The main signs are continued wallet activity, reuse of the same addresses across multiple incidents, and transaction patterns that move funds into the same exchanges or cash out points after an attack. On the defensive side, recurring matches to known indicators, repeated phishing or intrusion tactics, and new victim reports tied to the same cluster all suggest the network remains active.
What to look for after a designation
Post-designation activity is usually visible through continuity, not a single smoking gun. The strongest signals are that the infrastructure still behaves like an active operational chain: wallets continue moving, the same receiving endpoints reappear, and funds still route through the same exchanges or cash-out points. That matters because designation is a disruption event, not proof that the network has been dismantled.
A useful practical distinction is between dormant infrastructure and reconstituted infrastructure. If the same cluster keeps generating victims, reusing phishing or intrusion tradecraft, or resurfacing with closely related payment paths, the underlying operation is still intact enough to support abuse, even if individual nodes, domains, or accounts have changed.
For readers tracking reuse patterns in adjacent identity and access cases, the same logic applies to compromised non-human credentials: reuse and persistence are the signs that matter more than one-off technical churn. NHIMG’s Ultimate Guide to Non-Human Identities is useful background on why stale, reused, or overexposed secrets remain operationally dangerous over time. One relevant data point from that guide is that 91.6% of secrets remain valid five days after the targeted organisation is notified, which illustrates how slowly real-world remediation can trail exposure.
Why sanctions do not stop the infrastructure immediately
Sanctions or designations change the legal and operational environment, but they do not automatically sever access, liquidity, or tradecraft. A sanctioned ransomware ecosystem can keep functioning if it still has wallet control, exchange access through intermediaries, mirrored payment routes, or enough operational resilience to rotate assets faster than defenders can attribute and freeze them.
That is why practitioners should expect partial adaptation rather than clean shutdown. Infrastructure often fragments into smaller payment clusters, alternate laundering routes, short-lived domains, or proxy services. The underlying question is whether the campaign can still convert intrusion activity into money or leverage. If that conversion path still exists, the designation has not fully neutralised the operation.
- Wallet continuity indicates retained financial control.
- Repeated recipient addresses suggest reused operational infrastructure.
- Shared exchanges or cash-out points imply the same monetisation channel is still being used.
- Recurring victimology and intrusion patterns suggest the same crew, or its close operators, remains active.
External threat reporting helps confirm that ransomware groups commonly adjust infrastructure and tactics rather than stopping after disruption measures. CISA cyber threat advisories and the ENISA Threat Landscape both provide the broader context for how threat actors persist, rotate tooling, and reuse access paths after public exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1657 — Financial Theft | Ransomware infrastructure persistence is ultimately about converting access into illicit funds. |
| T1071 — Application Layer Protocol | Repeated infrastructure reuse often shows up through consistent comms and payment-support traffic patterns. | |
| Recommendation — Map recurring cash-out routes to T1657 and trace the financial transfer chain. Hunt for repeated application-layer traffic patterns that indicate the same operator-controlled infrastructure. | ||
| CIS Controls v8 | 8 — Audit Log Management | Repeated wallet, exchange, and incident linkage depends on retained evidence and correlation records. |
| Recommendation — Retain and correlate logs that connect wallet activity, intrusion events, and victim reports. | ||
| NIST CSF 2.0 | DE.CM — Security Continuous Monitoring | Ongoing monitoring is needed to spot post-designation reuse and reactivation of the same cluster. |
| RS.AN — Analysis | Analysts must determine whether repeated activity reflects the same active ransomware cluster. | |
| Recommendation — Continuously monitor for reused indicators and reappearing payment infrastructure. Analyze recurring indicators to confirm whether the same cluster remains operational. | ||
Practitioner Guidance
What to verify: Treat designation as one input, not the endpoint. The highest-value verification is whether the same wallet clusters, cash-out routes, or victim-facing infrastructure are still appearing together over time, because that pattern is more reliable than any single observed transaction or domain.
Decision rule: If attribution shows the same cluster continuing to move funds or repeat intrusion patterns after designation, treat the network as active and prioritise containment, tracing, and disruption support over narrative-only monitoring.
What to measure: Track recurrence rate, address reuse, and time-to-reappearance across incidents. A rising pattern of reuse after public designation is a stronger operational signal than a one-time spike in noise or a lone associated address.
Practitioner takeaway: Designation raises friction, but continued wallet reuse and repeated operational patterns are what prove the infrastructure is still alive, so focus on corroborated cluster behaviour rather than on whether the actor has simply changed labels or addresses.
Related resources from NHI Mgmt Group
- Who is accountable when a SaaS app still has access to sensitive health data after it is no longer used?
- What are the signs that AI infrastructure is being used for unauthorised model abuse?
- What are the signs that an attacker is still active after a password or MFA reset?
- What are the signs that an account is being used for persistence after compromise?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org