Threat Groups
359 tracked groups
everest
ransomware grouplockbit3
ransomware groupakira
ransomware groupplay
ransomware groupqilin
ransomware groupclop
ransomware grouplockbit2
ransomware groupalphv
ransomware groupincransom
ransomware groupbianlian
ransomware groupblackbasta
ransomware groupmedusa
ransomware groupransomhub
ransomware group8base
ransomware groupsafepay
ransomware groupdragonforce
ransomware grouplynx
ransomware groupconti
ransomware groupdispossessor
ransomware groupinterlock
ransomware grouppysa
ransomware grouphunters
ransomware groupkillsec
ransomware groupnightspire
ransomware groupsinobi
ransomware groupRansomware group active in data extortion.
rhysida
ransomware groupthegentlemen
ransomware groupActive ransomware group with data extortion operations.
cactus
ransomware groupransomhouse
ransomware grouphive
ransomware groupMajor RaaS operation disrupted by FBI in January 2023.
FOG
ransomware groupvicesociety
ransomware groupblacksuit
ransomware groupmalas
ransomware grouphandala
ransomware groupfunksec
ransomware grouplockbit5
ransomware groupdevman
ransomware groupFormer RansomHub and INC Ransom affiliate.
royal
ransomware groupcloak
ransomware groupbabuk2
ransomware groupBabuk 2.0/SatanLock. Impersonates original Babuk.
coinbasecartel
ransomware groupCoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on...
blackbyte
ransomware groupavaddon
ransomware groupstormous
ransomware groupmeow
ransomware groupsarcoma
ransomware groupsnatch
ransomware groupworldleaks
ransomware groupActive ransomware and data leak group.
ragnarlocker
ransomware groupnoescape
ransomware groupspacebears
ransomware groupraworld
ransomware groupRA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.
toufan
ransomware groupPro-Palestinian Group
monti
ransomware groupcuba
ransomware groupeldorado
ransomware grouparcusmedia
ransomware groupnova
ransomware groupNova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion t...
pear
ransomware groupPure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a...
apt73
ransomware grouprevil
ransomware groupransomexx
ransomware groupSilentRansomGroup
ransomware groupa former Conti team
abyss
ransomware groupwarlock
ransomware groupThe Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is al...
lorenz
ransomware groupcicada3301
ransomware groupshinyhunters
ransomware groupkarakurt
ransomware groupkairos
ransomware groupdirewolf
ransomware groupavoslocker
ransomware groupquantum
ransomware groupransomed
ransomware groupbeast
ransomware groupRansomware group active in data extortion.
anubis
ransomware groupRansomware group active in data extortion.
threeam
ransomware groupblacklock
ransomware groupBlackLock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most acti...
orion
ransomware grouplv
ransomware groupmaze
ransomware groupflocker
ransomware grouppayoutsking
ransomware groupchaos
ransomware groupblacknevas
ransomware groupdarkvault
ransomware groupknight
ransomware grouptengu
ransomware groupRansomware group active in data extortion.
losttrust
ransomware groupgenesis
ransomware groupmedusalocker
ransomware groupMedusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predec...
braincipher
ransomware grouptrigona
ransomware groupmallox
ransomware groupnitrogen
ransomware groupryuk
ransomware groupblackshrantac
ransomware groupJ
ransomware groupcrypto24
ransomware groupdonutleaks
ransomware groupmidas
ransomware groupembargo
ransomware group0mega
ransomware groupdaixin
ransomware groupdarkleakmarket
ransomware grouptermite
ransomware groupmetaencryptor
ransomware grouphelldown
ransomware groupnokoyawa
ransomware groupciphbit
ransomware grouparvinclub
ransomware groupobscura
ransomware groupspook
ransomware groupsecurotrop
ransomware groupwannacry
ransomware groupWannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its...
suncrypt
ransomware groupblackmatter
ransomware groupmarketo
ransomware groupdatacarry
ransomware groupdAn0n
ransomware groupfrag
ransomware groupdragonransomware
ransomware groupDragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a...
global
ransomware groupinsomnia
ransomware groupmoneymessage
ransomware groupwerewolves
ransomware groupkelvinsecurity
ransomware groupnetwalker
ransomware groupunderground
ransomware groupdoppelpaymer
ransomware groupvect
ransomware groupradar
ransomware groupAiLock
ransomware groupxinglocker
ransomware grouppayloadbin
ransomware groupralord
ransomware groupleaktheanalyst
ransomware groupsabbath
ransomware grouphellcat
ransomware groupgunra
ransomware grouppayload
ransomware groupcephalus
ransomware groupsiegedsec
ransomware grouptrinity
ransomware groupmorpheus
ransomware groupmountlocker
ransomware groupbravox
ransomware groupRansomware group active in data extortion.
brotherhood
ransomware groupd4rk4rmy
ransomware grouptridentlocker
ransomware groupmosesstaff
ransomware groupmadliberator
ransomware groupsparta
ransomware groupredransomware
ransomware groupbenzona
ransomware groupdunghill
ransomware groupapos
ransomware groupnefilim
ransomware groupazroteam
ransomware groupfreecivilian
ransomware groupweyhro
ransomware groupkawa4096
ransomware groupcheers
ransomware groupunsafe
ransomware groupA group which seems to recycle leak from other ransomware groups
onyx
ransomware grouplapsus$
ransomware groupargonauts
ransomware groupmindware
ransomware groupgroove
ransomware groupcryp70n1c0d3
ransomware groupatomsilo
ransomware groupalphalocker
ransomware groupIMNCrew
ransomware groupteamxxx
ransomware groupblackout
ransomware groupicefire
ransomware groupsecp0
ransomware groupEncrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only
darkrace
ransomware groupdarkside
ransomware groupdarkpower
ransomware groupcrazyhunter
ransomware groupkazu
ransomware groupmogilevich
ransomware grouprook
ransomware groupradiant
ransomware groupskira
ransomware groupmalekteam
ransomware groupcryptbb
ransomware groupbabuk
ransomware grouplockbit3_fs
ransomware groupkarma
ransomware groupchort
ransomware groupbert
ransomware grouppay2key
ransomware groupcyclops
ransomware groupcipherforce
ransomware groupRunSomeWares
ransomware grouparkana
ransomware groupVanHelsing
ransomware groupyanluowang
ransomware groupegregor
ransomware groupsilent
ransomware groupUnlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own...
rancoz
ransomware groupdataleak
ransomware grouppandora
ransomware groupkryptos
ransomware groupminteye
ransomware groupdonex
ransomware groupraznatovic
ransomware groupRANSOMED.VC aka Raznatovic
projectrelic
ransomware groupALP-001
ransomware groupredalert
ransomware grouplockbit
ransomware groupValenciaLeaks
ransomware groupbqtlock
ransomware grouplockdata
ransomware groupvanirgroup
ransomware grouplinkc
ransomware grouporca
ransomware groupdesolator
ransomware groupnullbulge
ransomware groupblacktor
ransomware groupshaoleaks
ransomware groupsatanlockv2
ransomware groupkraken
ransomware grouposiris
ransomware groupragnarok
ransomware groupsnake
ransomware groupbluebox
ransomware groupvendetta
ransomware groupms13089
ransomware grouphellogookie
ransomware groupqiulong
ransomware groupgrief
ransomware groupnoname
ransomware groupbonacigroup
ransomware groupexitium
ransomware grouprebornvc
ransomware groupblackshadow
ransomware groupbitlocker
ransomware groupdatakeeper
ransomware groupsensayq
ransomware groupcryptnet
ransomware groupkittykatkrew
ransomware groupprolock
ransomware grouptrisec
ransomware grouplunalock
ransomware groupdharma
ransomware grouppryx
ransomware groupContFR
ransomware groupRAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon...
wastedlocker
ransomware groupnightsky
ransomware groupransomcortex
ransomware grouprobinhood
ransomware groupla_piovra
ransomware groupℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
playboy
ransomware groupronggolawe
ransomware groupnasirsecurity
ransomware groupagelocker
ransomware groupGDLockerSec
ransomware groupOur team members are from different countries and we are not interested in anything else, we are only interested in doll...
deathkitty
ransomware groupphoenixcryptolocker
ransomware groupcring
ransomware groupnetflim
ransomware groupmaui
ransomware groupsicarii
ransomware groupzerolockersec
ransomware groupzerotolerance
ransomware groupmacaw
ransomware groupastroteam
ransomware groupsynack
ransomware groupinsane
ransomware groupmemedusalockerdusa
ransomware groupkyber
ransomware groupslug
ransomware groupblogxx
ransomware groupsekhmet
ransomware groupcry0
ransomware groupShadowByt3$
ransomware grouphades
ransomware groupwalocker
ransomware grouproadsweep
ransomware groupreynolds
ransomware groupzeppelin
ransomware groupnetworm
ransomware groupthanos
ransomware groupranstreet
ransomware groupyurei
ransomware groupcrosslock
ransomware groupako
ransomware groupmydecryptor
ransomware grouplambda
ransomware groupransomcartel
ransomware grouppromptlock
ransomware groupFirst known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama ...
fsteam
ransomware groupNew possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware ...
aware
ransomware groupShinySp1d3r
ransomware groupLikely associated with the cybercrime group BlingLibra (ShinyHunters)
qlocker
ransomware groupshadow
ransomware grouphellokitty
ransomware groupnevada
ransomware grouphotarus
ransomware groupx001xs
ransomware groupu-bomb
ransomware groupthegreenbloodgroup
ransomware groupbluesky
ransomware groupchilelocker
ransomware groupxinof
ransomware groupdiavol
ransomware groupfletchen
ransomware groupmbc
ransomware groupholyghost
ransomware groupbluelocker
ransomware groupBlue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum
entropy
ransomware groupmamona
ransomware group0xFFF
ransomware group0apt
ransomware groupThe group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele...
Abrahams_Ax
ransomware grouponepercent
ransomware groupdarkbit
ransomware groupavos
ransomware groupaGl0bGVyCg
ransomware groupech0raix
ransomware grouplilith
ransomware groupvfokx
ransomware groupC3RB3R
ransomware groupranion
ransomware groupagainstthewest
ransomware grouplolnek
ransomware groupxp95
ransomware grouprransom
ransomware groupep918
ransomware groupn3tworm
ransomware grouprabbithole
ransomware groupmadcat
ransomware groupaztroteam
ransomware groupadminlocker
ransomware groupcrylock
ransomware groupdagonlocker
ransomware groupexorcist
ransomware groupdarkangels
ransomware groupzeon
ransomware groupdarkbit01
ransomware groupnemty
ransomware groupunsafeleak
ransomware groupsugar
ransomware groupranzy
ransomware groupransombay
ransomware groupLaunched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative