News Room
16
Share
criticalOffensive Tools

Emerging Threats in South Asia: The Rise of Mercenary Spyware and Ransomware-as-a-Service

South Asia is witnessing a surge in cyber threats, notably from mercenary spyware operations and Ransomware-as-a-Service (RaaS) groups, posing critical risks to regional security.

29 March 2026Last updated 29 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
South Asia
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

As of March 2026, South Asia is experiencing a significant escalation in cyber threats, particularly from mercenary spyware operations and Ransomware-as-a-Service (RaaS) groups. These developments present critical challenges to regional security and necessitate immediate attention.

Mercenary Spyware Operations

Mercenary spyware groups, often referred to as "hackers-for-hire," have been increasingly active in South Asia. A notable example is the group "CostaRicto," identified by BlackBerry researchers in 2020. This group has targeted organizations across South Asia, including India, Bangladesh, and Singapore, employing custom backdoors like "SombRAT" to infiltrate systems. The adaptability and persistence of such tools indicate a long-term strategic approach to cyber espionage. (cyberscoop.com)

Another significant threat is the "CNC group," which has been orchestrating advanced cyber-espionage campaigns targeting research institutions, universities, and government organizations in South Asia. Their operations involve sophisticated phishing techniques and the deployment of custom malware, such as RCE backdoors and keyloggers, to facilitate surveillance and data theft. (cyware.com)

Ransomware-as-a-Service (RaaS) Groups

The RaaS model has gained prominence in South Asia, with several groups offering ransomware tools and infrastructure to affiliates. "CyberVolk," a pro-Russian hacktivist collective, emerged in 2024 and has claimed responsibility for over 120 attacks against various sectors, including government ministries and critical infrastructure operators. Their operations underscore the global reach and impact of RaaS groups originating from the region. (en.wikipedia.org)

Additionally, the "Kazu" ransomware group, identified in mid-2025, has rapidly gained traction by targeting government, healthcare, financial services, and public sector entities worldwide. Utilizing a double-extortion model, Kazu exfiltrates sensitive data before deploying ransomware, pressuring victims into compliance. (tatacommunications.com)

Exploitation Brokers and Commercial Offensive Tools

The proliferation of exploitation brokers has facilitated the acquisition and sale of zero-day vulnerabilities, further empowering cybercriminals and state-sponsored actors. These brokers often operate in the dark web, providing a marketplace for exploits that can be weaponized by various threat actors. The availability of such tools has lowered the barrier to entry for cyberattacks, enabling less sophisticated actors to execute complex operations.

Commercial offensive tools, including red team frameworks, have also been observed in the region. While these tools are legitimate when used for defensive purposes, their misuse by malicious actors for unauthorized access and data exfiltration poses significant risks.

Surveillance-as-a-Service

The concept of surveillance-as-a-service has emerged, where cybercriminals offer monitoring and data exfiltration services to clients. This model allows entities to conduct espionage activities without developing their own tools or infrastructure, thereby expanding the reach and impact of surveillance operations.

Conclusion

The convergence of mercenary spyware operations, RaaS groups, exploitation brokers, and surveillance-as-a-service models in South Asia presents a multifaceted and escalating cyber threat landscape. These developments necessitate enhanced regional cooperation, robust cybersecurity measures, and continuous monitoring to mitigate potential risks and safeguard critical infrastructure.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo