ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs — Threadlinqs Intelligence
As of 2026-07-21, ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs is a medium-severity threat actor threat attributed to ReHub Forum Operators (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1594 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_ACTOR
Attribution: ReHub Forum Operators · Russia · FINANCIAL
ReHub is a Russian-language cybercrime forum and marketplace launched on August 10, 2025 by a former XSS forum moderator following the July 22, 2025 law-enforcement seizure of XSS.is. It hosts
ReHub emerged directly out of the disruption of two prior Russian-language cybercrime hubs. On July 22, 2025, a joint operation by the French Cybercrime Brigade (BL2C), Europol, and Ukraine's SBU Cyber Department seized the XSS.is forum -- a 50,000+ member marketplace whose administrator ('Toha') was arrested in Kyiv on allegations of profiting over EUR7 million from ransomware, malware, and stolen-data trade. A faction of former XSS moderators first launched DamageLib on August 1, 2025 as a knowledge-base-only successor with no commercial trading, explicitly rejecting illicit commerce. Nine days later, on August 10, 2025, a separate former XSS moderator launched ReHub instead as a commercially-focused alternative, positioning it as 'free from state and law enforcement interference' and framing surviving XSS mirror iterations as compromised or monitored.
ReHub operates on both the clearweb and via a Tor (.onion) hidden-service mirror. It is organized into distinct sections: Sandbox (entry-level OPSEC/fraud-logistics discussion, and since a mid-April 2026 Zero Trust policy change the only section new members can access), Technical (network vulnerabilities, AI jailbreaking, deepfake social engineering, carding), Programming (malicious tooling and automation development), Library (leaked databases, cracked utility software, aggregated security news), Supermarket (the commercial core -- ransomware affiliate-program threads and paid illicit services), Arbitration (dispute resolution and a 'Black List' scammer registry standard to Russian-language cybercrime forums), and Administration. Paid membership tiers exist: 'Premium' (gold, $100/year) grants custom titles and unlimited post editing; 'Patron' (pink/magenta, $5,000/year) grants custom profile styling and personal profile links -- a monetization model mirroring earlier elite forums like Exploit and XSS.
The forum's growth was sharply accelerated by the January 28, 2026 FBI seizure of the RAMP (Ransom Anon Market Place) forum, executed with the U.S. Attorney's Office for the Southern District of Florida and DOJ CCIPS. RAMP had operated since 2021 as the only major dark-web forum explicitly permitting RaaS program advertising, hosting affiliate recruitment for Qilin, LockBit, DragonForce, RansomHub, ALPHV/BlackCat, Anubis, and CHAOS, among others. Its nameservers were repointed to ns1/ns2.fbi.seized.gov, and one alleged RAMP operator publicly confirmed the takedown, writing it 'destroyed years of my work to create the most free forum in the world.' The RAMP disruption pushed its displaced ransomware-affiliate community to ReHub, which had already positioned itself as a commerce-friendly Supermarket-style venue.
ReHub's Supermarket section now hosts affiliate-recruitment threads for six active ransomware brands, several of which are themselves recent splinters or rebrands of earlier disrupted operations, reflecting the underground's rapid reconstitution cycle:
- DragonForce: a RaaS group active since 2023 that declared itself a ransomware 'cartel' on March 19, 2025, letting affiliates white-label DragonForce's builder/infrastructure under their own brand while paying a reduced 0-23% cartel fee (versus the ~20% RaaS industry standard) or up to 80% affiliate payout under other terms. In September 2025, DragonForce announced a formal cartel partnership with Qilin and LockBit to coordinate attacks, share resources, and suppress conflicts between affiliates. By June 2026, DragonForce had accumulated 579 confirmed victims (216 in H1 2026 alone), targeting organizations with >$15M revenue across manufacturing, construction, IT services, healthcare, and retail. DragonForce's logo is permanently displayed on ReHub's homepage as its primary sponsor.
- DevMan: emerged April 2025 as a DragonForce/Conti-lineage variant -- DEVMAN's codebase derives from a leaked DragonForce builder, which itself derives from Conti. DevMan operated first as a multi-RaaS affiliate across Qilin, DragonForce, A
Target sectors: manufacturing, construction, informationtechnology, health, retail, professionalservices, government administration, criticalinfrastructure, financialservices
Target regions: Global, North America, Europe, Asia-Pacific, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, MEDIUM, threat intelligence, cybersecurity, T1585, T1583, T1650, T1588, T1588, T1586, T1591, T1078, T1133, T1566