The Observatory / Document Library / Group Pressure Tracking Template
EDP Corpus · Document 11

Group Pressure Tracking Template

RANSOMWARE ECOSYSTEM

DISRUPTION FRAMEWORK

Corpus documentDoc 11

Group Pressure Tracking Template

Version 0.2 | June 2026 | Working Document

Developed by Reno

HOW TO USE THIS TEMPLATE

This template is the operational instrument for group-level pressure tracking. When a working group initiates sustained operations against a specific ransomware actor or brand, this template is opened and populated from the start. It runs alongside the per-operation micro-layer log entries in the KPI framework.

The template serves two audiences: the operational team maintaining situational awareness on the target group, and leadership who need a pre/post picture of what specific pressure is producing against a specific actor.

RELATIONSHIP TO THE KPI FRAMEWORK This template sits between the micro layer (per-operation logs) and the meso layer (node cluster metrics) in the KPI framework architecture. Micro-layer operation logs document individual actions against this group. This template aggregates those actions and tracks the cumulative effect on the target group specifically. Meso-layer node metrics track ecosystem-wide pressure. This template tracks group-specific effects that contribute to those meso metrics. Leadership receives this template as a group-level summary, not a node-level or ecosystem-level report.

Population Instructions

SECTION 1 | GROUP PROFILE

Populate before operations begin. Update when material changes are observed.

Group Name / HandlePrimary name and known aliases
Template IDUnique identifier for this tracking file
Date OpenedDate this template was initiated
Owning Team / AgencyPrimary team responsible for population
Operational ModelRaaS franchise / Closed hierarchical / Independent affiliate / Other
Estimated Active SinceApproximate date of first confirmed activity
LineageKnown predecessor groups or personnel origins (e.g., former Conti operators)
Estimated Affiliate CountPoint-in-time estimate at template opening. Confidence level.
Primary RaaS PlatformIf applicable: Exploit, XSS, private recruitment, or other
Known Operating GeographyPrimary actor geography based on available intelligence

Node Exposure Assessment

For each ecosystem node, assess the target group's current dependency and known infrastructure. This drives which nodes to prioritize for pressure.

NodeDependency LevelKnown Infrastructure / ActorsSubstitutabilityPriority
Node 01: OTC BrokersHigh / Medium / Low / UnknownHigh / Medium / Low
Node 02: High-Risk ExchangesHigh / Medium / Low / UnknownHigh / Medium / Low
Node 03: BPHHigh / Medium / Low / UnknownHigh / Medium / Low
Node 04: IAB MarketsHigh / Medium / Low / UnknownHigh / Medium / Low
Node 05: Botnet/LoadersHigh / Medium / Low / UnknownHigh / Medium / Low
Node 06: Leak SiteHigh / Medium / Low / UnknownHigh / Medium / Low
Node 07: Underground TrustHigh / Medium / Low / UnknownHigh / Medium / Low
Node 08: MixersHigh / Medium / Low / UnknownHigh / Medium / Low
Node 09: Mule NetworksHigh / Medium / Low / UnknownHigh / Medium / Low

Protection Layer Assessment

Krysha Relationship StatusActive / Strained / Broken / Unknown / None Assessed
Assessed Protecting EntityFSB unit / officer / MVD / Other / Unknown. Move specifics to Tier 3 annex.
Confidence LevelCONFIRMED / CREDIBLE / INDICATIVE
Protection Evidence BasisBrief description of evidence basis. Full sourcing in controlled annex.
Backfire Risk AssessmentLow / Medium / High. Reference companion playbook engagement triggers.

SECTION 2 | BASELINE METRICS

Establish before any pressure actions begin. These are the pre-action reference points against which all observed effects will be measured. A baseline that cannot be established is marked UNKNOWN, not estimated.

BASELINE INTEGRITY RULE Baselines must be established before the first action. Retroactive baseline establishment is not permitted because actions may already have affected the indicators. If a baseline cannot be established before action commences, mark it UNKNOWN and note the date of first action. Future measurements will be relative to the first post-action observation, which must be clearly labeled as such.

Operational Tempo Baseline

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
Leak site post volume (monthly average, 90-day window)
Average time-to-publish (days from compromise to publication)
Estimated active affiliate count
Average ransom demand (USD, reported cases)
Victim payment rate (confirmed payments / confirmed incidents)
Average ransom demand fulfillment rate

Financial Infrastructure Baseline

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
Primary OTC broker nodes (count of identified)
Attributed wallet cluster activity (monthly volume, USD estimate)
Primary mixing service usage (identified services)
OFAC-designated wallet percentage (of attributed wallets)

Access and Delivery Infrastructure Baseline

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
IAB sourcing pattern (primary forums and volume)
Average IAB access cost (USD, by access type if available)
BPH provider count (identified hosting nodes)
Loader/botnet dependency (primary delivery mechanism)

Underground Trust and Forum Health Baseline

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
Forum reputation score (Exploit/XSS, if available)
Active dispute threads against group on monitored forums
Affiliate recruitment activity (posts per month, approximate)
Current affiliate split percentage (advertised)

SECTION 3 | PRESSURE ACTION LOG

Add one row per action targeting this group. Cross-reference the operation ID to the micro-layer log entry in the KPI framework. Do not duplicate the full micro-layer log here: record the action type, expected effect, and reference the micro-layer entry for detail.

DateOperation IDAction TypeTarget Node(s)Expected Primary Effect (30 days)Backfire RiskMicro-Layer Log Ref
Designation / Takedown / Sinkhole / Referral / Arrest / Journalism / InfrastructureLow / Med / High

SECTION 4 | OBSERVED EFFECTS TRACKER

Update at 30, 90, and 180 days from the date of first action. Compare against baselines in Section 2. Annotate any divergence from expected effects.

4.1 Operational Tempo Effects

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
Leak site post volume vs. baselineSee Section 2
Time-to-publish vs. baselineSee Section 2
Active affiliate count vs. baselineSee Section 2
Average ransom demand vs. baselineSee Section 2
Victim payment rate vs. baselineSee Section 2

4.2 Financial Infrastructure Effects

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
OTC broker nodes active vs. baselineSee Section 2
Attributed wallet activity vs. baselineSee Section 2
Mixing service usage vs. baselineSee Section 2
Designated wallet percentage vs. baselineSee Section 2

4.3 Access and Delivery Effects

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
IAB access costs vs. baselineSee Section 2
BPH provider count vs. baselineSee Section 2
Loader/botnet delivery capacity vs. baselineSee Section 2

4.4 Underground Trust Effects

MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
Forum dispute volume vs. baselineSee Section 2
Affiliate recruitment activity vs. baselineSee Section 2
Affiliate split percentage vs. baselineSee Section 2
New brand/splinter emergenceNone at baseline

4.5 Divergence Notes

Record any significant divergence between expected and observed effects here. Include the operation ID, the expected effect, what was actually observed, and a brief assessment of why the divergence occurred.

DateOperation IDExpected EffectObserved EffectDivergence Assessment

SECTION 5 | WAIS LOG

Populate when an arrest involving this group occurs. Score each arrest individually. Reference the full WAIS scoring guide in the KPI framework document, Section 6.

FieldArrest 1Arrest 2Arrest 3
Operation ID / Date
Actor Role / Node Criticality Score (1/2/3)
Cooperation Output Score (1/2/3 or PENDING)
Trust Cascade Effect Score (1/2/3)
Reconstitution Impact Score (1/2/3)
WAIS Total
Coordination Bonus Applied (+2)?
Final WAIS (with bonus if applicable)
WAIS Category (High/Moderate/Limited)
90-Day Update Required?Yes / NoYes / NoYes / No

Cooperation Output PENDING follow-up:

Arrest IDPENDING SinceDebrief Expected DateUpdate When Available

SECTION 6 | STRIFE EVENT LOG

Populate when any strife event is observed involving this group. Use the event types defined in the KPI framework Section 5.2. Each event gets one row. Add rows as needed.

DateEvent TypeSource ReliabilityDescriptionEcosystem Effect ObservedCausal Link to ActionsFollow-On Indicators to Watch
LEAK / PUBLIC DISPUTE / EXIT SCAM / DEFECTION / ARR-TRIGGERED FRAG / HANDLER COMPLAINT / DOXCONFIRMED / CREDIBLE / INDICATIVE

SECTION 7 | ASSESSMENT

Complete at each 90-day review cycle. This is the leadership-reportable summary for this group. One page maximum. Designed for Tier 1 leadership dashboard use.

7.1 Current Group Status

Assessment Date
Overall Group StatusFully Operational / Degraded / Significantly Degraded / Inactive / Dissolved
Operational Capacity vs. BaselinePercentage estimate with confidence label
Financial Rail StatusIntact / Partially Disrupted / Significantly Disrupted
Protection Layer StatusActive / Strained / Broken / Unknown
Reconstitution RiskLow / Medium / High. If high, what is enabling reconstitution?

7.2 Pressure Effect Summary

In plain language, what has the pressure campaign produced? What is working, what is not, and what is the next recommended action. Three to five sentences maximum.

7.3 Recommended Next Actions

PriorityRecommended ActionTarget NodeExpected EffectOwner
1
2
3

7.4 KPI Framework Feed

Which macro and meso-layer KPIs are updated by this assessment? List the specific metrics and the direction of movement.

KPI IDKPI NameDirection of MovementConfidenceNotes
Improving / Worsening / No Change

ANNEX A | EXAMPLE: PRE-POPULATED TEMPLATE (Qilin)

This annex shows what a partially populated template looks like for an active group. Qilin is used as the example because it is well-documented in open-source reporting and has been the dominant franchise since RansomHub went dark in April 2025 and its affiliate base dispersed. This is illustrative only: all data drawn from public sources, and fields that require operational intelligence are left blank. The RansomHub collapse that displaced the previous version of this example is itself a reference case for the Section 6 strife event log: an exit-scam-pattern shutdown, a public loyalty dispute, and affiliate migration to competing brands inside 60 days.

Section 1 Partial: Group Profile

Group Name / HandleQilin (formerly Agenda)
Template IDEXAMPLE-QL-001
Date OpenedJune 2026 (illustrative)
Operational ModelRaaS franchise. Open affiliate recruitment. Advertised affiliate split of 80 to 85 percent in favor of the affiliate, with added services (integrated DDoS capability, negotiation support) used as recruitment differentiators post-RansomHub. Confidence: CREDIBLE.
Estimated Active SinceMid-2022 as Agenda; rebranded to Qilin by late 2022. Confidence: CONFIRMED.
LineageOriginal core assessed distinct from the Conti diaspora. Absorbed a significant share of displaced RansomHub affiliates after the April 2025 collapse; that roster itself carried former LockBit and BlackCat/ALPHV personnel. Confidence: CREDIBLE.
Estimated Affiliate CountUnknown. Highest claimed-victim volume of any active brand since mid-2025; roster assessed large. Confidence: INDICATIVE.
Primary RaaS PlatformPrivate panel. Affiliate recruitment via Russian-language forums (RAMP primary) and direct outreach. Confidence: CREDIBLE.

Section 2 Partial: Operational Tempo Baseline (Illustrative)

NOTE The following baseline values are drawn from open-source leak site tracking data (Ransomlook, Ransomware.live) and public reporting. They are illustrative of what a baseline entry looks like, not operational intelligence.
MetricBaseline (Pre-Action)30-Day90-Day180-DayConfidence
Leak site post volume (monthly average, trailing 12 months)~100-120 victims/month; roughly 1,400 plus claims in the trailing 12 months (open-source trackers; tracker-dependent)CREDIBLE
Average time-to-publish~3-5 days post-compromise (estimated)INDICATIVE
Estimated active affiliate countUnknown. High volume suggests large roster.INDICATIVE
Average ransom demandVariable. High-value targets reported at $1M+CREDIBLE

What a Pressure Campaign Against Qilin Would Track

Given the position Qilin holds as the dominant franchise since April 2025 and its absorption of displaced RansomHub affiliates, a pressure campaign would prioritize:

RANSOMWARE ECOSYSTEM DISRUPTION FRAMEWORK: GROUP PRESSURE TRACKING TEMPLATE v0.2 — June 2026

Working Document — Handle Per Originating Agency Protocols — One Template Per Active Target Group

Ecosystem Dependency Project. This page is the full text of a corpus framework document, converted from the original for reading on the web. Content is unchanged. Figures and assessments carry the confidence language of the source document.