Threat Groups
708 tracked groups
qilin
Qilin (also known as Agenda) is a ransomware-as-a-service operation that emerged in 2022, initially targeting healthcare...
lockbit3
LockBit 3.0 (also known as LockBit Black) is the third major iteration of the LockBit ransomware-as-a-service platform, ...
akira
Akira ransomware first appeared in March 2023 and quickly became one of the most active groups of that year, targeting s...
play
Play ransomware (also known as PlayCrypt) emerged in mid-2022 and is characterized by its use of the ".play" file extens...
clop
Clop (also spelled Cl0p) is a financially motivated ransomware group attributed to the FIN11/TA505 threat cluster with a...
thegentlemen
The Gentlemen is a ransomware-as-a-service group that emerged in mid-2024 and rapidly accumulated victims across North A...
alphv
ALPHV (also known as BlackCat or Noberus) was a sophisticated ransomware-as-a-service operation launched in November 202...
incransom
INC Ransom (INCransom) is a double-extortion ransomware group that emerged in mid-2023, targeting healthcare, education,...
medusa
Medusa ransomware (not to be confused with MedusaLocker) is a ransomware-as-a-service operation that became highly activ...
lockbit2
LockBit 2.0 (also known as LockBit Red) was the second major version of the LockBit ransomware-as-a-service platform, ac...
8base
8Base is a double-extortion ransomware group that first appeared in early 2022 but dramatically escalated activity in mi...
ransomhub
RansomHub is a ransomware-as-a-service operation that launched in February 2024 and rapidly became one of the most activ...
blackbasta
Black Basta emerged in April 2022 and is widely assessed by researchers and law enforcement to be composed of former Con...
dragonforce
DragonForce is a ransomware-as-a-service operation with roots in a Malaysian hacktivist group of the same name that was ...
safepay
SafePay is a double-extortion ransomware group that emerged in late 2024, quickly attracting attention for its professio...
everest
Everest is a Russian-speaking ransomware and data extortion group active since at least 2020, known for targeting critic...
lynx
Lynx is a ransomware-as-a-service operation that emerged in mid-2024 and is assessed to be a rebrand or direct successor...
sinobi
Sinobi is a data extortion and ransomware group that emerged in 2024 and is assessed to have inherited personnel and cod...
lockbit5
LockBit 5.0 (also referred to as LockBit Nation-State) is a claimed successor to LockBit 3.0 that emerged after Operatio...
cactus
Cactus ransomware surfaced in March 2023 and quickly gained attention for exploiting vulnerabilities in Qlik Sense analy...
killsec
KillSec (Kill Security) is a hacktivist-turned-cybercriminal group that emerged in late 2023, linked by researchers to I...
bianlian
BianLian ransomware first appeared in June 2022 and is attributed by multiple researchers and the FBI/CISA to a China-ba...
rhysida
Rhysida is a ransomware group that emerged in May 2023, quickly gaining notoriety for attacking healthcare providers and...
conti
Conti was one of the most prolific and financially damaging ransomware operations in history, attributed by the FBI and ...
dispossessor
Dispossessor (also tracked as Radar) was a ransomware-adjacent data extortion operation active from August 2023 until it...
blacksuit
BlackSuit is the rebranded continuation of the Royal ransomware operation, confirmed by CISA and FBI in an August 2024 j...
nightspire
Nightspire is a relatively new double-extortion ransomware group that emerged in early 2025 and has quickly accumulated ...
killsec3
handala
Handala (also known as Handala Hack Team or Hatef) is an Iran-linked hacktivist group that emerged during the Israel-Ham...
hunters
Hunters International emerged in October 2023 and is widely assessed to be a rebrand or direct continuation of the Hive ...
nova
Nova (formerly known as RALord) is a ransomware-as-a-service operation that rebranded from RALord in late 2024. The grou...
pysa
PYSA (also known as Mespinoza) is a ransomware group active since 2019 that has primarily targeted education, healthcare...
stormous
Stormous is a pro-Russian hacktivist and ransomware group that emerged around mid-2021, believed to include members from...
worldleaks
WorldLeaks is the rebranded continuation of Hunters International, launched in January 2025 after the group ceased file-...
FOG
FOG ransomware is a sophisticated strain first observed in May 2024, initially targeting US educational institutions bef...
ransomhouse
RansomHouse is a data extortion group and marketplace active since December 2021 that focuses on stealing data without n...
sarcoma
Sarcoma is a double-extortion ransomware group that emerged in mid-2024, primarily targeting manufacturing, professional...
funksec
FunkSec is an Algerian ransomware group that emerged in late 2024 and quickly generated a high victim count through a co...
royal
Royal ransomware was active from September 2022 to mid-2023 and is believed to have been formed by former members of the...
spacebears
SpaceBears is a data extortion group that emerged in 2024, focusing on stealing and publishing sensitive corporate data ...
devman
Devman is a former RansomHub and INC Ransom affiliate that began operating independently as a ransomware-as-a-service pl...
hive
Hive was a major ransomware-as-a-service operation active from June 2021 until January 2023, targeting over 1,500 organi...
beast
Beast ransomware operates as a ransomware-as-a-service platform targeting Windows, Linux, and VMware ESXi environments. ...
coinbasecartel
CoinbaseCartel (also known as CoinBase Cartel) is a financially motivated cybercrime group that operates a data acquisit...
vicesociety
Vice Society is a ransomware group that was active from mid-2021 to 2023, distinguished by its heavy focus on the educat...
blackbyte
BlackByte is a ransomware-as-a-service operation first observed in July 2021, assessed to be Russia-linked and notable f...
meow
Meow ransomware is a strain that emerged in 2022, appending the ".MEOW" extension to encrypted files and primarily targe...
shinyhunters
ShinyHunters is a prolific data theft and extortion group responsible for numerous high-profile breaches including the 2...
malas
Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its
avaddon
Avaddon was a ransomware-as-a-service operation active from June 2020 to June 2021, when the operators unexpectedly shut...
snatch
Snatch ransomware (not to be confused with the 2022 data extortion group reusing the brand) is a Russia-linked operation...
apt73
APT73 is a ransomware group that operated under the "eraleign" identity before rebranding as Bashe in October 2024. Some...
eldorado
Eldorado is a ransomware-as-a-service operation that emerged in early 2024, offering both Windows and VMware ESXi encryp...
threeam
3AM (ThreeAM) is a ransomware group discovered in September 2023, first observed being deployed as a fallback when LockB...
genesis
Financial interests only. <br/> We do not provide or work with affiliate programs, no collaborations either. <br/...
noescape
NoEscape was a ransomware-as-a-service operation that launched in June 2023 and is assessed by multiple researchers to b...
anubis
Anubis ransomware emerged in 2024 as a data extortion and ransomware-as-a-service platform that distinguishes itself wit...
krybit
Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with suppo
monti
Monti is a ransomware group that emerged in June 2022, widely assessed to be a copycat or offshoot of the Conti operatio...
deadlock
interlock
Interlock ransomware emerged in late 2024 and is notable for deploying a custom ransomware variant that targets both Win...
ransomexx
RansomExx (also known as Defray777) is a ransomware family that targeted multiple high-profile organizations including K...
babuk2
Babuk 2.0 (also styled as Babuk Locker 2.0 or SatanLock) is a group that impersonates the original Babuk ransomware oper...
direwolf
DirewWolf is a recently emerged double-extortion ransomware group that conducts targeted attacks against medium to large...
pear
PEAR (Pure Extraction And Ransom) Team is a data extortion group that emerged in 2024, focusing on publishing stolen cor...
kairos
Kairos is a double-extortion ransomware group that emerged in 2024, operating a dark web leak site and targeting organiz...
SilentRansomGroup
SilentRansomGroup (SRG) is a former Conti team that continued operating independently following Conti's dissolution in 2...
wannacry
WannaCry was a destructive ransomware worm deployed in May 2017 that infected over 200,000 computers across 150 countrie...
revil
REvil (also known as Sodinokibi) was one of the most financially damaging ransomware-as-a-service operations in history,...
abyss
Abyss (Abyss Data) is a data extortion group that emerged in early 2023, focusing on stealing and publishing sensitive c...
arcusmedia
Arcus Media is a ransomware-as-a-service operation that first emerged in May 2024, offering affiliates a Linux and Windo...
payload
Payload is a ransomware group that emerged in 2024, primarily targeting organizations in North America and Europe throug...
CRPxO
CRPxO is actively recruiting affiliates, offering: 🔹 70% revenue share 🔹 XMR/BTC payouts 🔹 Claimed payouts within 24 ...
cuba
Cuba ransomware is a ransomware-as-a-service operation active since at least 2019, assessed to be Russia-linked despite ...
ragnarlocker
RagnarLocker was a Russia-linked ransomware group active from 2019 to 2023, known for conducting its own intrusions with...
avoslocker
AvosLocker is a ransomware-as-a-service operation that launched in mid-2021, known for targeting critical infrastructure...
chaos
Chaos ransomware operates as a ransomware-as-a-service builder that has been widely distributed on underground forums si...
embargo
Embargo is a ransomware-as-a-service operation that emerged in mid-2024, utilizing Rust-based encryptors for both Window...
losttrust
LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within da
payoutsking
Payouts King Group is a data extortion collective that explicitly states it does not operate as a RaaS and does not use ...
warlock
Warlock ransomware emerged in mid-2025 and has been attributed by Microsoft, Sophos, and Trend Micro with moderate-to-hi...
AiLock
AiLock is a ransomware-as-a-service group that emerged in early 2025, marketing itself as AI-assisted and suspected by r...
cicada3301
Cicada3301 (unrelated to the 2012 internet puzzle) is a ransomware-as-a-service operation that emerged in June 2024 with...
ransomed
RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims inclu
toufan
Toufan (also known as Toufan Al-Aqsa) is an Iran-linked hacktivist group that emerged during the Israel-Hamas conflict i...
insomnia
Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organ
knight
Knight is a Ransomware-as-a-Service (RaaS) operation first observed in August 2023, believed to be a rebrand or evolutio...
raworld
RA World (formerly known as RA Group, active since April 2023) is a ransomware operation linked by Symantec and Palo Alt...
CMDOrganization
CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all...
cloak
Cloak is a cybercriminal ransomware group that first emerged in late 2023, targeting small to mid-size businesses across...
braincipher
BrainCipher ransomware surfaced in mid-2024, initially gaining attention for a major attack against Indonesia's National...
gunra
Gunra is an emerging ransomware group first identified in April 2025. It employs a classic double-extortion model—encryp...
karakurt
Karakurt is a data extortion group established in 2021 as an offshoot of the Conti ransomware operation (Wizard Spider),...
lv
parser needs to be built
quantum
Quantum ransomware emerged in August 2021 as a rebrand of the MountLocker operation and was subsequently linked to the C...
settra
tengu
Ransomware group active in data extortion.
lorenz
Lorenz is a ransomware group active since early 2021, known for an unusual tactic of selling access to victim networks t...
blacklock
BlackLock (also known as Mamona) is a ransomware-as-a-service operation that emerged in late 2023 as an evolution of the...
darkvault
DarkVault is a versatile threat actor that emerged in 2024, conducting both ransomware and data extortion operations aga...
securotrop
Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while mainta
trigona
Trigona ransomware was active from late 2022 to 2023, targeting businesses across multiple sectors with AES encryption a...
crypto24
aka Public Data Storage <br/>Crypto24 emerged in early 2025 as a fast-growing double-extortion ransomware-as-a-service ...
frag
Frag ransomware emerged in late 2024, primarily observed exploiting Veeam Backup & Replication vulnerabilities (CVE-2024...
obscura
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via
leakeddata
metaencryptor
We are a group of young people who identify themselves as specialists in the field of network security with at least 15 ...
m3rx
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in
maze
Maze ransomware pioneered the double-extortion model in late 2019, becoming the first major group to combine file encryp...
nitrogen
Nitrogen is a data extortion group that emerged in 2023, primarily conducting data theft without encryption to pressure ...
termite
Termite is a ransomware group that emerged in late 2024, gaining attention for exploiting a zero-day vulnerability in Cl...
donutleaks
DonutLeaks is a data extortion group that emerged in 2022, publishing stolen data from organizations that refused to pay...
dAn0n
dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model...
global secret group
blacknevas
BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct deriv...
blackshrantac
aka black shrantac
lamashtu
Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Roma
aurora
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams fro
bravox
Ransomware group active in data extortion.
J
J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 includi
dragonransomware
Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a...
medusalocker
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predec...
ryuk
Ryuk ransomware is attributed to the Russia-based Wizard Spider cybercriminal group and was one of the most damaging ran...
spook
Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on th
darkleakmarket
DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransom
mallox
Mallox (also known as TargetCompany, Fargo, or Tohnichi) is a ransomware-as-a-service operation assessed to be China-lin...
moneymessage
Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional
alphalocker
AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin pane
eraleign (apt73)
Eraleign (APT73) rebranded as Bashe in October 2024 after operating under the Eraleign name, with the transition coincid...
midas
Midas ransomware is a data extortion group active since late 2021 that shares significant technical similarities with th...
fulcrumsec
FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration
helldown
Helldown is a double-extortion ransomware group that emerged in late 2024, known for exploiting vulnerabilities in Zyxel...
lapsus$
Lapsus$ is a data extortion group that emerged in late 2021, known for social engineering, SIM-swapping, and insider rec...
IMNCrew
IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial service
nokoyawa
Nokoyawa ransomware is a strain active from early 2022 that shares significant code and infrastructure with the Karma an...
radar
Radar (also known as Dispossessor), active since August 2023 and led by an actor called "Brain," was a RaaS group target
werewolves
Werewolves is a Russia-linked ransomware group that emerged in mid-2023, using a modified version of the LockBit 3.0 sou...
ciphbit
CiphBit is a ransomware operation first detected in early 2024, using a custom encryptor targeting Windows and network s...
titan
Founded 4 April 2026
blackmatter
BlackMatter was a ransomware-as-a-service operation active from July to November 2021, widely assessed as a direct rebra...
exfilsquad
Only exfiltration
morpheus
Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCa
marketo
Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or ba
Orova
Emerging actor candidate first observed 2026-07-07; no verified public victim disclosure yet.
daixin
Daixin Team is a ransomware and data extortion group active since mid-2022, primarily targeting the US healthcare and pu...
ShadowByt3$
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communic
arvinclub
Arvin Club first appeared around early to mid-2021, debuting on its Tor leak site with posts dating back to May 5, 2021....
cephalus
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomwar
orion
Jan13, 2026: We believe the group might be related to Babuk-Bjorka.
trinity
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaC
vect
VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a f
madliberator
Group is also currently known as MADDLL32 and Metatron.
ALP-001
⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified. WE HAVE DECIDED TO REMOVE
global
Now a RaaS by BlackLock ($$$). <br/>Global Group is a newly emerged Ransomware-as-a-Service (RaaS) platform that debuted...
leaknet
<br/> <br/>In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside infor...
suncrypt
SunCrypt is a ransomware group active since 2019 that joined the Maze ransomware cartel in 2020, adopting the double-ext...
xinglocker
xing use a custom mountlocker exe
dunghill
Dunghill Leak is the publicly branded data leak site (DLS) operated by the Dark Angels ransomware group, established cir...
ralord
RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, edu
bavacai
brotherhood
Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia ac
cyclops
Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023. It operates as a Ransomwar...
d4rk4rmy
D4rk4rmy is a data-extortion focused threat actor that emerged in mid-2025, targeting high-profile organizations across ...
doppelpaymer
DoppelPaymer ransomware is attributed to the Russia-based Evil Corp cybercriminal organization and is a successor to Bit...
kelvinsecurity
Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and web...
netwalker
NetWalker (also known as Mailto) was a ransomware operation active from 2019 to January 2021, when US and Bulgarian auth...
leaktheanalyst
LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims,
tridentlocker
TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of r
unsafe
A group which seems to recycle leak from other ransomware groups
VanHelsing
VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and s
sabbath
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebran
siegedsec
Not a ransomware group but a hacktivist group that appeared coincidentally days before Russia’s invasion of Ukraine
weyhro
Appears to be a Data Extortion group with no encryption.
atomsilo
AtomSilo emerged in September 2021 and ceased operations by year-end 2021. It functioned with a double‑extortion model, ...
booba team
cheers
Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi ...
LeakBazaar
mogilevich
Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, bu
payloadbin
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix line
teamxxx
TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, ag
benzona
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organization
cryptbb
CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to
flocker
Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows
hellcat
HellCat is a ransomware-as-a-service operation that emerged in late 2024, with KELA researchers identifying core operato...
mountlocker
MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and
underground
Underground ransomware (also known as Underground Team) is a Russia-linked group associated with the RomCom RAT threat c...
cipherforce
For those out of the loop, you may already know us as TeamPCP or Shellforce, we have been active a while publishing data...
datacarry
DataCarry is a newly observed ransomware and data-extortion operation, first seen in May 2025. It operates a double-exto...
freecivilian
FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukr
groove
Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its agg...
icarus
samsam
azroteam
darkrace
DarkRace is a moderately destructive ransomware strain observed since 2024. It encrypts files and appends a randomized e...
RunSomeWares
RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain ser
secp0
Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only
skira
Skira is a small ransomware group that emerged around late 2024, claiming responsibility for the breach of Carruth Compl
apos
Apos ransomware surfaced in April 2024 and is best characterized as a data‑broker or leak‑only operation, rather than a ...
arkana
Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband pro
blackout
Blackout surfaced in February 2024, using a variant based on DarkSide and BlackMatter ransomware source code, establishi...
nefilim
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is remov...
redransomware
Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across
sparta
Sparta is a short-lived ransomware group first observed in September 2022 that conducted double-extortion attacks primar
darkside
FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable dis...
linkc
Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based
malekteam
Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel),
mosesstaff
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation a
ms13089
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Secu
storm
Black X
crazyhunter
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, ex
doommageddon
Direct Extortion Double Extortion
qiulong
Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double ex
radiant
Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extort
secpo
0day Syndicate
bitpaymer
blackwater
Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and target
cryp70n1c0d3
Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology,
dataleak
Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited
donex
Donex is a ransomware family that emerged in early 2022 as a rebrand of the older Muse ransomware. It uses a double-exto...
icefire
IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability
l group
mindware
Ransomware, potential rebranding of win.sfile.
netrunner
NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunicat
onyx
Onyx is a ransomware group first observed in April 2022, based on the Chaos ransomware builder, that is notably destruct
osiris
Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driv
panzer
3am
3AM, also known as ThreeAM, is a relatively new ransomware family that emerged in late 2023, initially deployed as a fal...
AuditTeam
AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and
babuk
Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most us
chort
Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning ...
cryptnet
CryptNet is a newer Ransomware-as-a-Service (RaaS) operation first identified in April 2023. It follows a double-extorti...
cryptolocker
ethics
kraken
Kraken leak blog (hellokitty) <br/>Kraken is a ransomware family first observed in August 2018 as a Ransomware-as-a-Serv...
mnt6
MNT6 is a lower-profile ransomware group claiming victims across legal, manufacturing, construction, healthcare, and log
pay2key
Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, tar
projectrelic
Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-b
rebornvc
RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion
rook
Ransomware.
silent
Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own...
TiMc
TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader S
argonauts
Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics,
bert
BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux sy...
darkpower
Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations ac...
helix
raznatovic
RANSOMED.VC aka Raznatovic
ValenciaLeaks
Official twitter account: https://x.com/ValenciaLeaks72
wallstreet
xp95
XP95 is a cyber-extortion group that emerged in March 2026, using a pure data-theft-and-extortion model with a Windows X
yanluowang
Ransomware.
0mega
0mega is a ransomware group first observed in May 2022, operating with a double extortion model: <br/>* Encrypting victi...
barracuda
Booba Project
Booba
bqtlock
aka BaqiyatLock <br/>BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a...
cryptowall
d1r
D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion
exitium
Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targetin
gammax
karma
Karma is a ransomware group first observed in November 2021, operating a double-extortion model that combines data theft...
kawa4096
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education
lunalock
LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplac
minteye
MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction
orca
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targe
redalert
RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware
scarab
snake
thegreenbloodgroup
blackbyte-crux
Crux is a newly identified ransomware variant active since July 2025, which claims affiliation with the established Blac...
blackshadow
BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2...
desolator
Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America
dharma
Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It opera...
GDLockerSec
Our team members are from different countries and we are not interested in anything else, we are only interested in doll...
hellogookie
HelloGookie is a rebrand of the HelloKitty ransomware group announced in April 2024, releasing previously stolen data fr
insane
Insane is a short-lived ransomware group that briefly surfaced in early 2024, claiming a single victim in Thailand befor
kittykatkrew
KittyKatKrew is a newly emerged ransomware group first identified in early 2026, using both direct and double-extortion
lockdata
LockData Auction is a dark web marketplace that emerged around May 2021 operating an invite-only stolen data auction por
pandora
Pandora ransomware was obtained by vx-underground at 2022-03-14.
PrinzEugen
ragnarok
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes...
robinhood
RobbinHood is a ransomware group first observed in April–May 2019, responsible for high-profile attacks on US cities inc
slug
Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing
0day
agelocker
astroteam
bitlocker
blacktor
Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victim
bonacigroup
Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going off
cry0
Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payloa
dark project
Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortio
datakeeper
DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "
egregor
Egregor is a ransomware strain that appeared in September 2020, widely believed to be a rebrand or successor to the Maze...
gandcrab
GandCrab was a prolific Ransomware-as-a-Service (RaaS) operation active from January 2018 to mid-2019. It quickly became...
hermes
Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group op...
kazu
Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting govern
locky
memedusalockerdusa
nasirsecurity
Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organiz
netflim
nightsky
Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, g
noname
NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized bu
rancoz
Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension t
robbinhood
ronggolawe
satanlock
Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages).
satanlockv2
SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after
sekhmet
sensayq
SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortio
sovcali
teslacrypt
triple x
walocker
WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and g
blogxx
bluebox
Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims prim
cerber
ContFR
RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon...
crosslock
CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion ...
cryptomix
cryptoware
deathkitty
erebus
global3
goznym
hades
Hades is a ransomware group first observed in December 2020, believed by several threat intelligence firms to be operate...
hddcryptor
keyholder
kryptos
Kryptos is a small ransomware group first observed in October 2025, conducting simultaneous attacks across North America
lechiffre
macaw
majinahanashi
megacode
nullbulge
A hacktivist group protecting artists' rights and ensuring fair compensation for their work.
pewcrypt
playboy
PlayBoy Locker is a ransomware-as-a-service operation that emerged in September 2024, targeting Windows, NAS, and ESXi s
prolock
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and loc...
ransomcortex
RansomCortex emerged in July 2024 with a narrow focus on healthcare facilities, claiming four victims within days of its
ranstreet
Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lis
roadsweep
samas
shaoleaks
SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but la
sicarii
Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targetin
synack
SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Do
triplem
trisec
Trisec is a Tunisian-origin ransomware group that emerged in February 2024, claiming affiliation with the Tunisian gover
vendetta
Ransomware, which appears to be a rebranding of win.cuba.
wastedlocker
yurei
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-sour
0apt
The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele...
0xFFF
2023lock
2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus fa...
a1project
The locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for E...
Abrahams_Ax
Abrahams_Ax, first observed in November 2022, is not a Ransomware-as-a-Service (RaaS) operation but a politically motiva...
adminlocker
AdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear Rans...
againstthewest
AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived
aGl0bGVyCg
This ransomware group (notably stylized as aGl0bGVyCg) has extremely limited publicly available information. No confirme...
ako
First observed in early January 2020 (initial victim post on January 9, 2020), Ako (also known as MedusaReborn) operates...
amnesia
Amnesia ransomware was first identified in May 2017, particularly affecting enterprise cloud environments. It does not a...
ank
antefrigus
antibrok3rs
Antibrok3rs emerged as an access broker (not a ransomware operator itself) linked to the aftermath of the 2023 MOVEit su...
aptlock
Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage. T...
arachna leak
arcane
Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations aga...
arcrypter
ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government en...
argonauts group
Argonauts Group is a data extortion operation that surfaced around September–October 2024, primarily targeting organizat...
arkana security
Arkana Security emerged in early 2025, debuting with a high-profile data-extortion campaign against the U.S. internet pr...
astralocker
AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-e...
avos
First observed in July 2021, AvosLocker operates as a Ransomware-as-a-Service (RaaS) platform employing a double-extorti...
aware
Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documenta
axxes
Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing ...
aztroteam
AztroTeam is a ransomware group with very limited public documentation and no confirmed victims, listed as offline on ra
azzasec
We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botne...
b0 group
B0 is a relatively obscure ransomware operation with very limited public reporting outside of leak site monitoring. It a...
babuk-bjorka
On January 26th, Babuk's dedicated leak site (DLS) was "relaunched". Bjorka (Telegram: @bjorkanesiaaaa) is the current a...
babuk-locker
Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises ...
babyduck
BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduc
babylockerkz
BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023. It operates under a double‑extortion ...
backmydata
BackMyData is a variant of the Phobos ransomware family, first observed in early 2024. It follows a double‑extortion mod...
balletspistol
BalletsPistol is a Python-based ransomware strain distributed via GitHub. An investigative report from June 2025 reveals...
belsen group
aka Belesn Group. <br/>Belsen Group emerged in January 2025 as a data broker and leak-focused threat actor, not engaging...
bidon
BIDON is a variant of the Monti ransomware family, first observed around mid‑2023. It employs a double‑extortion strateg...
bitransomware
BitRansomware (also known as DCryptSoft or ReadMe) surfaced in November 2020, primarily as a widespread cryptolocker tar...
bjorka
Hellcome Bjorkanism <br/>Bjorka emerged as a prominent data-extortion actor and hacktivist initially active in 2022, ta...
black witch
blackberserk
Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023. It operates under a single‑extort...
blackbit
BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and func...
blackfield
blackfile
blackhunt
Black Hunt ransomware has been active since at least mid-2021 and operates under a double-extortion model, encrypting vi...
blacksnake
BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began re...
bluelocker
Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum
bluesky
BlueSky ransomware first emerged in July 2022 and is characterized by aggressive, high-speed file encryption using a mul...
bluewhale
bober
br0k3r
Br0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group lever...
buddyransome
bytesfromheaven
C3RB3R
Cerber ransomware, active since 2016, has resurfaced occasionally using the name C3RB3R. It operates as a semi-private R...
catb
CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distribut...
cerberimposter
Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting o...
cerbersyslock
CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceiv...
chilelocker
ChileLocker first emerged in August 2022 and is considered part of the broader ARCrypter ransomware family. It employs a...
cipherwolf
clearwater
cloak.su (locker leak)
clop torrents
colossus
Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S...
cooming
previous clearnet domain coomingproject.com
core
Core ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion m...
crazyhunter team
CrazyHunter is a rising ransomware threat first detected in early 2025, with particularly dangerous campaigns targeting ...
cring
cryakl
also known as “Fantomas”. <br/>Cryakl first appeared in 2014, spreading primarily across Eastern Europe and Russia via p...
crylock
CryLock is a ransomware variant that emerged around April 2020, evolving from the Cryakl (Fantomas) ransomware family. I...
crynox
Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to...
crypt ransomware
.crYpt <br/>MD5: 54EFAC23D7B524D56BEDBCE887E11849 <br/> <br/>Babuk Variant
cryptedpay
CryptedPay is a standalone ransomware strain observed around early 2025, that encrypts files using AES-256 and appends t...
cryptxxx
CryptXXX is a ransomware strain that first appeared in April 2016, developed by the same group behind the Reveton and An...
crysis
Crysis ransomware was first identified in early 2016 and is a long-running family that later evolved into the Dharma ran...
cs-137
Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for enc...
ctblocker
aka Critroni <br/>CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve crypt...
cyberex
cylance
d0glun
D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermedia...
dagonlocker
Dagon Locker is a double-extortion ransomware family that surfaced around September 2022. It represents an evolution of ...
dark shinigami
darkangel
Dark Angels is a highly targeted ransomware and data-extortion group that emerged in spring 2022. Rather than using an a...
darkangels
Dark Angels is a highly selective ransomware group active since April 2022 that targets a small number of large enterpri
darkbit
DarkBit is an ideologically motivated ransomware group that appeared in February 2023, primarily targeting Israeli entit
darkbit01
DarkBit is a politically motivated ransomware operation active since February 2023, targeting academic and public sector...
darkhav0c
darkmatter
darkrypt
darkwave
Written in python
darkylock
Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk s...
dataf locker
DataF Locker is a ransomware variant first observed in 2024, closely tied to the Babuk ransomware lineage. It operates u...
deadbydawn
deathgrip
DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked...
deathransom
DeathRansom is a ransomware family first seen in the wild in late 2019, initially appearing as a bluff—dropping ransom n...
delta
desolated
devman2
DevMan 2.0 is the evolved iteration of the DevMan ransomware, first documented in July 2025. It enhances the capabilitie...
diavol
Diavol is a ransomware strain first observed in June 2021, associated with the Wizard Spider threat group—best known for...
dread
Dread is a ransomware group that appears in tracking databases but has no publicly documented attacks or confirmed TTPs
ech0raix
The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom not...
eclipse
elcometa
elonmusknow
elpaco
Elpaco is a variant of Mimic ransomware that emerged around August 2023. Designed with significant customization and ste...
emperador
enciphered
aka xoriste
encrypthub
endurance
Endurance is a destructive ransomware variant first observed in 2023, developed and operated by the threat actor known a...
entropy
Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomw...
ep918
EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly document
eruption
Rebranded to Sabbath.
esxiargs
ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-202...
evolution
exorcist
Ransomware.
fakersa
farattack
fargo
Fargo is a ransomware variant that surfaced in 2022, primarily targeting Microsoft SQL Server (MSSQL) systems. Believed ...
faust
Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since ...
fivehands
FiveHands is a ransomware family first observed in January 2021, believed to be a successor to the HelloKitty ransomware...
fletchen
Fletchen is primarily documented as a sophisticated infostealer-as-a-service written in Rust, targeting browser credenti
freeworld
FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomw...
frozen
fsociety
This group is also known by their malware name, FLOCKER. <br/>FSociety is a modern Ransomware-as-a-Service (RaaS) operat...
fsteam
New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware ...
ftcode
FTCode is a ransomware family first observed in 2013 as a PowerShell-based threat and later resurfaced in September 2019...
fusion
gangbang
gazprom
ghost
aka Cring / Ghost (Cring) <br/> <br/>Beginning early 2021, Ghost actors began attacking victims whose internet facing se...
globe
Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allow...
globeimposter
GlobeImposter is a ransomware family that first appeared in mid-2017, designed to mimic the appearance and naming conven...
Goddamn ransomwhere
good day
Good Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to it...
grep
grief
Grief, also known as Pay or Grief, is a ransomware group that emerged in May 2021 and is widely believed to be operated ...
grinch
gwisin
Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South K...
haron
Haron is a ransomware group that emerged in July 2021 and is believed to share operational similarities with the Avaddon...
hellokitty
HelloKitty is a ransomware family first observed in November 2020, named after a string found in its binary. It operates...
help_restoremydata
Help_restoremydata is a ransomware variant identified around late 2024/early 2025, notable for appending the .help_resto...
himalayaa
hiveleak
holyghost
HolyGhost is a ransomware group first publicly reported in July 2022, believed to be operated by a North Korean state-sp...
homeland
hotarus
Hotarus is a ransomware and data extortion group first observed in March 2021, believed to be linked to threat actors of...
hyflock
inpivx
insane ransomware
Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public thr...
invaderx
ironchain
izis
j group
jackalock
jaff
Jaff is a ransomware family first discovered in May 2017, notable for its distribution via large-scale spam campaigns op...
jigsaw
Jigsaw is a ransomware family first observed in April 2016, notorious for its psychological intimidation tactics. It enc...
jo of satan
jsworm
JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolut...
justice_blade
kasseika
Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatt...
kawa
key group
killada
kirov
krypt
kryptina
kuiper
Kuiper is a relatively new ransomware strain first analyzed in April 2023, notable for being written in Rust and designe...
kuza
kyber
Kyber is a recently identified ransomware group using sophisticated hybrid encryption (AES-256-CTR with X25519 and Kyber
la_piovra
ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
lambda
lamialocker
late.lol
Affiliates: <br/>@Mr.C <br/>@Empathy <br/>@jayze <br/>@Widow <br/>@Memory <br/> <br/>
lcryptorx
leak bazaar
lilith
Lilith is a C/C++-based double-extortion ransomware that emerged in July 2022, targeting 64-bit Windows systems and shar
lockbit
LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak acc
lockbit3_fs
LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating
lockbit4
lockergoga
locus
loki
lokilocker
lolnek
Lolnek (also known as Lolkek/GlobeImposter) is a commodity ransomware strain primarily targeting small and medium-sized
lsd
luckbit
lulzsec muslims
lynxr
lyrix
madcat
MadCat is a suspected fraudulent ransomware operation that surfaced briefly in late 2023, apparently linked to scammers
mailto
makop
malphas
mamona
Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed be
mario esxi
maui
mbc
MBC is a very obscure ransomware group with minimal public documentation and no significant threat intelligence reports
mcafee
mcrypt2019
megacortex
megazord
mespinoza
miga
#MakeIsraelGreatAgain
miliphen
mimic
mimic-guram
Mimic v.10 Ransomware-as-a-Service (RaaS). The malware is designed to target various operating systems (Windows, ESXi, N...
moisha
monolock
montage
monte
mortalkombat
MORTAR
Encrypting ransomware with a Tor negotiation portal; no verified public victim disclosure yet.
muliaka
mydata
mydecryptor
MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platfo
n3tworm
N3tw0rm ransomware group is linked to Iran by many security researchers especially for the fact that the group targeting
naga
nblock
nemesis
nemty
Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed throug...
networm
nevada
Nevada Ransomware is a RaaS operation written in Rust that emerged on the RAMP dark web forum in late 2022, offering aff
Notpetya
nozelesn
nvrmre
AKA Lemon
obsidian orb
oceans
octovillan
offwhite
onepercent
OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using p
osyolorz collective
ox thief
paradise
paradise2
Payday
petya
phalcon
phantom
phobos
phoenixcryptolocker
pink
piratelock
polyvice
prinz eugen
prometheus
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
promptlock
First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama ...
proton
providence
proxima
pryx
punisher
pyrx
qilin-securotrop
qlocker
login page, no posts
quicklock
quoter
ra group
rabbithole
RabbitHole is a low-profile ransomware group with limited publicly available threat intelligence, not appearing prominen
radiant group
RAMP
RAMP (Russian Anonymous Marketplace) was a Russian-speaking dark web forum founded in 2021 that served as a central mark
ranion
Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model
ransom corp
ransombay
Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative
ransomcartel
Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to sh
ransomedvc2
RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.
ransomware blog
Also known as MedusaLocker
ranzy
Ranzy Locker, Former known as ThunderX. The group hosting a data leak site in the darknet where they posting sensitive i
raptum
rapture
redact
relic
reynolds
Reynolds is a ransomware family first identified in early 2026, notable for embedding BYOVD (Bring Your Own Vulnerable D
risen
Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malwa...
robbing hood
root
rransom
RRansom is a low-profile ransomware group whose dark web leak site has been listed as offline in tracking directories, w
rtm locker
rustylocker
satancd
scattered lapsus$ hunters
schoolboys
section9
🚨 This is a fake group with fake victims.
SevyWare
Direct Extortion Double Extortion
shade
shadow
Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; s
sharpboys
shiba
ShinySp1d3r
Likely associated with the cybercrime group BlingLibra (ShinyHunters)
sicari
sifrecikis
silent ransom
skira team
slam
soleenya
solidbit
Ransomware, written in .NET.
spectre
sphinx
spirigatito
spring
spy corporate
sugar
Ransomware, written in Delphi.
sundawn
superblack
synapse
syndicate
targetcompany
taronis
team underground
telegram
thanos
The syndicate
Data Broker
thor
threatmarket
thunder x
thundercrypt
tommyleaks
tooda
Members: <br/>Eco <br/>Ego <br/>emo <br/>elo <br/>user <br/>Dante <br/>Sevy
toxic
tssxx25
tuborg
turkish crypter
tycoon
u-bomb
U-Bomb is a low-profile ransomware operation discovered in March 2023 that arrives via phishing emails and uses third-pa
ulose
umbra
unknown
"Unknown" is a catch-all tracking label used on ransomware monitoring platforms for attacks where the responsible threat
unsafeleak
v is vendetta
vandev
vanirgroup
VanirGroup is an Eastern European ransomware group composed of former affiliates from Karakurt, LockBit, and Knight rans
vasalocker
vaultcrypt
vegalocker
vfokx
VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentatio
vsop
aka Onix/Onyx
vulcan
vurten
w3crypto
waissbein
weaxor
white lock
wiki ransomware
wikileaksv2
Group is connected to Qilin.
wiper leak
x001xs
X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing st
xelera
xinof
XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and
xleaks
xollam
xpl0itrs
yashma
ymir
zeon
Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of forme
zeoticus
zeoticus2
zeppelin
Zeppelin ransomware is a derivative of the Delphi-based Vega malware family and functions as a Ransomware as a Service (...
zero tolerance gang (ztg)
zerolockersec
ZeroLockerSec is a small ransomware group with very limited public documentation that became inactive by Q2 2025 with no
zerotolerance
ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles,