ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs

ReHub: Russian-Language Cybercrime Marketplace Sponsoring (TL-2026-1594), also tracked as ReHub Marketplace, is a medium-severity tracked threat-actor profile, first published 2026-07-21. It is attributed to ReHub Forum Operators (Russia) with medium confidence, maps to 20 MITRE ATT&CK techniques (T1005, T1027, T1046), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1594

Threat ID
TL-2026-1594
Also known as
ReHub Marketplace, ReHub Ransomware Marketplace
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-07-21
Last reviewed
2026-07-21
Attribution
ReHub Forum Operators
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
manufacturing, construction, informationtechnology, health, retail, professionalservices, government administration, criticalinfrastructure, financialservices
Target regions
Global, North America, Europe, Asia-Pacific, Middle East
Detection rules
9
Indicators of compromise
20

Malware and tooling in ReHub: Russian-Language Cybercrime Marketplace Sponsoring

Malware and tooling: AgendaCrypt, Chaos, DEVMAN, DragonForce, LockBit, anubis, black suit, the gentlemen

ReHub is a Russian-language cybercrime forum and marketplace launched on August 10, 2025 by a former XSS forum moderator following the July 22, 2025 law-enforcement seizure of XSS.is. It hosts ransomware affiliate program advertisements, compromised network access sales, malware and stolen financial data trading, bulk spam infrastructure, forged documents, and anonymous hosting/crypto laundering services, and sponsors ransomware groups including DragonForce (primary sponsor, homepage-featured), The Gentlemen, CHAOS, Anubis, LockBit, and DevMan. Following the January 28, 2026 FBI seizure of the RAMP forum, ReHub absorbed the displaced RaaS community and by July 2026 had grown to over 8,300 active users, ~15,000 posts, and nearly 3,000 threads.

How ReHub: Russian-Language Cybercrime Marketplace Sponsoring works

ReHub emerged directly out of the disruption of two prior Russian-language cybercrime hubs. On July 22, 2025, a joint operation by the French Cybercrime Brigade (BL2C), Europol, and Ukraine's SBU Cyber Department seized the XSS.is forum -- a 50,000+ member marketplace whose administrator ('Toha') was arrested in Kyiv on allegations of profiting over EUR7 million from ransomware, malware, and stolen-data trade. A faction of former XSS moderators first launched DamageLib on August 1, 2025 as a knowledge-base-only successor with no commercial trading, explicitly rejecting illicit commerce. Nine days later, on August 10, 2025, a separate former XSS moderator launched ReHub instead as a commercially-focused alternative, positioning it as 'free from state and law enforcement interference' and framing surviving XSS mirror iterations as compromised or monitored.

ReHub operates on both the clearweb and via a Tor (.onion) hidden-service mirror. It is organized into distinct sections: Sandbox (entry-level OPSEC/fraud-logistics discussion, and since a mid-April 2026 Zero Trust policy change the only section new members can access), Technical (network vulnerabilities, AI jailbreaking, deepfake social engineering, carding), Programming (malicious tooling and automation development), Library (leaked databases, cracked utility software, aggregated security news), Supermarket (the commercial core -- ransomware affiliate-program threads and paid illicit services), Arbitration (dispute resolution and a 'Black List' scammer registry standard to Russian-language cybercrime forums), and Administration. Paid membership tiers exist: 'Premium' (gold, $100/year) grants custom titles and unlimited post editing; 'Patron' (pink/magenta, $5,000/year) grants custom profile styling and personal profile links -- a monetization model mirroring earlier elite forums like Exploit and XSS.

The forum's growth was sharply accelerated by the January 28, 2026 FBI seizure of the RAMP (Ransom Anon Market Place) forum, executed with the U.S. Attorney's Office for the Southern District of Florida and DOJ CCIPS. RAMP had operated since 2021 as the only major dark-web forum explicitly permitting RaaS program advertising, hosting affiliate recruitment for Qilin, LockBit, DragonForce, RansomHub, ALPHV/BlackCat, Anubis, and CHAOS, among others. Its nameservers were repointed to ns1/ns2.fbi.seized.gov, and one alleged RAMP operator publicly confirmed the takedown, writing it 'destroyed years of my work to create the most free forum in the world.' The RAMP disruption pushed its displaced ransomware-affiliate community to ReHub, which had already positioned itself as a commerce-friendly Supermarket-style venue.

ReHub's Supermarket section now hosts affiliate-recruitment threads for six active ransomware brands, several of which are themselves recent splinters or rebrands of earlier disrupted operations, reflecting the underground's rapid reconstitution cycle:

- DragonForce: a RaaS group active since 2023 that declared itself a ransomware 'cartel' on March 19, 2025, letting affiliates white-label DragonForce's builder/infrastructure under their own brand while paying a reduced 0-23% cartel fee (versus the ~20% RaaS industry standard) or up to 80% affiliate payout under other terms. In September 2025, DragonForce announced a formal cartel partnership with Qilin and LockBit to coordinate attacks, share resources, and suppress conflicts between affiliates. By June 2026, DragonForce had accumulated 579 confirmed victims (216 in H1 2026 alone), targeting organizations with >$15M revenue across manufacturing, construction, IT services, healthcare, and retail. DragonForce's logo is permanently displayed on ReHub's homepage as its primary sponsor. - DevMan: emerged April 2025 as a DragonForce/Conti-lineage variant -- DEVMAN's codebase derives from a leaked DragonForce builder, which itself derives from Conti. DevMan operated first as a multi-RaaS affiliate across Qilin, DragonForce, Apos, and RansomHub before breaking away by July 2025 to run its own independent RaaS operation using a modified DragonForce codebase, evolving from affiliate to independent provider by late 2025.

MITRE ATT&CK techniques used in TL-2026-1594

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information

Discovery

T1046 Network Service Discovery

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing

Command and Control

T1090 Proxy

Credential Access

T1110 Brute Force

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1657 Financial Theft

Exfiltration

T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1588 Obtain Capabilities; T1650 Acquire Access

Reconnaissance

T1591 Gather Victim Org Information

defense-impairment

T1685 Disable or Modify Tools

Remediation for ReHub: Russian-Language Cybercrime Marketplace Sponsoring

Immediate actions

  • Add ReHub clearweb and .onion domains to threat-intel blocklists and dark-web monitoring watchlists
  • Monitor for Initial Access Broker (IAB) listings referencing your organization's sector/region on ReHub's Supermarket section
  • Flag any network access, stolen credential, or stolen financial data listings tied to your organization surfaced via dark-web monitoring feeds
  • Cross-reference ransom notes and leak-site postings from DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan against active incidents

Longer-term hardening

  • Maintain continuous dark-web/forum monitoring coverage that follows migrating cybercrime-forum populations (XSS -> RAMP -> ReHub pattern)
  • Track RaaS cartel consolidation (DragonForce/Qilin/LockBit) for shared TTP and infrastructure overlap in incident response playbooks
  • Build detection coverage for all six ReHub-sponsored ransomware families given their affiliate-driven, rapidly evolving codebases
  • Include IAB/marketplace intelligence in third-party and supply-chain risk assessments

Timeline of ReHub: Russian-Language Cybercrime Marketplace Sponsoring

  • XSS.is, a 50,000+ member Russian-language cybercrime forum, is seized in a joint operation by the French Cybercrime Brigade (BL2C), Europol, and Ukraine's SBU Cyber Department; administrator 'Toha' is arrested in Kyiv.
  • A faction of former XSS moderators launches DamageLib as a knowledge-base-only successor forum, explicitly abandoning illicit commercial trading.
  • A separate former XSS forum moderator launches ReHub as a commercially-focused alternative, embracing ransomware affiliate advertising and illicit marketplace trading that DamageLib rejected.
  • DragonForce, ReHub's primary ransomware sponsor, publicly announces a cartel partnership with Qilin and LockBit to coordinate attacks and share resources.
  • The FBI seizes the RAMP dark-web forum in coordination with the U.S. Attorney's Office for the Southern District of Florida and DOJ CCIPS; RAMP had been the primary venue for RaaS affiliate recruitment since 2021.
  • Following the RAMP seizure, the displaced ransomware-affiliate community migrates in significant numbers to ReHub, accelerating its growth as the primary ransomware marketplace destination.
  • ReHub implements a Zero Trust policy restricting new members to the Sandbox section only, tightening vetting in response to increased scrutiny and inbound migration.
  • Flashpoint publishes 'Understanding Illicit Ecosystems: Inside the ReHub Ransomware Marketplace,' documenting the forum's structure, sponsorships, and growth to over 8,300 active users, ~15,000 posts, and nearly 3,000 threads.

Sources cited for ReHub: Russian-Language Cybercrime Marketplace Sponsoring

More in threat actor

Detection coverage for TL-2026-1594

As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1594 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats