers for BPH-linked domainsPrivate sector (abuse reporting); FVEY LE for formal referralsAbuse notifications with blockchain and infrastructure attributionLOWDomain suspension; disrupts criminal communications and panel access; forces domain reconstitution
3CDN / DDoS protection provider engagement: notify CDN and DDoS protection providers (Cloudflare, Akamai-adjacent services) serving BPH infrastructurePrivate sector; FVEY LE formal referralsTerms of service violation notifications; formal referralsLOWCDN service termination; BPH infrastructure exposed to DDoS disruption; forces reconstitution under worse operational conditions
4Upstream ISP / transit provider notification: send documented abuse notifications to Tier-1/Tier-2 transit providers upstream of the BPH-linked ASNFVEY LE FOs / IC; Shadowserver coordinationAbuse notifications; null-routing requests; peering termination requestsLOWASN upstream pressure; may result in null-routing of BPH-linked IP ranges; most impactful single upstream action
5Payment rail pressure: designate or engage BPH provider's cryptocurrency payment wallets and any identified payment processorsOFAC / FVEY financial partners; blockchain forensicsWallet designation; payment processor engagementLOW-MEDIUMCriminal customers cannot pay for hosting; BPH provider loses revenue; forces payment method changes that surface new attribution
6Infrastructure takedown: coordinate domain seizure, server seizure, and panel access, simultaneous with upstream actions to prevent emergency reconstitutionFVEY LE (FBI, NCA, Europol, BKA)Domain seizure; server seizure; backend accessMEDIUMOperational disruption across all hosted criminal customers; backend data yields customer list and operational intelligence
7Seized data exploitation: cross-reference BPH backend records with blockchain forensics and IC intelligence; pursue criminal customer identification and follow-on actionsFVEY LE FOs + ICRecord analysis; customer identification; arrest warrants; additional designationsMEDIUMProsecutions and designations across multiple criminal groups from single takedown; compounding ecosystem pressure
8Reconstitution takedown: when BPH reconstitutes under new brand (detected via infrastructure fingerprinting), immediately attribute new brand to prior identity and repeat upstream pressureFVEY LE / IC; private sector attributionPublic attribution; upstream notification; repeat upstream pressure sequenceMEDIUMResets brand equity to zero; complicates customer recruitment; imposes reconstitution cost repeatedly

⚠ Monitor before takedown. The intelligence value of a live BPH backend, criminal customer list, operational planning, active campaign data, generally exceeds the disruption value of an immediate takedown. Define the monitoring-to-takedown trigger before beginning (Main Playbook §6.5). Do not allow monitoring to run indefinitely.

⚠ Document all infrastructure fingerprints BEFORE takedown. If the same BPH reconstitutes post-takedown, immediate attribution closes the reconstitution window. Without pre-positioned fingerprints, you restart attribution from zero.

5. PARTNER LANES

PartnerRoleSpecific Contribution
FVEY ICPRIMARYInfrastructure monitoring; upstream dependency mapping; BPH backend access; customer list intelligence; reconstitution tracking
FVEY LE (FBI/NCA/Europol/BKA)PRIMARYDomain and server seizure; operator arrest; formal abuse referrals to ISPs; seized data exploitation
Shadowserver / CensysPRIMARYPassive infrastructure scanning; ASN and hosting clustering; reconstitution monitoring; pre/post-takedown baseline
Private Sector (ISPs/CDNs)PRIMARYVoluntary abuse-driven service termination; upstream transit pressure; CDN / DDoS protection termination
Registrars / DNS ProvidersPRIMARYDomain suspension on abuse notification; terms of service enforcement
OFAC / TreasurySUPPORTPayment rail designation; cryptocurrency wallet designation for BPH payment acceptance
Blockchain Forensics FirmsSUPPORTPayment rail attribution; BPH cryptocurrency wallet clustering; criminal customer payment tracing
Recorded Future / MDTISUPPORTDomain and IP intelligence; cross-platform OSINT fusion; BPH actor profiling

6. RECONSTITUTION MONITORING

The BreachForums reconstitution cycle (Main Playbook §6.4) applies equally to BPH. Each iteration of takedown-and-reconstitution produces intelligence on who rebuilds, where new infrastructure goes, and who the resilient actors are. Monitor reconstitution as the beginning of the next action cycle, not as a failure of the previous one.

7. KPIs

KPIMeasurement MethodCadenceSignal if Declining
Active BPH provider count (high-risk, abuse-resistant)Shadowserver / Censys monthly scan; underground forum advertising monitoringMonthlyDeclining count = upstream pressure working; stable = new entrants filling gap; rising = ecosystem expanding
Time-to-reconstitution after BPH takedown (days)Log from takedown date to confirmed reconstitution detection; compare to baselinePer eventIncreasing trend = friction compounding; decreasing = reconstitution becoming easier; investigate
Time-to-upstream-severance after ISP/registrar notification (days)Track from notification to confirmed null-route / domain suspensionPer eventFaster severance = growing provider awareness and cooperation; slower = escalate or find alternative upstream leverage
Count of BPH providers with full upstream dependency maps completedInternal tracking of dependency graph coverageMonthlyRising coverage = improving leverage position; target 100% coverage on top-10 BPH providers
Criminal customer disruption count from BPH seizure dataCount of follow-on actions (arrests, designations) attributable to seized BPH recordsPer event (90-day window)Higher count = BPH seizures are being fully exploited; low count = seized data not being actioned

8. ENGAGEMENT TRIGGERS TO AVOID

Cross-reference: Main Playbook §8.

TriggerEffectSubstitute Action
Taking down BPH infrastructure before backend access is obtainedSnapshot disruption only; loses criminal customer list and operational intelligence; actors migrate without exposureMonitor until backend access is obtained or mapping is sufficient (Main Playbook §6.5 trigger framework)
Failing to document infrastructure fingerprints before takedownReconstitution under new brand is undetectable; attribution restarts from zero; reconstitution window is open indefinitelyMandatory pre-takedown fingerprinting: panel code, ASN patterns, domain registration style, SSL certs
Single upstream action without coordinating others simultaneouslyBPH provider patches single dependency; other upstream relationships remain intact; disruption is partial and temporaryCoordinate registrar, DNS, CDN, and ISP actions simultaneously or within 24-hour window
Targeting BPH brand without upstream dependency mappingBrand disruption only; operator reconstitutes under new brand with same upstream relationships; minimum friction imposedBuild upstream dependency chain first; target the relationships, not the brand name
Attributing BPH seizure publicly to specific IC methodsBurns collection methods; BPH community hardens OPSEC; future infiltration attempts face increased frictionPublic attribution of legal basis only; protect SIGINT and access methods

NODE 16 | EXPLOIT / VULNERABILITY BROKERS

Priority TierCRITICAL
Node FunctionZero-day and N-day exploit acquisition for affiliates and operators. Enables complete bypass of Node 04 (IAB Markets) for targets requiring stealth or specific access capabilities. A single 0-day acquisition can produce thousands of victim accesses within days — per-unit impact exceeds all other nodes in the map.
Replace DifficultyHIGH — zero-day market concentrated among a small number of trusted brokers; relationships reputation-dependent and slow to rebuild; bug class exhaustion following coordinated disclosure permanently degrades specific exploit families.
Backfire RiskMEDIUM — highest in Phase A range; driven entirely by state adjacency (FSB/GRU maintain parallel exploit acquisition operations); Dark Covenant 3.0 screening is mandatory before any designation or attribution action.
Phase AssignmentA+ (pre-Phase B prerequisite). Initiate simultaneously with Phase A nodes, not sequenced after. Primary lever is policy-track (CISA KEV enforcement, bug bounty economics reform), not LE or financial designation.
Primary OwnerPolicy lead: CISA + NSA (CISA KEV enforcement, coordinated vulnerability disclosure reform, bug bounty scaling) | OFAC (designation of confirmed criminal-only brokers, post-screening) | FVEY IC (broker attribution, acquisition monitoring)

1. ECOSYSTEM ROLE

Exploit and vulnerability brokers occupy the highest per-unit-impact position in the ransomware supply chain. A single 0-day acquisition by a CL0p-model operator produced more victim accesses in days than months of IAB market activity across the entire ecosystem. This node enables complete bypass of Node 04 (IAB Markets) for operators with 0-day capability — the financial value of IAB disruption is partially negated if exploit-capable groups remain unaddressed.

The disruption logic is structurally different from every other Phase A node. The primary lever is policy-track: CISA Known Exploited Vulnerabilities (KEV) enforcement, patch mandate acceleration, and bug bounty economics reform. These actions reduce the exploitable window and close the criminal-versus-legitimate price differential. Law enforcement and financial designation are secondary levers, constrained by state adjacency backfire risk. This sequencing is not optional — it reflects the actual leverage structure of the node.

State adjacency is the defining constraint. FSB/GRU maintain parallel vulnerability research and acquisition operations. Some criminal exploit brokers may simultaneously supply state intelligence operations. Dark Covenant 3.0 screening is mandatory before any designation or attribution action. The MEDIUM backfire risk is the highest of any Phase A node and is driven entirely by state adjacency, not operational concern.

2. STRUCTURAL VULNERABILITIES

2.1 Price Differential (Root Vulnerability)

Criminal market prices exceed vendor bug bounty caps by 10x–100x for critical infrastructure-relevant 0-days. This price differential is the root driver of researcher behavior — not ideology or criminal intent. The supply pipeline exists because the financial incentive exists. No law enforcement action addresses this root cause; only bug bounty economics reform durably closes the gap. Until the differential narrows, disrupting individual brokers shifts researchers to new brokers rather than legitimate programs.

2.2 Forum Matchmaking Dependency

Criminal forums (RAMP, XSS, DarkForums) are the primary broker-to-buyer discovery mechanism. 'Seeking 0-day' threads on these platforms provide the earliest available signal of RaaS group acquisition intent — upstream of any other warning indicator. This is a Node 07 dependency: Underground Forums disruption (Phase B) compounds exploit broker matchmaking friction and provides pre-deployment victim notification opportunities via CISA and sector CERTs.

2.3 Financial Infrastructure Overlap

High-value exploit transactions (six-to-eight figures) require functioning cryptocurrency OTC and exchange infrastructure. Phase A financial pressure (Nodes 01–02) degrades liquidity available for major exploit purchases. Effective Nodes 01–02 disruption simultaneously degrades the financing layer for exploit acquisition. Coordinate timing to compound these effects.

2.4 Patch Window as Counter-Lever

Every exploit has a natural expiration date triggered by vendor patching. CISA KEV enforcement and patch mandate acceleration continuously shrink the exploitation window. Current enterprise patch deployment averages 30–60 days for the software categories most targeted by criminal operators (file transfer tools, VPN appliances, enterprise collaboration). Shortening this window degrades exploit ROI regardless of whether the broker transaction is disrupted. Patch velocity is the only durable counter.

2.5 CL0p Off-Market Model (Structural Exception)

CL0p and analogous operators have developed direct researcher relationships that bypass the criminal broker market entirely. For this actor segment, broker interdiction has no effect — there is no broker to target. Only patch velocity acceleration addresses this capability. This segment must be tracked separately and should not be conflated with broker-dependent actors when assessing action effectiveness. Identifying which RaaS programs maintain off-market 0-day capability is a standing IC collection requirement.

3. PRE-ACTION REQUIREMENTS

Dark Covenant 3.0 screening: mandatory before any designation, attribution, or law enforcement action. Sequence policy-track actions (CISA KEV enforcement, bug bounty economics reform) first — zero state adjacency exposure. Proceed to financial designation and attribution only after confirmed-criminal-only operator screening has been completed. This sequencing requirement is non-negotiable for this node.

Forum monitoring build-out: integrate exploit broker 'seeking' thread surveillance into existing Node 07 (Underground Forums) collection operations before any disruptive action. This provides pre-deployment early warning and establishes the intelligence baseline required to assess broker-to-buyer relationships and identify successor nodes.

Substitute node pre-positioning: identify which brokers will absorb migrating buyers post-designation. Pre-position attribution on successor nodes before acting on primary targets. Historical pattern (Zerodium price cap period, 2019–2023): supply redirects within days to weeks following individual broker disruption.

RaaS group segmentation: identify which RaaS programs maintain 0-day acquisition capability (CL0p model) versus which are exclusively dependent on IAB-sourced credential access. This segmentation determines whether exploit supply disruption or IAB disruption is the effective lever for each target group and prevents misallocation of action resources.

4. ACTION SEQUENCE

Ordered by timeline and backfire risk. Policy-track actions (1–2) carry no state adjacency exposure and should be initiated immediately and maintained continuously. Intelligence and LE actions (3–5) require Dark Covenant 3.0 screening and forum monitoring build-out as prerequisites.

#ActionOwnerMethodBackfireExpected Effect
1Patch velocity acceleration + CISA KEV enforcementCISA + software vendors (non-IC, non-LE)Federal procurement patch mandates; vendor-direct patch deployment acceleration; CISA KEV catalog enforcementLOWShrinks exploitation window for all deployed 0-days; only durable counter to 0-day acquisition capability at scale; operates continuously regardless of LE action
2Bug bounty economics reformSoftware vendors, HackerOne, Bugcrowd (non-government industry action)Raise bounty caps to $500K–$1M for critical infrastructure-relevant 0-days; coordinated industry action targeting the criminal price differentialLOWCloses price differential over time; reduces researcher incentive to sell to criminal markets; addresses root driver that no LE action can reach
3Forum 'seeking' thread monitoring + pre-deployment victim notificationFVEY LE + Intel471/Flashpoint; CISA for victim notificationSurveillance of RAMP, DarkForums, XSS exploit acquisition threads; pre-deployment victim notification via CISA and sector CERTsLOWPre-deployment victim notification pipeline; raises matchmaking friction for broker-to-buyer connections; does not eliminate supply but degrades per-deployment ROI
4Financial designation (confirmed criminal-only brokers, post-screening)OFAC + Chainalysis / TRM LabsDark Covenant 3.0 screening first; SDN designation for confirmed criminal-only operators; T3 (Tether/TRON/TRM Labs) coordination for USDT-denominated transactionsMEDIUM (screening mandatory)Disrupts payment rails; intelligence collection opportunity during transition period; shifts buyers to successor brokers — pre-position attribution before acting
5IC-led acquisition monitoring + attribution (post-screening, selected targets)FVEY IC (NSA, GCHQ, CSE)SIGINT/HUMINT monitoring of RaaS-researcher channels; acquisition signal detection; attribution intelligence for OFAC designation pipelineLOW (passive); MEDIUM if public attribution involves state-adjacent operatorsEnables pre-deployment victim notification; builds designation pipeline for Action 4; does not disrupt broker market but degrades per-deployment ROI for acquisition events detected

5. PARTNER LANES

PartnerRoleSpecific Contribution
CISA + NSAPRIMARYCISA KEV catalog enforcement and update cadence; patch mandate policy design and federal procurement requirements; bug bounty economics advocacy; coordinated vulnerability disclosure reform
FVEY IC (NSA, GCHQ, CSE)PRIMARYBroker attribution; RaaS-researcher channel acquisition monitoring; pre-deployment victim notification pipeline; Dark Covenant 3.0 screening support for designation candidates
FVEY LE (FBI / NCA / Europol)SUPPORTCriminal-only broker investigation (post Dark Covenant 3.0 screening); Western-jurisdiction actor prosecution; forum 'seeking' thread disruption coordination; Node 07 compounding action
OFAC / TreasurySUPPORTSDN designation of confirmed criminal-only brokers (post-screening); T3 (Tether/TRON/TRM Labs) coordination for USDT-denominated exploit transactions; financial pressure on broker payment rails
Blockchain Forensics (Chainalysis / TRM)SUPPORTExploit transaction tracing; broker cryptocurrency wallet clustering; payment rail attribution; T3 referral pipeline for USDT blacklisting
HackerOne / Bugcrowd / Software VendorsSUPPORTBug bounty cap advocacy and coordinated economics reform; legitimate-market pricing transparency; coordinated industry action to narrow criminal-vs-legitimate price differential

6. RECONSTITUTION MONITORING

Forum monitoring continuity: maintain 'seeking 0-day' thread surveillance on RAMP, XSS, and DarkForums as a continuous operation, not an event-based trigger. Broker displacement following disruption shifts demand to new channels within days; monitoring must pre-date any action to establish a baseline and detect migration.

Successor broker identification: track new broker-to-buyer matchmaking signals in encrypted channels and underground forums following any designation action. Supply redirection — not supply elimination — is the primary reconstitution pattern for this node. Pre-positioned attribution on successor nodes is required before acting on primary targets.

Patch velocity baseline maintenance: establish and maintain enterprise patch deployment time baselines for the software categories targeted by CL0p-model operators (file transfer tools, VPN appliances, enterprise collaboration). CISA KEV enforcement effectiveness is measured against this baseline; declining baseline times confirm policy-track actions are working.

RaaS exploit acquisition signal monitoring: alert on evidence of RaaS group 0-day acquisition through SIGINT or HUMINT channels. New mass exploitation campaigns by previously credential-dependent groups signal acquisition of new off-market capability — treat as a new actor assessment, not a continuation of the prior profile. Update RaaS group segmentation (Section 3) accordingly.

7. KPIs

KPICadenceMethodSignal if Declining
Active criminal broker count (forum-visible)MonthlyUnderground forum monitoring; Intel471/FlashpointDeclining count = matchmaking friction compounding; stable/rising = new entrants filling gap; investigate substitute channels
Time-to-enterprise-patch for KEV catalog entries (days)MonthlyCISA KEV catalog analysis; enterprise patch deployment dataDecreasing time = CISA KEV enforcement working; stagnant at 30+ days = patch mandate acceleration needed
Bug bounty cap vs. criminal market price ratioQuarterlyZerodium/Crowdfense pricing vs. HackerOne/Bugcrowd public cap analysis by 0-day categoryNarrowing gap = reform working; widening gap = incentive problem worsening; advocacy action required
RaaS group 0-day acquisition events (confirmed or credible)Per eventIC collection; DFIR casework tagging; threat intel vendor reportingRising frequency = CL0p model spreading to new actors; update actor segmentation; new patch velocity urgency
Pre-deployment victim notifications issued via CISA/sector CERTsPer eventCISA operational trackingIncreasing = monitoring pipeline maturing; zero = baseline collection gap or acquisition events not being detected

8. ENGAGEMENT TRIGGERS TO AVOID

Cross-reference: Main Playbook §8.

TriggerEffectSubstitute Action
Designating or attributing a broker without Dark Covenant 3.0 screeningState adjacency exposure; potential disruption of IC equities or active state operations; MEDIUM backfire risk realizedComplete confirmed-criminal-only operator screening first; sequence all policy-track actions before any designation; consult Dark Covenant 3.0 screening framework
Conflating broker-dependent RaaS actors with CL0p off-market modelBroker interdiction resources directed at groups unaffected by it; off-market capability remains unaddressed; action appears effective but is notSegment RaaS programs by access acquisition model before action; address off-market actors through patch velocity acceleration, not broker targeting
Public attribution of individual broker identities without IC equity reviewBurns SIGINT and HUMINT collection access; broker community hardens OPSEC; surviving brokers implement counter-surveillance; future IC access faces increased frictionLimit public attribution to legal basis only; protect signals intelligence and human access methods; coordinate with IC before any public naming
Treating individual broker takedown as function eliminationReplace difficulty is HIGH but function persists; supply redirects within days; overconfidence in disruption durability leads to premature disengagementDefine success as increased acquisition cost and friction, not function elimination; measure via KPIs; maintain monitoring continuously post-action

EDP MODULE 06 SUPPLEMENTAL FINDINGS: EXPLOIT / VULNERABILITY BROKERS

NEXT STEPS

Phase A (CRITICAL nodes, including Node 16 Phase A+ prerequisite) is complete. Recommended Phase B sequence:

Phase B nodes share two characteristics: lower individual backfire risk than CRITICAL nodes, and high ecosystem-level impact when combined with the financial pressure established in Phase A. IAB and trust node disruption attacks the operational engine; mixing disruption attacks the financial obscuration layer. All three compound the pressure imposed by the CRITICAL node actions.

Document maintenance: review and update each node playbook quarterly, or following any major takedown, actor rebrand, significant enforcement action, or material change in VASP / infrastructure provider compliance posture.

Ecosystem Dependency Project. This page is the full text of a corpus framework document, converted from the original for reading on the web. Content is unchanged. Figures and assessments carry the confidence language of the source document.