Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Ransomware News

The Brotherhood Introduces BloodForge RaaS: A New Player in the Ransomware Scene

September 10, 2024
Reading Time: 2 mins read
The Brotherhood Introduces BloodForge RaaS: A New Player in the Ransomware Scene

The Brotherhood, a new organization linking the underground communities of BlackForums and BloodForge RaaS, has announced its presence and future plans. With a focus on high-level ransomware operations, The Brotherhood connects BlackForums—a malware and leaks forum established in early 2023—and the soon-to-be-released BloodForge Ransomware-as-a-Service (RaaS).

Who Are The Brotherhood?

The Brotherhood positions itself as a key connector in the cybercrime landscape, aiming to bring together the established BlackForums community and the emerging BloodForge ransomware group. BlackForums, managed by @ReservedMemory, serves as a hub for discussions and exchanges around malware and data leaks. Meanwhile, BloodForge RaaS, expected to debut soon, promises to deliver advanced ransomware capabilities and evasion techniques.

Introducing BloodForge Onyx (V1)

The initial version of BloodForge RaaS, called Onyx (V1), offers a range of features that make it a formidable tool for cybercriminals:

  • Fully Undetectable (FUD): BloodForge Onyx completely evades all major antivirus solutions and automatically deletes itself after execution, ensuring stealth and minimizing traces.
  • High-Speed Encryption: It encrypts data quickly with a small payload size, facilitating rapid data takeover.
  • Enterprise-Grade Ciphers: The ransomware uses AES-256 and ChaCha20 algorithms for top-tier encryption, which makes decryption attempts nearly impossible.
  • Advanced Polymorphic Engine – BloodShift: BloodShift adapts its structure on every execution, which renders it undetectable by traditional security measures.
  • Information Grabbing: The software extracts sensitive data, including passwords and cookies, to maximize the attack’s impact.
  • Automatic Privilege Escalation: It seamlessly bypasses User Account Control (UAC) and escalates to admin privileges, granting full system control.
  • Network Worming: BloodForge spreads across networks, infecting multiple devices effortlessly.
  • Anti-Antivirus Measures: Customizable watchdog functionalities block antivirus software and disable Task Manager to prevent interference.
  • Real-Time Monitoring: Users can manage infections, monitor encryption progress, and handle ransom payments through an intuitive control panel.
  • Delayed Encryption: The ransomware offers delayed encryption options, allowing deeper system penetration before locking down files.
  • Single Execution Lock: This feature prevents redundant encryption, maintaining optimal performance and reducing system load.

Limited Availability and Pricing

BloodForge Onyx (V1) is being sold at $750 per slot, with only 10 slots available. This limited release suggests a focus on targeted operations and exclusivity, making it a highly sought-after tool.

Goals and Future Plans

The Brotherhood aims to strengthen ties between its own operations, BlackForums, and other similar groups in the cybercrime ecosystem. As BloodForge RaaS approaches its official release, The Brotherhood plans to play a pivotal role in its adoption and integration within the wider underground community.

Tags: BloodForgeRaaSransomware
ShareTweet

Related Posts

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal
Ransomware News

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal

April 27, 2026
Narteks Tekstil A.S. Suffers Krybit Ransomware Attack
Ransomware News

Narteks Tekstil A.S. Suffers Krybit Ransomware Attack

April 27, 2026
Synmosa Biopharma Hit by Dragonforce Ransomware Attack
Ransomware News

Synmosa Biopharma Hit by Dragonforce Ransomware Attack

April 27, 2026
K2 Electric Inc Targeted in Genesis Ransomware Attack
Ransomware News

K2 Electric Inc Targeted in Genesis Ransomware Attack

April 22, 2026
Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup
Ransomware News

Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup

April 22, 2026
Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk
Ransomware News

Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk

April 22, 2026
Next Post
Data Breach Hits Immigrus: 7,000 Clients’ Personal Information Exposed

Data Breach Hits Immigrus: 7,000 Clients' Personal Information Exposed

PopinBorder Database Allegedly Breached

PopinBorder Database Allegedly Breached

Recommended Stories

Evaly E-commerce Platform Allegedly Breached

Evaly E-commerce Platform Allegedly Breached

May 23, 2025
KillSec Allegedly Breaches Laxmi Capital, Demands €10,000 Ransom

KillSec Allegedly Breaches Laxmi Capital, Demands €10,000 Ransom

May 17, 2024
Alleged Leak of 1951 Stealer Logs Raises Data Privacy Concerns

Alleged Leak of 1951 Stealer Logs Raises Data Privacy Concerns

December 18, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?