Threat Groups

660 tracked groups

lockbit3

ransomware group🇷🇺RaaS
ACTIVE

LockBit 3.0 (also known as LockBit Black) is the third major iteration of the LockBit ransomware-as-a-service platform, ...

2607 victims

everest

ransomware group🇷🇺
ACTIVE

Everest is a Russian-speaking ransomware and data extortion group active since at least 2020, known for targeting critic...

2235 victims

qilin

ransomware group🇷🇺RaaS
ACTIVE

Qilin (also known as Agenda) is a ransomware-as-a-service operation that emerged in 2022, initially targeting healthcare...

1794 victims

akira

ransomware group🇷🇺
ACTIVE

Akira ransomware first appeared in March 2023 and quickly became one of the most active groups of that year, targeting s...

1730 victims

play

ransomware group
ACTIVE

Play ransomware (also known as PlayCrypt) emerged in mid-2022 and is characterized by its use of the ".play" file extens...

1298 victims

clop

ransomware group🇷🇺
ACTIVE

Clop (also spelled Cl0p) is a financially motivated ransomware group attributed to the FIN11/TA505 threat cluster with a...

1263 victims

cactus

ransomware group
ACTIVE

Cactus ransomware surfaced in March 2023 and quickly gained attention for exploiting vulnerabilities in Qlik Sense analy...

1048 victims

lockbit2

ransomware group🇷🇺RaaS
INACTIVE

LockBit 2.0 (also known as LockBit Red) was the second major version of the LockBit ransomware-as-a-service platform, ac...

933 victims

incransom

ransomware group
ACTIVE

INC Ransom (INCransom) is a double-extortion ransomware group that emerged in mid-2023, targeting healthcare, education,...

787 victims

chaos

ransomware groupRaaS
ACTIVE

Chaos ransomware operates as a ransomware-as-a-service builder that has been widely distributed on underground forums si...

764 victimsSince Feb 13, 2026

alphv

ransomware group🇷🇺RaaS
ACTIVE

ALPHV (also known as BlackCat or Noberus) was a sophisticated ransomware-as-a-service operation launched in November 202...

734 victims

blackbasta

ransomware group🇷🇺
ACTIVE

Black Basta emerged in April 2022 and is widely assessed by researchers and law enforcement to be composed of former Con...

522 victims

dragonforce

ransomware group🇲🇾RaaS
ACTIVE

DragonForce is a ransomware-as-a-service operation with roots in a Malaysian hacktivist group of the same name that was ...

521 victims

medusa

ransomware groupRaaS
ACTIVE

Medusa ransomware (not to be confused with MedusaLocker) is a ransomware-as-a-service operation that became highly activ...

520 victims

ransomhub

ransomware group🇷🇺RaaS
ACTIVE

RansomHub is a ransomware-as-a-service operation that launched in February 2024 and rapidly became one of the most activ...

487 victims

safepay

ransomware group
ACTIVE

SafePay is a double-extortion ransomware group that emerged in late 2024, quickly attracting attention for its professio...

477 victimsSince Dec 31, 2024

8base

ransomware group
INACTIVE

8Base is a double-extortion ransomware group that first appeared in early 2022 but dramatically escalated activity in mi...

455 victims

thegentlemen

ransomware group🇷🇺RaaS
ACTIVE

The Gentlemen is a ransomware-as-a-service group that emerged in mid-2024 and rapidly accumulated victims across North A...

424 victims

bianlian

ransomware group🇨🇳
INACTIVE

BianLian ransomware first appeared in June 2022 and is attributed by multiple researchers and the FBI/CISA to a China-ba...

422 victims

lynx

ransomware group🇷🇺RaaS
ACTIVE

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 and is assessed to be a rebrand or direct successor...

383 victims

interlock

ransomware group
ACTIVE

Interlock ransomware emerged in late 2024 and is notable for deploying a custom ransomware variant that targets both Win...

360 victims

conti

ransomware group🇷🇺
ACTIVE

Conti was one of the most prolific and financially damaging ransomware operations in history, attributed by the FBI and ...

351 victims

nightspire

ransomware group
ACTIVE

Nightspire is a relatively new double-extortion ransomware group that emerged in early 2025 and has quickly accumulated ...

343 victimsSince Apr 27, 2025

dispossessor

ransomware group🇤🇤
ACTIVE

Dispossessor (also tracked as Radar) was a ransomware-adjacent data extortion operation active from August 2023 until it...

334 victims

pysa

ransomware group🇫🇷
INACTIVE

PYSA (also known as Mespinoza) is a ransomware group active since 2019 that has primarily targeted education, healthcare...

309 victims

hunters

ransomware group🇷🇺RaaS
ACTIVE

Hunters International emerged in October 2023 and is widely assessed to be a rebrand or direct continuation of the Hive ...

308 victims

coinbasecartel

ransomware group🇷🇺RaaS
ACTIVE

CoinbaseCartel (also known as CoinBase Cartel) is a financially motivated cybercrime group that operates a data acquisit...

300 victimsSince Feb 13, 2026

killsec

ransomware group🇮🇳RaaS
ACTIVE

KillSec (Kill Security) is a hacktivist-turned-cybercriminal group that emerged in late 2023, linked by researchers to I...

286 victimsSince Dec 31, 2024

sinobi

ransomware group🇷🇺
ACTIVE

Sinobi is a data extortion and ransomware group that emerged in 2024 and is assessed to have inherited personnel and cod...

279 victims

rhysida

ransomware group
ACTIVE

Rhysida is a ransomware group that emerged in May 2023, quickly gaining notoriety for attacking healthcare providers and...

270 victims

lockbit5

ransomware group🇷🇺RaaS
ACTIVE

LockBit 5.0 (also referred to as LockBit Nation-State) is a claimed successor to LockBit 3.0 that emerged after Operatio...

267 victimsSince Feb 12, 2026

payload

ransomware group
ACTIVE

Payload is a ransomware group that emerged in 2024, primarily targeting organizations in North America and Europe throug...

246 victims

ransomhouse

ransomware group🇷🇺
ACTIVE

RansomHouse is a data extortion group and marketplace active since December 2021 that focuses on stealing data without n...

228 victims

hive

ransomware group🇷🇺
INACTIVE

Hive was a major ransomware-as-a-service operation active from June 2021 until January 2023, targeting over 1,500 organi...

207 victimsSince Jun 1, 2021

blacksuit

ransomware group🇷🇺RaaS
INACTIVE

BlackSuit is the rebranded continuation of the Royal ransomware operation, confirmed by CISA and FBI in an August 2024 j...

191 victims

handala

ransomware group🇮🇷
ACTIVE

Handala (also known as Handala Hack Team or Hatef) is an Iran-linked hacktivist group that emerged during the Israel-Ham...

191 victims

FOG

ransomware group
INACTIVE

FOG ransomware is a sophisticated strain first observed in May 2024, initially targeting US educational institutions bef...

189 victims

vicesociety

ransomware group🇷🇺
INACTIVE

Vice Society is a ransomware group that was active from mid-2021 to 2023, distinguished by its heavy focus on the educat...

188 victims

ciphbit

ransomware group🇷🇺
ACTIVE

CiphBit is a ransomware operation first detected in early 2024, using a custom encryptor targeting Windows and network s...

183 victims

malas

ransomware group
ACTIVE
180 victims

funksec

ransomware group🇩🇿
ACTIVE

FunkSec is an Algerian ransomware group that emerged in late 2024 and quickly generated a high victim count through a co...

175 victimsSince Dec 31, 2024

royal

ransomware group🇷🇺
INACTIVE

Royal ransomware was active from September 2022 to mid-2023 and is believed to have been formed by former members of the...

164 victims

stormous

ransomware group🇤🇤
ACTIVE

Stormous is a pro-Russian hacktivist and ransomware group that emerged around mid-2021, believed to include members from...

157 victims

worldleaks

ransomware group🇷🇺RaaS
ACTIVE

WorldLeaks is the rebranded continuation of Hunters International, launched in January 2025 after the group ceased file-...

157 victims

babuk2

ransomware group🇷🇺
ACTIVE

Babuk 2.0 (also styled as Babuk Locker 2.0 or SatanLock) is a group that impersonates the original Babuk ransomware oper...

156 victimsSince Jan 27, 2025

blackbyte

ransomware group🇷🇺RaaS
ACTIVE

BlackByte is a ransomware-as-a-service operation first observed in July 2021, assessed to be Russia-linked and notable f...

148 victims

avaddon

ransomware group🇷🇺
INACTIVE

Avaddon was a ransomware-as-a-service operation active from June 2020 to June 2021, when the operators unexpectedly shut...

146 victims

meow

ransomware group
INACTIVE

Meow ransomware is a strain that emerged in 2022, appending the ".MEOW" extension to encrypted files and primarily targe...

145 victims

sarcoma

ransomware group
ACTIVE

Sarcoma is a double-extortion ransomware group that emerged in mid-2024, primarily targeting manufacturing, professional...

143 victims

snatch

ransomware group🇷🇺
ACTIVE

Snatch ransomware (not to be confused with the 2022 data extortion group reusing the brand) is a Russia-linked operation...

143 victims

spacebears

ransomware group
ACTIVE

SpaceBears is a data extortion group that emerged in 2024, focusing on stealing and publishing sensitive corporate data ...

136 victims

eraleign (apt73)

ransomware group🇷🇺

Eraleign (APT73) rebranded as Bashe in October 2024 after operating under the Eraleign name, with the transition coincid...

136 victimsSince Jun 22, 2024

ragnarlocker

ransomware group🇷🇺
INACTIVE

RagnarLocker was a Russia-linked ransomware group active from 2019 to 2023, known for conducting its own intrusions with...

129 victims

SilentRansomGroup

ransomware group🇷🇺
ACTIVE

SilentRansomGroup (SRG) is a former Conti team that continued operating independently following Conti's dissolution in 2...

129 victimsSince Feb 13, 2026

noescape

ransomware group🇷🇺RaaS
INACTIVE

NoEscape was a ransomware-as-a-service operation that launched in June 2023 and is assessed by multiple researchers to b...

126 victims

nova

ransomware group🇷🇺RaaS
ACTIVE

Nova (formerly known as RALord) is a ransomware-as-a-service operation that rebranded from RALord in late 2024. The grou...

124 victimsSince Oct 1, 2025

toufan

ransomware group🇮🇷
ACTIVE

Toufan (also known as Toufan Al-Aqsa) is an Iran-linked hacktivist group that emerged during the Israel-Hamas conflict i...

121 victimsSince Dec 31, 2024

pear

ransomware group
ACTIVE

PEAR (Pure Extraction And Ransom) Team is a data extortion group that emerged in 2024, focusing on publishing stolen cor...

118 victimsSince Feb 13, 2026

apt73

ransomware group🇷🇺
ACTIVE

APT73 is a ransomware group that operated under the "eraleign" identity before rebranding as Bashe in October 2024. Some...

117 victims

shinyhunters

ransomware group🇤🇤
ACTIVE

ShinyHunters is a prolific data theft and extortion group responsible for numerous high-profile breaches including the 2...

115 victimsSince Nov 4, 2025

devman

ransomware group🇷🇺RaaS
INACTIVE

Devman is a former RansomHub and INC Ransom affiliate that began operating independently as a ransomware-as-a-service pl...

114 victimsSince Jun 16, 2025

monti

ransomware group🇷🇺
INACTIVE

Monti is a ransomware group that emerged in June 2022, widely assessed to be a copycat or offshoot of the Conti operatio...

108 victims

eldorado

ransomware group🇷🇺RaaS
INACTIVE

Eldorado is a ransomware-as-a-service operation that emerged in early 2024, offering both Windows and VMware ESXi encryp...

105 victims

cuba

ransomware group🇷🇺RaaS
INACTIVE

Cuba ransomware is a ransomware-as-a-service operation active since at least 2019, assessed to be Russia-linked despite ...

103 victims

arcusmedia

ransomware groupRaaS
INACTIVE

Arcus Media is a ransomware-as-a-service operation that first emerged in May 2024, offering affiliates a Linux and Windo...

98 victims

ransomexx

ransomware group🇷🇺
ACTIVE

RansomExx (also known as Defray777) is a ransomware family that targeted multiple high-profile organizations including K...

97 victims

revil

ransomware group🇷🇺RaaS
INACTIVE

REvil (also known as Sodinokibi) was one of the most financially damaging ransomware-as-a-service operations in history,...

95 victims

blackout

ransomware group🇷🇺
ACTIVE

Blackout surfaced in February 2024, using a variant based on DarkSide and BlackMatter ransomware source code, establishi...

92 victims

anubis

ransomware group🇷🇺
ACTIVE

Anubis ransomware emerged in 2024 as a data extortion and ransomware-as-a-service platform that distinguishes itself wit...

88 victims

kairos

ransomware group🇷🇺
ACTIVE

Kairos is a double-extortion ransomware group that emerged in 2024, operating a dark web leak site and targeting organiz...

88 victims

abyss

ransomware group
INACTIVE

Abyss (Abyss Data) is a data extortion group that emerged in early 2023, focusing on stealing and publishing sensitive c...

81 victims

cloak

ransomware group
ACTIVE

Cloak is a cybercriminal ransomware group that first emerged in late 2023, targeting small to mid-size businesses across...

81 victims

payoutsking

ransomware group
ACTIVE

Payouts King Group is a data extortion collective that explicitly states it does not operate as a RaaS and does not use ...

81 victimsSince Feb 13, 2026

karakurt

ransomware group🇷🇺
ACTIVE

Karakurt is a data extortion group established in 2021 as an offshoot of the Conti ransomware operation (Wizard Spider),...

80 victims

warlock

ransomware group🇨🇳RaaS
ACTIVE

Warlock ransomware emerged in mid-2025 and has been attributed by Microsoft, Sophos, and Trend Micro with moderate-to-hi...

80 victimsSince Jun 11, 2025

lorenz

ransomware group
ACTIVE

Lorenz is a ransomware group active since early 2021, known for an unusual tactic of selling access to victim networks t...

79 victims

threeam

ransomware group🇷🇺
ACTIVE

3AM (ThreeAM) is a ransomware group discovered in September 2023, first observed being deployed as a fallback when LockB...

78 victims

cicada3301

ransomware group🇷🇺RaaS
INACTIVE

Cicada3301 (unrelated to the 2012 internet puzzle) is a ransomware-as-a-service operation that emerged in June 2024 with...

75 victims

beast

ransomware groupRaaS
ACTIVE

Beast ransomware operates as a ransomware-as-a-service platform targeting Windows, Linux, and VMware ESXi environments. ...

75 victims

direwolf

ransomware group
ACTIVE

DirewWolf is a recently emerged double-extortion ransomware group that conducts targeted attacks against medium to large...

72 victimsSince Feb 13, 2026

genesis

ransomware group
ACTIVE

Financial interests only. <br/> We do not provide or work with affiliate programs, no collaborations either. <br/...

72 victimsSince Feb 13, 2026

avoslocker

ransomware group
INACTIVE

AvosLocker is a ransomware-as-a-service operation that launched in mid-2021, known for targeting critical infrastructure...

70 victims

quantum

ransomware group🇷🇺
INACTIVE

Quantum ransomware emerged in August 2021 as a rebrand of the MountLocker operation and was subsequently linked to the C...

68 victims

raworld

ransomware group🇨🇳
INACTIVE

RA World (formerly known as RA Group, active since April 2023) is a ransomware operation linked by Symantec and Palo Alt...

68 victimsSince Dec 31, 2024

ransomed

ransomware group
ACTIVE
68 victimsSince Sep 1, 2023

blacknevas

ransomware group
ACTIVE

BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct deriv...

66 victimsSince Feb 13, 2026

medusalocker

ransomware group
ACTIVE

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predec...

66 victimsSince Mar 1, 2024

orion

ransomware group
ACTIVE

Jan13, 2026: We believe the group might be related to Babuk-Bjorka.

64 victimsSince Feb 13, 2026

blacklock

ransomware group🇷🇺
INACTIVE

BlackLock (also known as Mamona) is a ransomware-as-a-service operation that emerged in late 2023 as an evolution of the...

64 victimsSince Aug 25, 2025

nitrogen

ransomware group
ACTIVE

Nitrogen is a data extortion group that emerged in 2023, primarily conducting data theft without encryption to pressure ...

63 victims

lv

ransomware group
INACTIVE

parser needs to be built

62 victims

maze

ransomware group🇷🇺
ACTIVE

Maze ransomware pioneered the double-extortion model in late 2019, becoming the first major group to combine file encryp...

61 victims

tengu

ransomware group
ACTIVE

Ransomware group active in data extortion.

61 victims

braincipher

ransomware group
ACTIVE

BrainCipher ransomware surfaced in mid-2024, initially gaining attention for a major attack against Indonesia's National...

56 victims

darkvault

ransomware group
INACTIVE

DarkVault is a versatile threat actor that emerged in 2024, conducting both ransomware and data extortion operations aga...

55 victims

knight

ransomware groupRaaS
INACTIVE

Knight is a Ransomware-as-a-Service (RaaS) operation first observed in August 2023, believed to be a rebrand or evolutio...

55 victims

icarus

ransomware group
ACTIVE
53 victims

losttrust

ransomware group
INACTIVE
53 victims

trigona

ransomware group
INACTIVE

Trigona ransomware was active from late 2022 to 2023, targeting businesses across multiple sectors with AES encryption a...

49 victims

mallox

ransomware group🇨🇳RaaS
INACTIVE

Mallox (also known as TargetCompany, Fargo, or Tohnichi) is a ransomware-as-a-service operation assessed to be China-lin...

49 victims

ryuk

ransomware group🇷🇺
INACTIVE

Ryuk ransomware is attributed to the Russia-based Wizard Spider cybercriminal group and was one of the most damaging ran...

48 victims

metaencryptor

ransomware group
ACTIVE

We are a group of young people who identify themselves as specialists in the field of network security with at least 15 ...

48 victims

crypto24

ransomware groupRaaS
ACTIVE

aka Public Data Storage <br/>Crypto24 emerged in early 2025 as a fast-growing double-extortion ransomware-as-a-service ...

47 victimsSince Feb 13, 2026

termite

ransomware group
ACTIVE

Termite is a ransomware group that emerged in late 2024, gaining attention for exploiting a zero-day vulnerability in Cl...

42 victims

donutleaks

ransomware group
INACTIVE

DonutLeaks is a data extortion group that emerged in 2022, publishing stolen data from organizations that refused to pay...

42 victims

darkleakmarket

ransomware group
ACTIVE
42 victims

embargo

ransomware group🇷🇺RaaS
ACTIVE

Embargo is a ransomware-as-a-service operation that emerged in mid-2024, utilizing Rust-based encryptors for both Window...

42 victims

midas

ransomware group
INACTIVE

Midas ransomware is a data extortion group active since late 2021 that shares significant technical similarities with th...

41 victims

J

ransomware group
INACTIVE
39 victimsSince Dec 15, 2025

blackshrantac

ransomware group
ACTIVE

aka black shrantac

39 victimsSince Jan 15, 2026

krybit

ransomware group
ACTIVE
38 victimsSince Apr 3, 2026

securotrop

ransomware group
ACTIVE
37 victimsSince Feb 13, 2026

nokoyawa

ransomware group
INACTIVE

Nokoyawa ransomware is a strain active from early 2022 that shares significant code and infrastructure with the Karma an...

36 victims

gunra

ransomware group
ACTIVE

Gunra is an emerging ransomware group first identified in April 2025. It employs a classic double-extortion model—encryp...

36 victimsSince Feb 3, 2026

helldown

ransomware group
INACTIVE

Helldown is a double-extortion ransomware group that emerged in late 2024, known for exploiting vulnerabilities in Zyxel...

36 victims

AiLock

ransomware group🇷🇺RaaS
ACTIVE

AiLock is a ransomware-as-a-service group that emerged in early 2025, marketing itself as AI-assisted and suspected by r...

36 victimsSince Mar 7, 2026

insomnia

ransomware group
ACTIVE
35 victimsSince Feb 13, 2026

spook

ransomware group
INACTIVE
35 victims

radar

ransomware group
ACTIVE
35 victimsSince Feb 13, 2026

arvinclub

ransomware group
INACTIVE

Arvin Club first appeared around early to mid-2021, debuting on its Tor leak site with posts dating back to May 5, 2021....

35 victims

obscura

ransomware group
INACTIVE
33 victimsSince Jan 21, 2026

wannacry

ransomware group🇰🇵
INACTIVE

WannaCry was a destructive ransomware worm deployed in May 2017 that infected over 200,000 computers across 150 countrie...

33 victims

suncrypt

ransomware group🇷🇺
INACTIVE

SunCrypt is a ransomware group active since 2019 that joined the Maze ransomware cartel in 2020, adopting the double-ext...

32 victims

blackmatter

ransomware group🇷🇺
INACTIVE

BlackMatter was a ransomware-as-a-service operation active from July to November 2021, widely assessed as a direct rebra...

32 victims

marketo

ransomware group
INACTIVE
32 victims

dAn0n

ransomware group
INACTIVE

dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model...

31 victims

frag

ransomware group
INACTIVE

Frag ransomware emerged in late 2024, primarily observed exploiting Veeam Backup & Replication vulnerabilities (CVE-2024...

30 victimsSince Sep 12, 2025

dragonransomware

ransomware group
INACTIVE

Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a...

30 victimsSince Dec 31, 2024

global

ransomware groupRaaS
INACTIVE

Now a RaaS by BlackLock ($$$). <br/>Global Group is a newly emerged Ransomware-as-a-Service (RaaS) platform that debuted...

30 victimsSince Sep 17, 2025

werewolves

ransomware group🇷🇺
ACTIVE

Werewolves is a Russia-linked ransomware group that emerged in mid-2023, using a modified version of the LockBit 3.0 sou...

30 victims

moneymessage

ransomware group
ACTIVE
30 victims

bravox

ransomware group
ACTIVE

Ransomware group active in data extortion.

29 victims

vect

ransomware group
ACTIVE
29 victimsSince Jan 21, 2026

daixin

ransomware group🇨🇳
ACTIVE

Daixin Team is a ransomware and data extortion group active since mid-2022, primarily targeting the US healthcare and pu...

28 victims

fulcrumsec

ransomware group
ACTIVE
27 victimsSince Oct 30, 2025

lamashtu

ransomware group
ACTIVE
27 victimsSince Apr 13, 2026

kelvinsecurity

ransomware group
ACTIVE

Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and web...

26 victims

underground

ransomware group🇷🇺
ACTIVE

Underground ransomware (also known as Underground Team) is a Russia-linked group associated with the RomCom RAT threat c...

26 victims

netwalker

ransomware group🇨🇦
INACTIVE

NetWalker (also known as Mailto) was a ransomware operation active from 2019 to January 2021, when US and Bulgarian auth...

26 victims

bavacai

ransomware group
ACTIVE
25 victims

doppelpaymer

ransomware group🇷🇺
INACTIVE

DoppelPaymer ransomware is attributed to the Russia-based Evil Corp cybercriminal organization and is a successor to Bit...

25 victims

ShadowByt3$

ransomware group
ACTIVE
24 victimsSince Feb 28, 2026

flocker

ransomware group
INACTIVE
24 victims

sabbath

ransomware group
ACTIVE
22 victims

lapsus$

ransomware group🇬🇧
ACTIVE

Lapsus$ is a data extortion group that emerged in late 2021, known for social engineering, SIM-swapping, and insider rec...

22 victims

payloadbin

ransomware group
INACTIVE
21 victims

xinglocker

ransomware group
INACTIVE

xing use a custom mountlocker exe

21 victims

morpheus

ransomware group
ACTIVE
20 victimsSince Aug 3, 2025

ralord

ransomware group
ACTIVE
20 victimsSince Jul 11, 2025

leaktheanalyst

ransomware group
INACTIVE
20 victims

hellcat

ransomware group🇯🇴RaaS
ACTIVE

HellCat is a ransomware-as-a-service operation that emerged in late 2024, with KELA researchers identifying core operato...

20 victims

cephalus

ransomware group
ACTIVE
20 victimsSince Aug 29, 2025

siegedsec

ransomware group
INACTIVE
19 victims

secp0

ransomware group
ACTIVE

Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only

19 victimsSince Feb 13, 2026

bjorka

ransomware group

Hellcome Bjorkanism <br/>Bjorka emerged as a prominent data-extortion actor and hacktivist initially active in 2022, ta...

19 victimsSince Feb 1, 2025

ALP-001

ransomware group
ACTIVE
19 victimsSince Mar 21, 2026

leakeddata

ransomware group
18 victimsSince Feb 24, 2026

brotherhood

ransomware group
INACTIVE
18 victimsSince Jan 21, 2026

trinity

ransomware group
INACTIVE
18 victims

mountlocker

ransomware group
INACTIVE
18 victimsSince Sep 8, 2021

d4rk4rmy

ransomware group
INACTIVE

D4rk4rmy is a data-extortion focused threat actor that emerged in mid-2025, targeting high-profile organizations across ...

18 victimsSince Aug 30, 2025

tridentlocker

ransomware group
ACTIVE
18 victimsSince Feb 13, 2026

datacarry

ransomware group
ACTIVE

DataCarry is a newly observed ransomware and data-extortion operation, first seen in May 2025. It operates a double-exto...

17 victimsSince Feb 13, 2026

mosesstaff

ransomware group
ACTIVE
17 victims

m3rx

ransomware group
ACTIVE
17 victims

madliberator

ransomware group
INACTIVE

Group is also currently known as MADDLL32 and Metatron.

16 victims

dunghill

ransomware group
INACTIVE

Dunghill Leak is the publicly branded data leak site (DLS) operated by the Dark Angels ransomware group, established cir...

16 victimsSince Dec 31, 2024

redransomware

ransomware group
INACTIVE
16 victims

apos

ransomware groupRaaS
ACTIVE

Apos ransomware surfaced in April 2024 and is best characterized as a data‑broker or leak‑only operation, rather than a ...

15 victimsSince Oct 8, 2025

nefilim

ransomware group
INACTIVE

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is remov...

15 victims

malekteam

ransomware group
ACTIVE
15 victims

azroteam

ransomware group
INACTIVE
15 victims

weyhro

ransomware group
ACTIVE

Appears to be a Data Extortion group with no encryption.

15 victimsSince Mar 7, 2025

freecivilian

ransomware group
INACTIVE
14 victims

onyx

ransomware group
INACTIVE
14 victims

atomsilo

ransomware groupRaaS
ACTIVE

AtomSilo emerged in September 2021 and ceased operations by year-end 2021. It functioned with a double‑extortion model, ...

14 victims

sparta

ransomware group
INACTIVE
14 victims

cheers

ransomware group
INACTIVE

Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi ...

14 victims

unsafe

ransomware group
INACTIVE

A group which seems to recycle leak from other ransomware groups

14 victimsSince Dec 31, 2024

IMNCrew

ransomware group
ACTIVE
13 victimsSince Oct 27, 2025

argonauts

ransomware group
INACTIVE
13 victimsSince Mar 27, 2025

benzona

ransomware group
ACTIVE
13 victimsSince Feb 13, 2026

robinhood

ransomware group
ACTIVE
13 victims

mindware

ransomware group
INACTIVE
13 victims

alphalocker

ransomware group
ACTIVE
13 victims

cryp70n1c0d3

ransomware group
INACTIVE
13 victims

LeakBazaar

ransomware group
ACTIVE
13 victims

groove

ransomware group
INACTIVE

Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its agg...

13 victims

netrunner

ransomware group
ACTIVE
13 victimsSince Apr 3, 2026

samsam

ransomware group
12 victims

teamxxx

ransomware group
INACTIVE
12 victimsSince Sep 1, 2025

icefire

ransomware group
INACTIVE
11 victims

leak bazaar

ransomware group
10 victims

darkrace

ransomware group
INACTIVE

DarkRace is a moderately destructive ransomware strain observed since 2024. It encrypts files and appends a randomized e...

10 victims

darkside

ransomware group
INACTIVE

FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable dis...

10 victims

darkpower

ransomware group
INACTIVE

Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations ac...

10 victims

kazu

ransomware group
ACTIVE
10 victimsSince Feb 13, 2026

crazyhunter

ransomware group
INACTIVE
10 victimsSince Apr 3, 2025

aurora

ransomware group
ACTIVE
10 victims

0mega

ransomware group
ACTIVE

0mega is a ransomware group first observed in May 2022, operating with a double extortion model: <br/>* Encrypting victi...

9 victims

egregor

ransomware group

Egregor is a ransomware strain that appeared in September 2020, widely believed to be a rebrand or successor to the Maze...

9 victims

blackwater

ransomware group
ACTIVE
9 victimsSince Apr 12, 2026

mogilevich

ransomware group
INACTIVE
9 victims

exitium

ransomware group
ACTIVE
9 victimsSince Mar 17, 2026

rook

ransomware group
INACTIVE

Ransomware.

9 victims

babuk

ransomware group
INACTIVE
8 victims

pay2key

ransomware group
ACTIVE
8 victims

cryptolocker

ransomware group
ACTIVE
8 victims

cryptbb

ransomware group
INACTIVE
8 victims

cipherforce

ransomware group
ACTIVE

For those out of the loop, you may already know us as TeamPCP or Shellforce, we have been active a while publishing data...

8 victimsSince Feb 23, 2026

ms13089

ransomware group
ACTIVE
8 victimsSince Feb 13, 2026

skira

ransomware group
INACTIVE
8 victimsSince Dec 1, 2025

bitpaymer

ransomware group
ACTIVE
8 victims

lockbit3_fs

ransomware group
ACTIVE
8 victims

CMDOrganization

ransomware group
ACTIVE

CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all...

8 victims

radiant

ransomware group
INACTIVE
8 victimsSince Nov 12, 2025

AuditTeam

ransomware group
ACTIVE
8 victimsSince Apr 8, 2026

osyolorz collective

ransomware group
8 victimsSince Apr 13, 2026

RunSomeWares

ransomware group
ACTIVE
8 victimsSince Apr 19, 2025

bert

ransomware group
INACTIVE

BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux sy...

7 victimsSince Aug 2, 2025

cyclops

ransomware groupRaaS
INACTIVE

Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023. It operates as a Ransomwar...

7 victimsSince Oct 13, 2023

xp95

ransomware group
ACTIVE
7 victims

chort

ransomware group
INACTIVE

Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning ...

7 victimsSince Dec 31, 2024

karma

ransomware group
INACTIVE

Karma is a ransomware group first observed in November 2021, operating a double-extortion model that combines data theft...

7 victims

kawa4096

ransomware group
INACTIVE
7 victimsSince Aug 16, 2025

dataleak

ransomware group
INACTIVE
6 victims

silent

ransomware groupRaaS
INACTIVE

Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own...

6 victimsSince Nov 20, 2025

arkana

ransomware group
INACTIVE
6 victimsSince Jul 6, 2025

minteye

ransomware group
ACTIVE
6 victimsSince Dec 24, 2025

cipherwolf

ransomware groupRaaS
6 victimsSince Apr 13, 2026

yanluowang

ransomware group
INACTIVE

Ransomware.

6 victims

VanHelsing

ransomware groupRaaS
INACTIVE
6 victimsSince May 13, 2025

pandora

ransomware group
ACTIVE

Pandora ransomware was obtained by vx-underground at 2022-03-14.

6 victims

linkc

ransomware group
ACTIVE
6 victimsSince Apr 26, 2025

rancoz

ransomware group
INACTIVE
6 victims

raznatovic

ransomware group
ACTIVE

RANSOMED.VC aka Raznatovic

6 victimsSince May 28, 2024

nullbulge

ransomware group

A hacktivist group protecting artists' rights and ensuring fair compensation for their work.

6 victims

lockbit

ransomware groupRaaS
INACTIVE
5 victims

projectrelic

ransomware group
INACTIVE
5 victims

donex

ransomware groupRaaS
INACTIVE

Donex is a ransomware family that emerged in early 2022 as a rebrand of the older Muse ransomware. It uses a double-exto...

5 victims

bqtlock

ransomware groupRaaS
INACTIVE

aka BaqiyatLock <br/>BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a...

5 victimsSince Aug 21, 2025

PrinzEugen

ransomware group
ACTIVE
5 victims

orca

ransomware group
ACTIVE
5 victims

redalert

ransomware group
INACTIVE
5 victims

ValenciaLeaks

ransomware group
INACTIVE

Official twitter account: https://x.com/ValenciaLeaks72

5 victimsSince Dec 31, 2024

lockdata

ransomware group
INACTIVE
5 victims

leaknet

ransomware group

<br/> <br/>In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside infor...

5 victimsSince Aug 18, 2025

kraken

ransomware groupRaaS
INACTIVE

Kraken leak blog (hellokitty) <br/>Kraken is a ransomware family first observed in August 2018 as a Ransomware-as-a-Serv...

4 victimsSince Feb 13, 2026

desolator

ransomware group
INACTIVE
4 victimsSince Oct 19, 2025

TiMc

ransomware group
ACTIVE
4 victims

blacktor

ransomware group
INACTIVE
4 victims

killsec3

ransomware group
4 victimsSince Apr 13, 2026

grep

ransomware group
4 victimsSince Apr 13, 2026

scarab

ransomware group
4 victims

secpo

ransomware group
4 victims

cryptowall

ransomware group
ACTIVE
4 victims

vanirgroup

ransomware group
ACTIVE
4 victims

rebornvc

ransomware group
ACTIVE
4 victimsSince Oct 19, 2025

blackshadow

ransomware group
ACTIVE

BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2...

4 victims

satanlockv2

ransomware group
ACTIVE
4 victimsSince Feb 13, 2026

noname

ransomware group
ACTIVE
4 victimsSince Dec 31, 2024

shaoleaks

ransomware group
INACTIVE
4 victims

lockergoga

ransomware group
4 victims

osiris

ransomware group
ACTIVE
4 victimsSince Jan 14, 2026

bonacigroup

ransomware group
INACTIVE
3 victims

snake

ransomware group
INACTIVE
3 victims

mnt6

ransomware group
ACTIVE
3 victims

ragnarok

ransomware group
INACTIVE

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes...

3 victims

cry0

ransomware group
ACTIVE
3 victimsSince Feb 13, 2026

pryx

ransomware group
3 victims

locky

ransomware group
INACTIVE
3 victimsSince Dec 10, 2024

vendetta

ransomware group
INACTIVE
3 victims

nasirsecurity

ransomware group
ACTIVE
3 victimsSince Oct 14, 2025

hellogookie

ransomware group
INACTIVE
3 victims

homeland

ransomware group
ACTIVE
3 victimsSince Mar 10, 2026

sensayq

ransomware group
ACTIVE
3 victims

sekhmet

ransomware group
3 victims

bluebox

ransomware group
INACTIVE
3 victimsSince Dec 31, 2024

grief

ransomware groupRaaS
INACTIVE

Grief, also known as Pay or Grief, is a ransomware group that emerged in May 2021 and is widely believed to be operated ...

3 victims

clearwater

ransomware group
3 victimsSince Apr 13, 2026

qiulong

ransomware group
INACTIVE
3 victims

bitlocker

ransomware group
INACTIVE
2 victims

kryptos

ransomware groupRaaS
INACTIVE
2 victimsSince Dec 11, 2025

dharma

ransomware groupRaaS
INACTIVE

Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It opera...

2 victims

trisec

ransomware group
INACTIVE
2 victimsSince Feb 21, 2024

ContFR

ransomware groupRaaS
ACTIVE

RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon...

2 victimsSince Feb 13, 2026

nightsky

ransomware group
INACTIVE
2 victims

satanlock

ransomware group
ACTIVE

Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages).

2 victimsSince Apr 8, 2025

lunalock

ransomware group
INACTIVE
2 victimsSince Feb 5, 2026

cryptnet

ransomware group
INACTIVE

CryptNet is a newer Ransomware-as-a-Service (RaaS) operation first identified in April 2023. It follows a double-extorti...

2 victims

arachna leak

ransomware group
2 victimsSince Apr 13, 2026

kittykatkrew

ransomware group
INACTIVE
2 victims

antibrok3rs

ransomware group

Antibrok3rs emerged as an access broker (not a ransomware operator itself) linked to the aftermath of the 2023 MOVEit su...

2 victimsSince Dec 25, 2025

prolock

ransomware group
INACTIVE

PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and loc...

2 victims

teslacrypt

ransomware group
ACTIVE
2 victims

wastedlocker

ransomware group
INACTIVE
2 victims

datakeeper

ransomware group
INACTIVE
2 victimsSince Feb 13, 2026

ransomcortex

ransomware group
INACTIVE
2 victims

robbinhood

ransomware group
ACTIVE
2 victims

hades

ransomware group
INACTIVE

Hades is a ransomware group first observed in December 2020, believed by several threat intelligence firms to be operate...

1 victims

hddcryptor

ransomware group
ACTIVE
1 victims

cerber

ransomware group
ACTIVE
1 victims

cryptomix

ransomware group
ACTIVE
1 victims

prinz eugen

ransomware group
ACTIVE
1 victims

lechiffre

ransomware group
ACTIVE
1 victims

keyholder

ransomware group
ACTIVE
1 victims

deathkitty

ransomware group
INACTIVE
1 victims

satancd

ransomware group
1 victimsSince Apr 13, 2026

cryptoware

ransomware group
ACTIVE
1 victims

goznym

ransomware group
ACTIVE
1 victims

megacode

ransomware group
ACTIVE
1 victims

memedusalockerdusa

ransomware group
INACTIVE
1 victims

sharpboys

ransomware group
1 victimsSince Jul 8, 2025

kyber

ransomware group
ACTIVE
1 victimsSince Feb 13, 2026

sicarii

ransomware group
INACTIVE
1 victimsSince Jan 19, 2026

maui

ransomware group
INACTIVE
1 victims

team underground

ransomware group
1 victimsSince Sep 30, 2023

threatmarket

ransomware group
1 victimsSince Apr 13, 2026

darkrypt

ransomware group
1 victimsSince Jan 25, 2025

thanos

ransomware group
INACTIVE
1 victims

macaw

ransomware group
INACTIVE
1 victims

blackbyte-crux

ransomware group

Crux is a newly identified ransomware variant active since July 2025, which claims affiliation with the established Blac...

1 victimsSince Nov 17, 2025

wikileaksv2

ransomware group

Group is connected to Qilin.

1 victimsSince Jul 9, 2024

insane

ransomware group
INACTIVE
1 victims

ranstreet

ransomware group
INACTIVE
1 victimsSince Dec 27, 2023

agelocker

ransomware group
INACTIVE
1 victims

late.lol

ransomware group

Affiliates: <br/>@Mr.C <br/>@Empathy <br/>@jayze <br/>@Widow <br/>@Memory <br/> <br/>

1 victimsSince Apr 13, 2026

zerolockersec

ransomware group
ACTIVE
1 victimsSince Feb 13, 2026

roadsweep

ransomware group
INACTIVE
1 victims

la_piovra

ransomware group
INACTIVE

ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)

1 victimsSince Jun 14, 2023

pewcrypt

ransomware group
ACTIVE
1 victims

astroteam

ransomware group
INACTIVE
1 victims

fletchen

ransomware group
ACTIVE
1 victimsSince Jan 24, 2026

zerotolerance

ransomware group
INACTIVE
1 victimsSince Dec 31, 2024

cring

ransomware group
INACTIVE
1 victims

erebus

ransomware group
ACTIVE
1 victims

global3

ransomware group
ACTIVE
1 victims

nozelesn

ransomware group
ACTIVE
1 victims

samas

ransomware group
ACTIVE
1 victims

triplem

ransomware group
ACTIVE
1 victims

slug

ransomware group
INACTIVE
1 victims

reynolds

ransomware group
ACTIVE
1 victimsSince Feb 13, 2026

ronggolawe

ransomware group
INACTIVE
1 victims

crosslock

ransomware group
INACTIVE

CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion ...

1 victims

blogxx

ransomware group
INACTIVE
1 victims

walocker

ransomware group
INACTIVE
1 victimsSince Aug 22, 2025

synack

ransomware group
INACTIVE
1 victims

Abrahams_Ax

ransomware group
ACTIVE

Abrahams_Ax, first observed in November 2022, is not a Ransomware-as-a-Service (RaaS) operation but a politically motiva...

1 victimsSince Dec 31, 2024

netflim

ransomware group
INACTIVE
1 victims

aGl0bGVyCg

ransomware group
ACTIVE

This ransomware group (notably stylized as aGl0bGVyCg) has extremely limited publicly available information. No confirme...

1 victims

phoenixcryptolocker

ransomware group
INACTIVE
1 victims

cloak.su (locker leak)

ransomware group
1 victimsSince Mar 24, 2026

zeppelin

ransomware groupRaaS
INACTIVE

Zeppelin ransomware is a derivative of the Delphi-based Vega malware family and functions as a Ransomware as a Service (...

1 victims

waissbein

ransomware group
1 victimsSince Apr 9, 2026

killada

ransomware group
1 victimsSince Apr 13, 2026

networm

ransomware group
INACTIVE
1 victims

playboy

ransomware group
INACTIVE
1 victimsSince Dec 31, 2024

zetarink

ransomware group
1 victimsSince Apr 13, 2026

GDLockerSec

ransomware group
INACTIVE

Our team members are from different countries and we are not interested in anything else, we are only interested in doll...

1 victimsSince Jan 27, 2025

yurei

ransomware group
INACTIVE
1 victimsSince Sep 12, 2025

hermes

ransomware groupRaaS

Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group op...

1 victims

gandcrab

ransomware groupRaaS
INACTIVE

GandCrab was a prolific Ransomware-as-a-Service (RaaS) operation active from January 2018 to mid-2019. It quickly became...

1 victimsSince Dec 9, 2024

lambda

ransomware group
INACTIVE
0 victims

dread

ransomware group
ACTIVE
0 victims

x001xs

ransomware group
INACTIVE
0 victims

bytesfromheaven

ransomware group
INACTIVE
0 victimsSince Aug 12, 2025

mydata

ransomware group
INACTIVE
0 victimsSince Dec 9, 2024

wiper leak

ransomware group
0 victimsSince Apr 13, 2026

white lock

ransomware group
INACTIVE
0 victimsSince Nov 4, 2025

xollam

ransomware group
0 victims

good day

ransomware group
INACTIVE

Good Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to it...

0 victimsSince Jun 24, 2024

aztroteam

ransomware group
INACTIVE
0 victims

moisha

ransomware group
INACTIVE
0 victims

ghost

ransomware group

aka Cring / Ghost (Cring) <br/> <br/>Beginning early 2021, Ghost actors began attacking victims whose internet facing se...

0 victims

mbc

ransomware group
INACTIVE
0 victims

j group

ransomware group
0 victimsSince Dec 15, 2025

miga

ransomware group
INACTIVE

#MakeIsraelGreatAgain

0 victimsSince Sep 29, 2025

jigsaw

ransomware group

Jigsaw is a ransomware family first observed in April 2016, notorious for its psychological intimidation tactics. It enc...

0 victims

mario esxi

ransomware group
0 victims

nvrmre

ransomware group
INACTIVE

AKA Lemon

0 victimsSince Mar 6, 2025

cooming

ransomware group
INACTIVE

previous clearnet domain coomingproject.com

0 victims

vandev

ransomware group
0 victims

sugar

ransomware group
INACTIVE
0 victims

piratelock

ransomware groupRaaS
0 victims

root

ransomware group
0 victims

polyvice

ransomware group
0 victims

wiki ransomware

ransomware group
0 victims

lokilocker

ransomware group
0 victims

vurten

ransomware group
0 victims

enciphered

ransomware group

aka xoriste

0 victims

inpivx

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

vasalocker

ransomware group
0 victims

w3crypto

ransomware group
INACTIVE
0 victimsSince Jun 16, 2025

thegreenbloodgroup

ransomware group
ACTIVE
0 victimsSince Feb 13, 2026

ranion

ransomware groupRaaS
INACTIVE
0 victims

megazord

ransomware group
0 victims

ransomedvc2

ransomware groupRaaS
INACTIVE

RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.

0 victimsSince Mar 27, 2026

shadow

ransomware group
INACTIVE
0 victims

darkbit

ransomware group
INACTIVE
0 victimsSince Feb 15, 2023

naga

ransomware group
INACTIVE
0 victimsSince Jun 2, 2025

deadbydawn

ransomware group
0 victims

zixer2

ransomware group
0 victims

vfokx

ransomware group
INACTIVE
0 victims

malphas

ransomware group
0 victims

phantom

ransomware group
0 victims

muliaka

ransomware group
0 victims

robbing hood

ransomware group
INACTIVE
0 victimsSince Jun 15, 2025

weaxor

ransomware group
0 victimsSince Dec 18, 2024

adminlocker

ransomware group
INACTIVE

AdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear Rans...

0 victims

mamona

ransomware groupRaaS
INACTIVE
0 victimsSince Mar 19, 2025

belsen group

ransomware group
INACTIVE

aka Belesn Group. <br/>Belsen Group emerged in January 2025 as a data broker and leak-focused threat actor, not engaging...

0 victimsSince Mar 12, 2025

globeimposter

ransomware group

GlobeImposter is a ransomware family that first appeared in mid-2017, designed to mimic the appearance and naming conven...

0 victims

lcryptorx

ransomware group
INACTIVE
0 victimsSince May 9, 2025

lilith

ransomware group
INACTIVE
0 victims

ox thief

ransomware group
INACTIVE
0 victimsSince Mar 13, 2025

aptlock

ransomware group
INACTIVE

Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage. T...

0 victimsSince Mar 24, 2025

madcat

ransomware group
INACTIVE
0 victimsSince Nov 27, 2023

cryptedpay

ransomware group

CryptedPay is a standalone ransomware strain observed around early 2025, that encrypts files using AES-256 and appends t...

0 victims

zeoticus2

ransomware group
0 victims

ranzy

ransomware group
INACTIVE
0 victims

monolock

ransomware group
INACTIVE
0 victimsSince Jan 23, 2026

mydecryptor

ransomware group
INACTIVE
0 victims

prometheus

ransomware group
INACTIVE

Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.

0 victims

0xFFF

ransomware group
INACTIVE
0 victims

turkish crypter

ransomware group
INACTIVE
0 victimsSince Apr 7, 2026

unknown

ransomware group
INACTIVE
0 victims

ctblocker

ransomware group
INACTIVE

aka Critroni <br/>CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve crypt...

0 victimsSince Dec 9, 2024

xelera

ransomware group
0 victims

haron

ransomware group
INACTIVE

Haron is a ransomware group that emerged in July 2021 and is believed to share operational similarities with the Avaddon...

0 victims

soleenya

ransomware group
INACTIVE
0 victimsSince Jun 15, 2025

kirov

ransomware group
0 victims

kuiper

ransomware group

Kuiper is a relatively new ransomware strain first analyzed in April 2023, notable for being written in Rust and designe...

0 victims

core

ransomware group

Core ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion m...

0 victims

slam

ransomware group
INACTIVE
0 victimsSince Jun 4, 2025

clop torrents

ransomware group
INACTIVE
0 victimsSince Jul 15, 2024

v is vendetta

ransomware group
0 victimsSince Feb 8, 2024

cyberex

ransomware group
INACTIVE
0 victimsSince May 27, 2025

blackbit

ransomware group
INACTIVE

BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and func...

0 victimsSince Aug 9, 2025

sicari

ransomware group
INACTIVE
0 victimsSince Jan 19, 2026

nemesis

ransomware group
INACTIVE
0 victimsSince Aug 13, 2025

krypt

ransomware group
INACTIVE
0 victimsSince Sep 28, 2025

fakersa

ransomware group
0 victims

elpaco

ransomware group

Elpaco is a variant of Mimic ransomware that emerged around August 2023. Designed with significant customization and ste...

0 victims

ShinySp1d3r

ransomware group
INACTIVE

Likely associated with the cybercrime group BlingLibra (ShinyHunters)

0 victims

toxic

ransomware group
INACTIVE
0 victimsSince Feb 22, 2025

lyrix

ransomware group
INACTIVE
0 victimsSince Dec 23, 2025

rapture

ransomware group
0 victims

tommyleaks

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

mcafee

ransomware group
0 victims

hyflock

ransomware group
INACTIVE
0 victimsSince Apr 7, 2026

zeoticus

ransomware group
0 victims

darkhav0c

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

unsafeleak

ransomware group
INACTIVE
0 victims

jo of satan

ransomware group
INACTIVE
0 victims

onepercent

ransomware group
INACTIVE
0 victims

rransom

ransomware group
INACTIVE
0 victims

desolated

ransomware group
0 victims

elcometa

ransomware group
0 victims

punisher

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

cerberimposter

ransomware group

Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting o...

0 victims

lockbit4

ransomware groupRaaS
0 victimsSince Jun 3, 2025

paradise

ransomware group
0 victims

kawa

ransomware group
0 victimsSince Aug 16, 2025

kasseika

ransomware group

Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatt...

0 victims

backmydata

ransomware group

BackMyData is a variant of the Phobos ransomware family, first observed in early 2024. It follows a double‑extortion mod...

0 victims

endurance

ransomware group
INACTIVE

Endurance is a destructive ransomware variant first observed in 2023, developed and operated by the threat actor known a...

0 victimsSince Jun 1, 2023

lynxr

ransomware group
0 victims

yashma

ransomware group
0 victims

proton

ransomware group
0 victims

bluesky

ransomware group
INACTIVE

BlueSky ransomware first emerged in July 2022 and is characterized by aggressive, high-speed file encryption using a mul...

0 victims

dataf locker

ransomware group
INACTIVE

DataF Locker is a ransomware variant first observed in 2024, closely tied to the Babuk ransomware lineage. It operates u...

0 victimsSince Dec 9, 2024

quicklock

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

ransomcartel

ransomware group
INACTIVE
0 victims

buddyransome

ransomware group
0 victims

jaff

ransomware group
INACTIVE

Jaff is a ransomware family first discovered in May 2017, notable for its distribution via large-scale spam campaigns op...

0 victimsSince Dec 10, 2024

aware

ransomware group
INACTIVE
0 victimsSince Jan 25, 2026

locus

ransomware group
INACTIVE
0 victimsSince Jan 1, 2026

arcrypter

ransomware group

ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government en...

0 victims

colossus

ransomware group

Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S...

0 victims

exorcist

ransomware group
INACTIVE

Ransomware.

0 victims

promptlock

ransomware group
INACTIVE

First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama ...

0 victims

tuborg

ransomware group
0 victims

nemty

ransomware group
INACTIVE

Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed throug...

0 victims

cryakl

ransomware group

also known as “Fantomas”. <br/>Cryakl first appeared in 2014, spreading primarily across Eastern Europe and Russia via p...

0 victims

2023lock

ransomware group

2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus fa...

0 victims

d0glun

ransomware group
INACTIVE

D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermedia...

0 victimsSince Jan 30, 2025

cs-137

ransomware group

Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for enc...

0 victims

paradise2

ransomware group
0 victims

darkangel

ransomware group
INACTIVE

Dark Angels is a highly targeted ransomware and data-extortion group that emerged in spring 2022. Rather than using an a...

0 victims

holyghost

ransomware group
INACTIVE

HolyGhost is a ransomware group first publicly reported in July 2022, believed to be operated by a North Korean state-sp...

0 victims

hotarus

ransomware group
INACTIVE

Hotarus is a ransomware and data extortion group first observed in March 2021, believed to be linked to threat actors of...

0 victims

mortalkombat

ransomware group
0 victims

sundawn

ransomware group
0 victims

makop

ransomware group
0 victims

crysis

ransomware group

Crysis ransomware was first identified in early 2016 and is a long-running family that later evolved into the Dharma ran...

0 victims

zeon

ransomware group
INACTIVE
0 victims

offwhite

ransomware group
0 victims

arcane

ransomware group

Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations aga...

0 victims

phalcon

ransomware group
0 victims

mailto

ransomware group
0 victims

solidbit

ransomware group
INACTIVE

Ransomware, written in .NET.

0 victims

farattack

ransomware group
0 victims

superblack

ransomware group
0 victims

eruption

ransomware group

Rebranded to Sabbath.

0 victims

taronis

ransomware group
0 victims

vsop

ransomware group
INACTIVE

aka Onix/Onyx

0 victimsSince Jan 2, 2023

ransom corp

ransomware group
INACTIVE
0 victims

ymir

ransomware group
0 victims

amnesia

ransomware group

Amnesia ransomware was first identified in May 2017, particularly affecting enterprise cloud environments. It does not a...

0 victims

babyduck

ransomware group
INACTIVE
0 victims

scattered lapsus$ hunters

ransomware group
0 victimsSince Apr 13, 2026

blackfield

ransomware group
INACTIVE
0 victimsSince Feb 17, 2026

fsteam

ransomware group
INACTIVE

New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware ...

0 victimsSince Jan 7, 2023

bidon

ransomware group

BIDON is a variant of the Monti ransomware family, first observed around mid‑2023. It employs a double‑extortion strateg...

0 victims

radiant group

ransomware group
INACTIVE
0 victimsSince Nov 12, 2025

hiveleak

ransomware group
INACTIVE
0 victims

gazprom

ransomware group
0 victims

telegram

ransomware group
0 victims

ech0raix

ransomware group
INACTIVE

The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom not...

0 victims

diavol

ransomware group
INACTIVE

Diavol is a ransomware strain first observed in June 2021, associated with the Wizard Spider threat group—best known for...

0 victims

nblock

ransomware group
INACTIVE
0 victimsSince Apr 10, 2026

megacortex

ransomware group
0 victims

providence

ransomware group
0 victims

quoter

ransomware group
0 victims

loki

ransomware group
INACTIVE
0 victimsSince Apr 12, 2026

rtm locker

ransomware group
INACTIVE
0 victimsSince Nov 5, 2025

phobos

ransomware group
0 victims

silent ransom

ransomware group
0 victims

mcrypt2019

ransomware group
0 victims

crypt ransomware

ransomware group
INACTIVE

.crYpt <br/>MD5: 54EFAC23D7B524D56BEDBCE887E11849 <br/> <br/>Babuk Variant

0 victimsSince Dec 11, 2024

azzasec

ransomware groupRaaS
INACTIVE

We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botne...

0 victimsSince Apr 28, 2025

insane ransomware

ransomware group
INACTIVE

Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public thr...

0 victimsSince Feb 12, 2024

himalayaa

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

risen

ransomware group
INACTIVE

Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malwa...

0 victimsSince Jun 5, 2024

proxima

ransomware group
0 victims

frozen

ransomware group
0 victims

lulzsec muslims

ransomware group
INACTIVE
0 victimsSince Jun 4, 2025

oceans

ransomware group
0 victims

schoolboys

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

relic

ransomware group
INACTIVE
0 victimsSince Jun 3, 2023

skira team

ransomware group
0 victimsSince Nov 29, 2025

ep918

ransomware group
INACTIVE
0 victims

thor

ransomware group
INACTIVE
0 victimsSince Jun 6, 2025

darkylock

ransomware group

Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk s...

0 victims

blacksnake

ransomware groupRaaS

BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began re...

0 victims

rustylocker

ransomware groupRaaS
INACTIVE
0 victimsSince Dec 10, 2025

zircon

ransomware group
INACTIVE
0 victimsSince Oct 30, 2025

hellokitty

ransomware group
INACTIVE

HelloKitty is a ransomware family first observed in November 2020, named after a string found in its binary. It operates...

0 victims

qilin-securotrop

ransomware group
0 victimsSince Apr 13, 2026

octovillan

ransomware group
INACTIVE
0 victimsSince Sep 18, 2025

babuk-locker

ransomware groupRaaS
INACTIVE

Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises ...

0 victimsSince Feb 26, 2024

ftcode

ransomware group
INACTIVE

FTCode is a ransomware family first observed in 2013 as a PowerShell-based threat and later resurfaced in September 2019...

0 victimsSince Dec 9, 2024

againstthewest

ransomware group
INACTIVE
0 victims

globe

ransomware group

Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allow...

0 victims

ironchain

ransomware group
INACTIVE
0 victimsSince Feb 22, 2026

qlocker

ransomware group
INACTIVE

login page, no posts

0 victims

bober

ransomware group
INACTIVE
0 victimsSince Aug 6, 2025

pyrx

ransomware group
INACTIVE
0 victimsSince Apr 17, 2025

targetcompany

ransomware group
0 victims

fsociety

ransomware groupRaaS
INACTIVE

This group is also known by their malware name, FLOCKER. <br/>FSociety is a modern Ransomware-as-a-Service (RaaS) operat...

0 victimsSince Aug 29, 2025

synapse

ransomware group
INACTIVE
0 victimsSince Jun 17, 2024

astralocker

ransomware group

AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-e...

0 victims

fivehands

ransomware groupRaaS

FiveHands is a ransomware family first observed in January 2021, believed to be a successor to the HelloKitty ransomware...

0 victims

gwisin

ransomware group
INACTIVE

Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South K...

0 victimsSince Dec 9, 2024

tooda

ransomware group

Members: <br/>Eco <br/>Ego <br/>emo <br/>elo <br/>user <br/>Dante <br/>Sevy

0 victimsSince Apr 13, 2026

spectre

ransomware group
0 victims

jsworm

ransomware group

JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolut...

0 victims

RAMP

ransomware group
INACTIVE
0 victims

dark shinigami

ransomware group
INACTIVE
0 victimsSince Dec 15, 2025

crazyhunter team

ransomware group

CrazyHunter is a rising ransomware threat first detected in early 2025, with particularly dangerous campaigns targeting ...

0 victimsSince Apr 3, 2025

obsidian orb

ransomware group
0 victims

ank

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

rabbithole

ransomware group
INACTIVE
0 victimsSince Dec 31, 2024

thundercrypt

ransomware group
0 victims

lamialocker

ransomware group
0 victims

evolution

ransomware group
0 victimsSince Jan 25, 2026

justice_blade

ransomware group
0 victimsSince Apr 13, 2026

chilelocker

ransomware group
INACTIVE

ChileLocker first emerged in August 2022 and is considered part of the broader ARCrypter ransomware family. It employs a...

0 victims

deathransom

ransomware group

DeathRansom is a ransomware family first seen in the wild in late 2019, initially appearing as a bluff—dropping ransom n...

0 victims

invaderx

ransomware group
0 victims

fargo

ransomware group

Fargo is a ransomware variant that surfaced in 2022, primarily targeting Microsoft SQL Server (MSSQL) systems. Believed ...

0 victims

help_restoremydata

ransomware group
INACTIVE

Help_restoremydata is a ransomware variant identified around late 2024/early 2025, notable for appending the .help_resto...

0 victimsSince Jan 27, 2025

kuza

ransomware group
0 victims

spring

ransomware group
0 victims

lsd

ransomware group
0 victimsSince Apr 13, 2026

vegalocker

ransomware group
0 victims

a1project

ransomware groupRaaS

The locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for E...

0 victims

devman2

ransomware groupRaaS
INACTIVE

DevMan 2.0 is the evolved iteration of the DevMan ransomware, first documented in July 2025. It enhances the capabilitie...

0 victimsSince Sep 28, 2025

xinof

ransomware group
INACTIVE
0 victims

C3RB3R

ransomware group
INACTIVE

Cerber ransomware, active since 2016, has resurfaced occasionally using the name C3RB3R. It operates as a semi-private R...

0 victims

n3tworm

ransomware group
INACTIVE
0 victims

key group

ransomware group
0 victims

xleaks

ransomware group
INACTIVE
0 victimsSince Oct 12, 2025

darkangels

ransomware group
INACTIVE
0 victims

balletspistol

ransomware group

BalletsPistol is a Python-based ransomware strain distributed via GitHub. An investigative report from June 2025 reveals...

0 victims

monte

ransomware group
INACTIVE
0 victimsSince Sep 28, 2022

sifrecikis

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

deathgrip

ransomware groupRaaS

DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked...

0 victims

sphinx

ransomware group
INACTIVE
0 victimsSince Sep 2, 2025

avos

ransomware group
INACTIVE

First observed in July 2021, AvosLocker operates as a Ransomware-as-a-Service (RaaS) platform employing a double-extorti...

0 victims

blackberserk

ransomware group

Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023. It operates under a single‑extort...

0 victims

catb

ransomware group

CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distribut...

0 victims

black witch

ransomware group
0 victims

zeta leaks

ransomware group
INACTIVE
0 victimsSince Aug 7, 2025

gangbang

ransomware group
0 victims

luckbit

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

zero tolerance gang (ztg)

ransomware group
INACTIVE
0 victimsSince May 20, 2024

babuk-bjorka

ransomware group
INACTIVE

On January 26th, Babuk's dedicated leak site (DLS) was "relaunched". Bjorka (Telegram: @bjorkanesiaaaa) is the current a...

0 victimsSince Jan 27, 2025

mimic

ransomware group
0 victims

mespinoza

ransomware group
0 victims

darkbit01

ransomware group
INACTIVE

DarkBit is a politically motivated ransomware operation active since February 2023, targeting academic and public sector...

0 victims

babylockerkz

ransomware group

BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023. It operates under a double‑extortion ...

0 victims

dagonlocker

ransomware groupRaaS
INACTIVE

Dagon Locker is a double-extortion ransomware family that surfaced around September 2022. It represents an evolution of ...

0 victims

crynox

ransomware group

Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to...

0 victims

bitransomware

ransomware group
INACTIVE

BitRansomware (also known as DCryptSoft or ReadMe) surfaced in November 2020, primarily as a widespread cryptolocker tar...

0 victimsSince Dec 9, 2024

nevada

ransomware group
INACTIVE
0 victims

darkwave

ransomware group
INACTIVE

Written in python

0 victimsSince Feb 19, 2026

petya

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

elonmusknow

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

zola

ransomware group
0 victims

ransomware blog

ransomware group
INACTIVE

Also known as MedusaLocker

0 victimsSince Nov 18, 2025

encrypthub

ransomware group
0 victims

ako

ransomware groupRaaS
INACTIVE

First observed in early January 2020 (initial victim post on January 9, 2020), Ako (also known as MedusaReborn) operates...

0 victims

ra group

ransomware group
INACTIVE
0 victimsSince Aug 25, 2023

fusion

ransomware group
0 victims

cryptxxx

ransomware group
INACTIVE

CryptXXX is a ransomware strain that first appeared in April 2016, developed by the same group behind the Reveton and An...

0 victimsSince Dec 9, 2024

mimic-guram

ransomware groupRaaS

Mimic v.10 Ransomware-as-a-Service (RaaS). The malware is designed to target various operating systems (Windows, ESXi, N...

0 victims

b0 group

ransomware group
INACTIVE

B0 is a relatively obscure ransomware operation with very limited public reporting outside of leak site monitoring. It a...

0 victimsSince May 8, 2025

freeworld

ransomware group

FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomw...

0 victims

tycoon

ransomware group
0 victims

cerbersyslock

ransomware group

CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceiv...

0 victims

0apt

ransomware groupRaaS
INACTIVE

The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele...

0 victimsSince Feb 13, 2026

izis

ransomware group
INACTIVE
0 victimsSince Sep 13, 2025

br0k3r

ransomware group
INACTIVE

Br0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group lever...

0 victimsSince Jan 16, 2025

axxes

ransomware group
INACTIVE

Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing ...

0 victimsSince Jul 8, 2025

vulcan

ransomware groupRaaS
0 victimsSince Apr 13, 2026

blackhunt

ransomware group
INACTIVE

Black Hunt ransomware has been active since at least mid-2021 and operates under a double-extortion model, encrypting vi...

0 victimsSince Jul 9, 2025

argonauts group

ransomware group
INACTIVE

Argonauts Group is a data extortion operation that surfaced around September–October 2024, primarily targeting organizat...

0 victimsSince Mar 27, 2025

arkana security

ransomware group
INACTIVE

Arkana Security emerged in early 2025, debuting with a high-profile data-extortion campaign against the U.S. internet pr...

0 victimsSince Jul 6, 2025

abyss-data

ransomware group
INACTIVE

Abyss‑Data, also known as Abyss Locker, is a ransomware operation first identified around March 2023. It conducts double...

0 victimsSince Oct 17, 2024

entropy

ransomware group
INACTIVE

Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomw...

0 victims

cylance

ransomware group
0 victims

shade

ransomware group
INACTIVE
0 victimsSince Dec 12, 2024

spirigatito

ransomware group
0 victims

Payday

ransomware group
ACTIVE
0 victims

u-bomb

ransomware group
INACTIVE
0 victimsSince Dec 31, 2024

esxiargs

ransomware group
ACTIVE

ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-202...

0 victims

miliphen

ransomware group
0 victims

vaultcrypt

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

grinch

ransomware group
0 victims

bluelocker

ransomware group
INACTIVE

Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum

0 victims

lolnek

ransomware group
INACTIVE
0 victims

kryptina

ransomware group
0 victims

tssxx25

ransomware group
INACTIVE
0 victimsSince Aug 28, 2025

ransombay

ransomware group
INACTIVE

Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative

0 victimsSince May 13, 2025

3am

ransomware group
INACTIVE

3AM, also known as ThreeAM, is a relatively new ransomware family that emerged in late 2023, initially deployed as a fal...

0 victimsSince Jan 9, 2025

crylock

ransomware groupRaaS
INACTIVE

CryLock is a ransomware variant that emerged around April 2020, evolving from the Cryakl (Fantomas) ransomware family. I...

0 victims

thunder x

ransomware group
0 victims

faust

ransomware group

Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since ...

0 victims

delta

ransomware group
0 victims