Emerging Threats in South Asia: The Rise of Mercenary Spyware and Ransomware-as-a-Service
South Asia is witnessing a surge in cyber threats, notably from mercenary spyware operations and Ransomware-as-a-Service (RaaS) groups, posing critical risks to regional security.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- South Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of March 2026, South Asia is experiencing a significant escalation in cyber threats, particularly from mercenary spyware operations and Ransomware-as-a-Service (RaaS) groups. These developments present critical challenges to regional security and necessitate immediate attention.
Mercenary Spyware Operations
Mercenary spyware groups, often referred to as "hackers-for-hire," have been increasingly active in South Asia. A notable example is the group "CostaRicto," identified by BlackBerry researchers in 2020. This group has targeted organizations across South Asia, including India, Bangladesh, and Singapore, employing custom backdoors like "SombRAT" to infiltrate systems. The adaptability and persistence of such tools indicate a long-term strategic approach to cyber espionage. (cyberscoop.com)
Another significant threat is the "CNC group," which has been orchestrating advanced cyber-espionage campaigns targeting research institutions, universities, and government organizations in South Asia. Their operations involve sophisticated phishing techniques and the deployment of custom malware, such as RCE backdoors and keyloggers, to facilitate surveillance and data theft. (cyware.com)
Ransomware-as-a-Service (RaaS) Groups
The RaaS model has gained prominence in South Asia, with several groups offering ransomware tools and infrastructure to affiliates. "CyberVolk," a pro-Russian hacktivist collective, emerged in 2024 and has claimed responsibility for over 120 attacks against various sectors, including government ministries and critical infrastructure operators. Their operations underscore the global reach and impact of RaaS groups originating from the region. (en.wikipedia.org)
Additionally, the "Kazu" ransomware group, identified in mid-2025, has rapidly gained traction by targeting government, healthcare, financial services, and public sector entities worldwide. Utilizing a double-extortion model, Kazu exfiltrates sensitive data before deploying ransomware, pressuring victims into compliance. (tatacommunications.com)
Exploitation Brokers and Commercial Offensive Tools
The proliferation of exploitation brokers has facilitated the acquisition and sale of zero-day vulnerabilities, further empowering cybercriminals and state-sponsored actors. These brokers often operate in the dark web, providing a marketplace for exploits that can be weaponized by various threat actors. The availability of such tools has lowered the barrier to entry for cyberattacks, enabling less sophisticated actors to execute complex operations.
Commercial offensive tools, including red team frameworks, have also been observed in the region. While these tools are legitimate when used for defensive purposes, their misuse by malicious actors for unauthorized access and data exfiltration poses significant risks.
Surveillance-as-a-Service
The concept of surveillance-as-a-service has emerged, where cybercriminals offer monitoring and data exfiltration services to clients. This model allows entities to conduct espionage activities without developing their own tools or infrastructure, thereby expanding the reach and impact of surveillance operations.
Conclusion
The convergence of mercenary spyware operations, RaaS groups, exploitation brokers, and surveillance-as-a-service models in South Asia presents a multifaceted and escalating cyber threat landscape. These developments necessitate enhanced regional cooperation, robust cybersecurity measures, and continuous monitoring to mitigate potential risks and safeguard critical infrastructure.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
