Zscaler Blog

Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang

Partner

TRM Labs and Zscaler ThreatLabz Join Forces to Track Cybercrime and Nation-State Blockchain Activity

image
THREATLABZ
Oktober 06, 2026 - 3 min read

Key takeaways

  • TRM Labs and Zscaler ThreatLabz are partnering to combine leading threat intelligence with advanced blockchain investigations, enabling technical analysis and threat actor attribution to be correlated with the flow of cryptocurrency funds.
  • Ransomware is a key focus area of the partnership, enabling continuous tracking of threat actors across rebrands and shifting aliases.
  • The collaboration will produce co-authored research, briefings, and insights for the wider security community.

Zscaler ThreatLabz and TRM Labs are partnering to combine leading cyber threat intelligence with advanced onchain analysis. By linking threat actor activity directly to cryptocurrency transactions, this collaboration delivers deeper visibility and fosters a better understanding of ransomware, nation-state actors, and other cybercriminal threats. Threat intelligence and onchain intelligence each provide different views into the adversary. In isolation, links between cyber attacks and cryptocurrency transactions can be harder to identify, but together they support a more comprehensive view into a threat actor’s operations.

Cyber attacks are part of an ecosystem of criminals and nation-state threat actors, and the networks that support them. However, all of these attacks heavily rely on cryptocurrency to pay for services such as hosting, tooling, and ransom demands. The Zscaler ThreatLabz and TRM Labs partnership will foster end-to-end investigations that provide unprecedented insights into this ecosystem.

Closing gaps between attacks and onchain investigations

Tracking ransomware and nation-state groups is a key focus of the Zscaler ThreatLabz and TRM partnership. ThreatLabz tracks these groups through malware code analysis, infrastructure, attacker behavior, and evolving tactics, techniques, and procedures (TTPs). TRM Labs brings onchain intelligence on the groups’ cryptocurrency transactions themselves, mapping the financial activity and networks associated with the flow of funds.

Our combined intelligence has already closed gaps in ransomware analytics by connecting operational activity with monetization and victim payment trends. In the newly-released ThreatLabz 2026 Ransomware Report, ThreatLabz and TRM Labs analyzed known victim ransom payments from April 2025 through March 2026, revealing a ransom economy that is thriving. Total known ransom exceeded USD 327.8M over the last year. In addition, the average payment per victim increased year-over-year by 5.3% to USD 431.9K.

Nation-state activity is another important focus. Intelligence from both teams can help attribute activity to state-backed actors and track related campaigns over time as state-sponsored operations become more complex, and as they increasingly leverage blockchains to conduct financial transactions and hijack cryptocurrency. 

Advancing ransomware and nation-state research 

This partnership will strengthen intelligence and analysis on cybercrime, ransomware, and nation-state activity, giving the security community more actionable context on how threat actors operate and monetize their activity. Focus areas will include:  

  • Ransomware ecosystem analysis that tracks leading ransomware groups, affiliates, and emerging families, and shifts in TTPs and monetization. 
  • Blockchain technology abuse including techniques like EtherHiding that turn the blockchain into a resilient command-and-control fallback mechanism.
  • Nation-state research that uses intelligence from both teams to link targeted attacks with cryptocurrency transactions.
  • Intelligence sharing and reporting that enriches active investigations with additional threat context and delivers validated findings to the wider security community. 

As ransomware groups disappear, splinter into affiliates, and re-form, and as state-backed actors change infrastructure and tradecraft, maintaining continuity across investigations becomes harder. By closing these intelligence gaps, ThreatLabz and TRM Labs provide defenders with a stronger basis for recognizing persistent threats, prioritizing risk, and responding more effectively.

form submtited
Danke fürs Lesen

War dieser Beitrag nützlich?

Haftungsausschluss: Dieser Blog-Beitrag wurde von Zscaler ausschließlich zu Informationszwecken erstellt und wird ohne jegliche Garantie für Richtigkeit, Vollständigkeit oder Zuverlässigkeit zur Verfügung gestellt. Zscaler übernimmt keine Verantwortung für etwaige Fehler oder Auslassungen oder für Handlungen, die auf der Grundlage der bereitgestellten Informationen vorgenommen werden. Alle in diesem Blog-Beitrag verlinkten Websites oder Ressourcen Dritter werden nur zu Ihrer Information zur Verfügung gestellt, und Zscaler ist nicht für deren Inhalte oder Datenschutzmaßnahmen verantwortlich. Alle Inhalte können ohne vorherige Ankündigung geändert werden. Mit dem Zugriff auf diesen Blog-Beitrag erklären Sie sich mit diesen Bedingungen einverstanden und nehmen zur Kenntnis, dass es in Ihrer Verantwortung liegt, die Informationen zu überprüfen und in einer Ihren Bedürfnissen angemessenen Weise zu nutzen.

Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang

Mit dem Absenden des Formulars stimmen Sie unserer Datenschutzrichtlinie zu.