PLANO, Texas — Ransomware gangs—which continue to plague credit unions and their vendors and to breach or partially breach systems–are increasingly rebranding themselves with new names and identities to evade law enforcement and cybersecurity defenses, creating new challenges for businesses already facing a growing wave of cyberattacks, according to a new report.
The Wall Street Journal reported that while cybercriminals have long changed identities after disruptions or law enforcement actions, the practice is becoming more common as artificial intelligence and advanced security tools make it easier for defenders to identify established hacking groups and recognize attack patterns.

According to cybersecurity firm ZeroFox, cited by The Wall Street Journal, organizations worldwide experienced 1,885 ransomware and data-extortion attacks during the past three months, up from 1,363 during the same period a year earlier and 1,186 in 2024.
‘Constantly Reinventing Themselves’
“Cybercriminal groups are constantly reinventing themselves,” Brian Carlson, chief technology, data, digital and innovation officer for North America at Sodexo, told The Wall Street Journal. He said organizations “can’t rely on yesterday’s defenses to address today’s threats.”
The publication reported that ransomware groups often adopt new names after website takedowns, sanctions, media scrutiny or declining trust within the cybercrime marketplace. Steven Masada, assistant general counsel in Microsoft’s digital crimes unit, told the newspaper that rebranding frequently extends beyond a new name to include changes in infrastructure providers, communications platforms, malware, payment methods and even business models.
Masada said AI and automation are lowering the barriers for cybercriminals, allowing threat actors to evolve more quickly and making rebranding an increasingly common tactic, according to The Wall Street Journal.
‘GodDamn Ransomware’
The report also cited research released Thursday by cybersecurity firm Symantec that linked a ransomware group known as GodDamn Ransomware to the previously identified Beast group, which itself evolved from a ransomware operation known as Monster that first appeared in 2022.
According to Symantec, GodDamn Ransomware uses many of the same techniques as its predecessors, including disabling Microsoft Windows security protections before encrypting files and demanding ransom payments.
Carlson told The Wall Street Journal that organizations should focus less on predicting the next ransomware brand and more on continuously adapting their defenses.
“The organizations best positioned to defend themselves aren’t the ones trying to predict every new group or tactic,” he told the newspaper. “They’re the ones that are continuously learning, adapting and responding as the threat landscape evolves.”




