Threat Groups

708 tracked groups

qilin

ransomware group🇷🇺RaaSNot trustworthy
ACTIVE

Qilin (also known as Agenda) is a ransomware-as-a-service operation that emerged in 2022, initially targeting healthcare...

2849 victimsSince Oct 8, 2022

lockbit3

ransomware group🇷🇺RaaS

LockBit 3.0 (also known as LockBit Black) is the third major iteration of the LockBit ransomware-as-a-service platform, ...

2413 victimsSince Jun 29, 2022

akira

ransomware group🇷🇺Recovery risk
ACTIVE

Akira ransomware first appeared in March 2023 and quickly became one of the most active groups of that year, targeting s...

1528 victimsSince Apr 26, 2023

play

ransomware group
ACTIVE

Play ransomware (also known as PlayCrypt) emerged in mid-2022 and is characterized by its use of the ".play" file extens...

1282 victimsSince Nov 26, 2022

clop

ransomware group🇷🇺
ACTIVE

Clop (also spelled Cl0p) is a financially motivated ransomware group attributed to the FIN11/TA505 threat cluster with a...

1031 victimsSince Mar 13, 2020

thegentlemen

ransomware group🇷🇺RaaS
ACTIVE

The Gentlemen is a ransomware-as-a-service group that emerged in mid-2024 and rapidly accumulated victims across North A...

869 victimsSince Sep 9, 2025

alphv

ransomware group🇷🇺RaaSNot trustworthy

ALPHV (also known as BlackCat or Noberus) was a sophisticated ransomware-as-a-service operation launched in November 202...

848 victimsSince Sep 9, 2021

incransom

ransomware group
ACTIVE

INC Ransom (INCransom) is a double-extortion ransomware group that emerged in mid-2023, targeting healthcare, education,...

777 victimsSince Aug 9, 2023

medusa

ransomware groupRaaS

Medusa ransomware (not to be confused with MedusaLocker) is a ransomware-as-a-service operation that became highly activ...

685 victimsSince Jan 11, 2023

lockbit2

ransomware group🇷🇺RaaS
INACTIVE

LockBit 2.0 (also known as LockBit Red) was the second major version of the LockBit ransomware-as-a-service platform, ac...

651 victimsSince Sep 9, 2021

8base

ransomware group
INACTIVE

8Base is a double-extortion ransomware group that first appeared in early 2022 but dramatically escalated activity in mi...

625 victimsSince May 23, 2023

ransomhub

ransomware group🇷🇺RaaS
INACTIVE

RansomHub is a ransomware-as-a-service operation that launched in February 2024 and rapidly became one of the most activ...

598 victimsSince Feb 10, 2024

blackbasta

ransomware group🇷🇺Recovery risk
INACTIVE

Black Basta emerged in April 2022 and is widely assessed by researchers and law enforcement to be composed of former Con...

543 victimsSince Apr 26, 2022

dragonforce

ransomware group🇲🇾RaaS
ACTIVE

DragonForce is a ransomware-as-a-service operation with roots in a Malaysian hacktivist group of the same name that was ...

541 victimsSince Dec 13, 2023

safepay

ransomware group
ACTIVE

SafePay is a double-extortion ransomware group that emerged in late 2024, quickly attracting attention for its professio...

495 victimsSince Nov 19, 2024

everest

ransomware group🇷🇺
ACTIVE

Everest is a Russian-speaking ransomware and data extortion group active since at least 2020, known for targeting critic...

462 victimsSince Sep 9, 2021

lynx

ransomware group🇷🇺RaaS
ACTIVE

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 and is assessed to be a rebrand or direct successor...

445 victimsSince Jul 29, 2024

sinobi

ransomware group🇷🇺
INACTIVE

Sinobi is a data extortion and ransomware group that emerged in 2024 and is assessed to have inherited personnel and cod...

359 victimsSince Jul 5, 2025

lockbit5

ransomware group🇷🇺RaaS
ACTIVE

LockBit 5.0 (also referred to as LockBit Nation-State) is a claimed successor to LockBit 3.0 that emerged after Operatio...

355 victimsSince Dec 4, 2025

cactus

ransomware group
INACTIVE

Cactus ransomware surfaced in March 2023 and quickly gained attention for exploiting vulnerabilities in Qlik Sense analy...

328 victimsSince Jul 20, 2023

killsec

ransomware group🇮🇳RaaS
ACTIVE

KillSec (Kill Security) is a hacktivist-turned-cybercriminal group that emerged in late 2023, linked by researchers to I...

327 victimsSince Mar 21, 2024

bianlian

ransomware group🇨🇳
INACTIVE

BianLian ransomware first appeared in June 2022 and is attributed by multiple researchers and the FBI/CISA to a China-ba...

317 victimsSince Jul 14, 2022

rhysida

ransomware group
ACTIVE

Rhysida is a ransomware group that emerged in May 2023, quickly gaining notoriety for attacking healthcare providers and...

295 victimsSince Jun 5, 2023

conti

ransomware group🇷🇺Reported reliable

Conti was one of the most prolific and financially damaging ransomware operations in history, attributed by the FBI and ...

289 victimsSince Jul 31, 2020

dispossessor

ransomware group🇤🇤RaaS
INACTIVE

Dispossessor (also tracked as Radar) was a ransomware-adjacent data extortion operation active from August 2023 until it...

283 victimsSince Apr 19, 2024

blacksuit

ransomware group🇷🇺RaaS
INACTIVE

BlackSuit is the rebranded continuation of the Royal ransomware operation, confirmed by CISA and FBI in an August 2024 j...

282 victimsSince Jun 12, 2023

nightspire

ransomware group
ACTIVE

Nightspire is a relatively new double-extortion ransomware group that emerged in early 2025 and has quickly accumulated ...

282 victimsSince Mar 12, 2025

killsec3

ransomware group
ACTIVE
277 victimsSince Apr 13, 2026

handala

ransomware group🇮🇷

Handala (also known as Handala Hack Team or Hatef) is an Iran-linked hacktivist group that emerged during the Israel-Ham...

253 victimsSince May 26, 2024

hunters

ransomware group🇷🇺RaaS
INACTIVE

Hunters International emerged in October 2023 and is widely assessed to be a rebrand or direct continuation of the Hive ...

227 victimsSince Oct 20, 2023

nova

ransomware group🇷🇺RaaS
ACTIVE

Nova (formerly known as RALord) is a ransomware-as-a-service operation that rebranded from RALord in late 2024. The grou...

223 victimsSince Apr 28, 2025

pysa

ransomware group🇫🇷Recovery risk
INACTIVE

PYSA (also known as Mespinoza) is a ransomware group active since 2019 that has primarily targeted education, healthcare...

223 victimsSince Jul 1, 2020

stormous

ransomware group🇤🇤

Stormous is a pro-Russian hacktivist and ransomware group that emerged around mid-2021, believed to include members from...

216 victimsSince Mar 22, 2022

worldleaks

ransomware group🇷🇺RaaS
ACTIVE

WorldLeaks is the rebranded continuation of Hunters International, launched in January 2025 after the group ceased file-...

198 victimsSince May 16, 2025

FOG

ransomware group
INACTIVE

FOG ransomware is a sophisticated strain first observed in May 2024, initially targeting US educational institutions bef...

192 victimsSince Jul 16, 2024

ransomhouse

ransomware group🇷🇺
ACTIVE

RansomHouse is a data extortion group and marketplace active since December 2021 that focuses on stealing data without n...

192 victimsSince Jun 1, 2021

sarcoma

ransomware group

Sarcoma is a double-extortion ransomware group that emerged in mid-2024, primarily targeting manufacturing, professional...

176 victimsSince Oct 9, 2024

funksec

ransomware group🇩🇿

FunkSec is an Algerian ransomware group that emerged in late 2024 and quickly generated a high victim count through a co...

174 victimsSince Dec 4, 2024

royal

ransomware group🇷🇺
INACTIVE

Royal ransomware was active from September 2022 to mid-2023 and is believed to have been formed by former members of the...

166 victimsSince Nov 4, 2022

spacebears

ransomware group
ACTIVE

SpaceBears is a data extortion group that emerged in 2024, focusing on stealing and publishing sensitive corporate data ...

164 victimsSince Apr 29, 2024

devman

ransomware group🇷🇺RaaS
INACTIVE

Devman is a former RansomHub and INC Ransom affiliate that began operating independently as a ransomware-as-a-service pl...

158 victimsSince Apr 6, 2025

hive

ransomware group🇷🇺
INACTIVE

Hive was a major ransomware-as-a-service operation active from June 2021 until January 2023, targeting over 1,500 organi...

155 victimsSince Jun 1, 2021

beast

ransomware groupRaaS
INACTIVE

Beast ransomware operates as a ransomware-as-a-service platform targeting Windows, Linux, and VMware ESXi environments. ...

146 victimsSince Jul 29, 2025

coinbasecartel

ransomware group🇷🇺RaaS
ACTIVE

CoinbaseCartel (also known as CoinBase Cartel) is a financially motivated cybercrime group that operates a data acquisit...

145 victimsSince Sep 15, 2025

vicesociety

ransomware group🇷🇺
INACTIVE

Vice Society is a ransomware group that was active from mid-2021 to 2023, distinguished by its heavy focus on the educat...

142 victimsSince May 31, 2021

blackbyte

ransomware group🇷🇺RaaS
INACTIVE

BlackByte is a ransomware-as-a-service operation first observed in July 2021, assessed to be Russia-linked and notable f...

139 victimsSince Oct 4, 2021

meow

ransomware group
INACTIVE

Meow ransomware is a strain that emerged in 2022, appending the ".MEOW" extension to encrypted files and primarily targe...

134 victimsSince Nov 24, 2023

shinyhunters

ransomware group🇤🇤
ACTIVE

ShinyHunters is a prolific data theft and extortion group responsible for numerous high-profile breaches including the 2...

133 victimsSince Oct 3, 2025

malas

ransomware group
INACTIVE

Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its

125 victimsSince Apr 9, 2023

avaddon

ransomware group🇷🇺
INACTIVE

Avaddon was a ransomware-as-a-service operation active from June 2020 to June 2021, when the operators unexpectedly shut...

123 victimsSince Feb 1, 2021

snatch

ransomware group🇷🇺
INACTIVE

Snatch ransomware (not to be confused with the 2022 data extortion group reusing the brand) is a Russia-linked operation...

113 victimsSince Nov 29, 2021

apt73

ransomware group🇷🇺
ACTIVE

APT73 is a ransomware group that operated under the "eraleign" identity before rebranding as Bashe in October 2024. Some...

110 victimsSince Apr 22, 2024

eldorado

ransomware group🇷🇺RaaS
INACTIVE

Eldorado is a ransomware-as-a-service operation that emerged in early 2024, offering both Windows and VMware ESXi encryp...

110 victimsSince Jun 6, 2024

threeam

ransomware group🇷🇺
ACTIVE

3AM (ThreeAM) is a ransomware group discovered in September 2023, first observed being deployed as a fallback when LockB...

109 victimsSince Sep 14, 2023

genesis

ransomware group
ACTIVE

Financial interests only. <br/> We do not provide or work with affiliate programs, no collaborations either. <br/...

108 victimsSince Oct 21, 2025

noescape

ransomware group🇷🇺RaaS
INACTIVE

NoEscape was a ransomware-as-a-service operation that launched in June 2023 and is assessed by multiple researchers to b...

107 victimsSince Jun 12, 2023

anubis

ransomware group🇷🇺RaaS
ACTIVE

Anubis ransomware emerged in 2024 as a data extortion and ransomware-as-a-service platform that distinguishes itself wit...

106 victimsSince Feb 25, 2025

krybit

ransomware group
ACTIVE

Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with suppo

105 victimsSince Apr 3, 2026

monti

ransomware group🇷🇺
INACTIVE

Monti is a ransomware group that emerged in June 2022, widely assessed to be a copycat or offshoot of the Conti operatio...

102 victimsSince Dec 7, 2022

deadlock

ransomware group
ACTIVE
98 victimsSince Jun 15, 2026

interlock

ransomware group
ACTIVE

Interlock ransomware emerged in late 2024 and is notable for deploying a custom ransomware variant that targets both Win...

97 victimsSince Oct 13, 2024

ransomexx

ransomware group🇷🇺

RansomExx (also known as Defray777) is a ransomware family that targeted multiple high-profile organizations including K...

97 victimsSince May 14, 2020

babuk2

ransomware group🇷🇺Not trustworthy
INACTIVE

Babuk 2.0 (also styled as Babuk Locker 2.0 or SatanLock) is a group that impersonates the original Babuk ransomware oper...

96 victimsSince Jan 27, 2025

direwolf

ransomware group
ACTIVE

DirewWolf is a recently emerged double-extortion ransomware group that conducts targeted attacks against medium to large...

95 victimsSince May 22, 2025

pear

ransomware group
ACTIVE

PEAR (Pure Extraction And Ransom) Team is a data extortion group that emerged in 2024, focusing on publishing stolen cor...

95 victimsSince Aug 5, 2025

kairos

ransomware group🇷🇺
ACTIVE

Kairos is a double-extortion ransomware group that emerged in 2024, operating a dark web leak site and targeting organiz...

93 victimsSince Nov 13, 2024

SilentRansomGroup

ransomware group🇷🇺
ACTIVE

SilentRansomGroup (SRG) is a former Conti team that continued operating independently following Conti's dissolution in 2...

92 victimsSince May 6, 2025

wannacry

ransomware group🇰🇵
INACTIVE

WannaCry was a destructive ransomware worm deployed in May 2017 that infected over 200,000 computers across 150 countrie...

92 victimsSince May 12, 2017

revil

ransomware group🇷🇺RaaSReported reliable
INACTIVE

REvil (also known as Sodinokibi) was one of the most financially damaging ransomware-as-a-service operations in history,...

90 victimsSince Aug 26, 2019

abyss

ransomware group

Abyss (Abyss Data) is a data extortion group that emerged in early 2023, focusing on stealing and publishing sensitive c...

87 victimsSince Mar 21, 2023

arcusmedia

ransomware groupRaaS
ACTIVE

Arcus Media is a ransomware-as-a-service operation that first emerged in May 2024, offering affiliates a Linux and Windo...

84 victimsSince May 15, 2024

payload

ransomware group
ACTIVE

Payload is a ransomware group that emerged in 2024, primarily targeting organizations in North America and Europe throug...

84 victimsSince Feb 17, 2026

CRPxO

ransomware group
ACTIVE

CRPxO is actively recruiting affiliates, offering: 🔹 70% revenue share 🔹 XMR/BTC payouts 🔹 Claimed payouts within 24 ...

82 victimsSince Jul 9, 2026

cuba

ransomware group🇷🇺RaaS
INACTIVE

Cuba ransomware is a ransomware-as-a-service operation active since at least 2019, assessed to be Russia-linked despite ...

82 victimsSince Feb 3, 2021

ragnarlocker

ransomware group🇷🇺
INACTIVE

RagnarLocker was a Russia-linked ransomware group active from 2019 to 2023, known for conducting its own intrusions with...

79 victimsSince Apr 1, 2020

avoslocker

ransomware group
INACTIVE

AvosLocker is a ransomware-as-a-service operation that launched in mid-2021, known for targeting critical infrastructure...

71 victimsSince Jun 13, 2021

chaos

ransomware groupRaaS
ACTIVE

Chaos ransomware operates as a ransomware-as-a-service builder that has been widely distributed on underground forums si...

70 victimsSince Mar 31, 2025

embargo

ransomware group🇷🇺RaaS

Embargo is a ransomware-as-a-service operation that emerged in mid-2024, utilizing Rust-based encryptors for both Window...

70 victimsSince Apr 21, 2024

losttrust

ransomware group
INACTIVE

LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within da

70 victimsSince Sep 26, 2023

payoutsking

ransomware group
ACTIVE

Payouts King Group is a data extortion collective that explicitly states it does not operate as a RaaS and does not use ...

69 victimsSince Jul 7, 2025

warlock

ransomware group🇨🇳RaaS
INACTIVE

Warlock ransomware emerged in mid-2025 and has been attributed by Microsoft, Sophos, and Trend Micro with moderate-to-hi...

69 victimsSince Jun 10, 2025

AiLock

ransomware group🇷🇺RaaS
ACTIVE

AiLock is a ransomware-as-a-service group that emerged in early 2025, marketing itself as AI-assisted and suspected by r...

64 victimsSince Mar 3, 2026

cicada3301

ransomware group🇷🇺RaaS
INACTIVE

Cicada3301 (unrelated to the 2012 internet puzzle) is a ransomware-as-a-service operation that emerged in June 2024 with...

62 victimsSince Jun 20, 2024

ransomed

ransomware group
INACTIVE

RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims inclu

62 victimsSince Aug 21, 2023

toufan

ransomware group🇮🇷
INACTIVE

Toufan (also known as Toufan Al-Aqsa) is an Iran-linked hacktivist group that emerged during the Israel-Hamas conflict i...

62 victimsSince Dec 17, 2023

insomnia

ransomware group
ACTIVE

Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organ

60 victimsSince Feb 7, 2026

knight

ransomware groupRaaS
INACTIVE

Knight is a Ransomware-as-a-Service (RaaS) operation first observed in August 2023, believed to be a rebrand or evolutio...

60 victimsSince Sep 6, 2023

raworld

ransomware group🇨🇳
INACTIVE

RA World (formerly known as RA Group, active since April 2023) is a ransomware operation linked by Symantec and Palo Alt...

59 victimsSince May 6, 2023

CMDOrganization

ransomware group
ACTIVE

CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all...

57 victimsSince May 2, 2026

cloak

ransomware group

Cloak is a cybercriminal ransomware group that first emerged in late 2023, targeting small to mid-size businesses across...

56 victimsSince Aug 24, 2023

braincipher

ransomware group
ACTIVE

BrainCipher ransomware surfaced in mid-2024, initially gaining attention for a major attack against Indonesia's National...

54 victimsSince Jul 1, 2024

gunra

ransomware group
ACTIVE

Gunra is an emerging ransomware group first identified in April 2025. It employs a classic double-extortion model—encryp...

54 victimsSince Apr 23, 2025

karakurt

ransomware group🇷🇺

Karakurt is a data extortion group established in 2021 as an offshoot of the Conti ransomware operation (Wizard Spider),...

53 victimsSince Dec 11, 2022

lv

ransomware group
INACTIVE

parser needs to be built

53 victimsSince Nov 22, 2021

quantum

ransomware group🇷🇺
INACTIVE

Quantum ransomware emerged in August 2021 as a rebrand of the MountLocker operation and was subsequently linked to the C...

53 victimsSince Sep 9, 2021

settra

ransomware group
ACTIVE
53 victimsSince Jun 28, 2026

tengu

ransomware group
INACTIVE

Ransomware group active in data extortion.

53 victimsSince Oct 23, 2025

lorenz

ransomware group
INACTIVE

Lorenz is a ransomware group active since early 2021, known for an unusual tactic of selling access to victim networks t...

52 victimsSince Jan 12, 2020

blacklock

ransomware group🇷🇺
INACTIVE

BlackLock (also known as Mamona) is a ransomware-as-a-service operation that emerged in late 2023 as an evolution of the...

51 victimsSince May 16, 2025

darkvault

ransomware group
INACTIVE

DarkVault is a versatile threat actor that emerged in 2024, conducting both ransomware and data extortion operations aga...

51 victimsSince Apr 11, 2024

securotrop

ransomware group
ACTIVE

Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while mainta

51 victimsSince Jul 22, 2025

trigona

ransomware group
INACTIVE

Trigona ransomware was active from late 2022 to 2023, targeting businesses across multiple sectors with AES encryption a...

48 victimsSince Apr 17, 2023

crypto24

ransomware groupRaaS

aka Public Data Storage <br/>Crypto24 emerged in early 2025 as a fast-growing double-extortion ransomware-as-a-service ...

47 victimsSince Apr 8, 2025

frag

ransomware group
INACTIVE

Frag ransomware emerged in late 2024, primarily observed exploiting Veeam Backup & Replication vulnerabilities (CVE-2024...

47 victimsSince Mar 24, 2025

obscura

ransomware groupNot trustworthy
INACTIVE

Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via

47 victimsSince Sep 5, 2025

leakeddata

ransomware group
ACTIVE
46 victimsSince Feb 24, 2026

metaencryptor

ransomware group
ACTIVE

We are a group of young people who identify themselves as specialists in the field of network security with at least 15 ...

46 victimsSince Aug 16, 2023

m3rx

ransomware group
ACTIVE

M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in

45 victimsSince Apr 29, 2026

maze

ransomware group🇷🇺
INACTIVE

Maze ransomware pioneered the double-extortion model in late 2019, becoming the first major group to combine file encryp...

45 victimsSince Oct 21, 2019

nitrogen

ransomware groupNot trustworthy
INACTIVE

Nitrogen is a data extortion group that emerged in 2023, primarily conducting data theft without encryption to pressure ...

45 victimsSince Sep 30, 2024

termite

ransomware group
ACTIVE

Termite is a ransomware group that emerged in late 2024, gaining attention for exploiting a zero-day vulnerability in Cl...

45 victimsSince Nov 17, 2024

donutleaks

ransomware group
INACTIVE

DonutLeaks is a data extortion group that emerged in 2022, publishing stolen data from organizations that refused to pay...

44 victimsSince Aug 24, 2022

dAn0n

ransomware group
INACTIVE

dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model...

43 victimsSince Apr 25, 2024

global secret group

ransomware group
ACTIVE
42 victimsSince Jul 26, 2026

blacknevas

ransomware group
ACTIVE

BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct deriv...

41 victimsSince Aug 6, 2025

blackshrantac

ransomware group
INACTIVE

aka black shrantac

41 victimsSince Sep 17, 2025

lamashtu

ransomware group

Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Roma

39 victimsSince Apr 13, 2026

aurora

ransomware group
ACTIVE

Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams fro

38 victimsSince Apr 29, 2026

bravox

ransomware group
ACTIVE

Ransomware group active in data extortion.

38 victimsSince Feb 11, 2026

J

ransomware group
INACTIVE

J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 includi

38 victimsSince May 2, 2025

dragonransomware

ransomware group
INACTIVE

Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a...

34 victimsSince Dec 15, 2024

medusalocker

ransomware group
INACTIVE

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predec...

34 victimsSince Nov 15, 2022

ryuk

ransomware group🇷🇺Recovery risk
INACTIVE

Ryuk ransomware is attributed to the Russia-based Wizard Spider cybercriminal group and was one of the most damaging ran...

34 victims

spook

ransomware group
INACTIVE

Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on th

34 victimsSince Oct 4, 2021

darkleakmarket

ransomware group
INACTIVE

DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransom

33 victimsSince Sep 9, 2021

mallox

ransomware group🇨🇳RaaS
INACTIVE

Mallox (also known as TargetCompany, Fargo, or Tohnichi) is a ransomware-as-a-service operation assessed to be China-lin...

33 victimsSince Nov 4, 2022

moneymessage

ransomware group
ACTIVE

Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional

33 victimsSince Mar 29, 2023

alphalocker

ransomware group

AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin pane

31 victimsSince Jan 24, 2024

eraleign (apt73)

ransomware group🇷🇺
ACTIVE

Eraleign (APT73) rebranded as Bashe in October 2024 after operating under the Eraleign name, with the transition coincid...

30 victimsSince Jun 22, 2024

midas

ransomware group
INACTIVE

Midas ransomware is a data extortion group active since late 2021 that shares significant technical similarities with th...

30 victimsSince Nov 29, 2021

fulcrumsec

ransomware group

FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration

29 victimsSince Oct 30, 2025

helldown

ransomware group
INACTIVE

Helldown is a double-extortion ransomware group that emerged in late 2024, known for exploiting vulnerabilities in Zyxel...

29 victimsSince Aug 13, 2024

lapsus$

ransomware group🇬🇧

Lapsus$ is a data extortion group that emerged in late 2021, known for social engineering, SIM-swapping, and insider rec...

29 victimsSince Mar 1, 2026

IMNCrew

ransomware group
INACTIVE

IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial service

28 victimsSince May 5, 2025

nokoyawa

ransomware group
INACTIVE

Nokoyawa ransomware is a strain active from early 2022 that shares significant code and infrastructure with the Karma an...

28 victimsSince Dec 9, 2022

radar

ransomware group

Radar (also known as Dispossessor), active since August 2023 and led by an actor called "Brain," was a RaaS group target

28 victimsSince Sep 10, 2025

werewolves

ransomware group🇷🇺

Werewolves is a Russia-linked ransomware group that emerged in mid-2023, using a modified version of the LockBit 3.0 sou...

28 victimsSince Dec 20, 2023

ciphbit

ransomware group🇷🇺

CiphBit is a ransomware operation first detected in early 2024, using a custom encryptor targeting Windows and network s...

27 victimsSince Sep 14, 2023

titan

ransomware group
ACTIVE

Founded 4 April 2026

27 victimsSince May 18, 2026

blackmatter

ransomware group🇷🇺
INACTIVE

BlackMatter was a ransomware-as-a-service operation active from July to November 2021, widely assessed as a direct rebra...

26 victimsSince Sep 8, 2021

exfilsquad

ransomware group
ACTIVE

Only exfiltration

26 victimsSince Jul 26, 2026

morpheus

ransomware group
ACTIVE

Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCa

26 victimsSince Jan 7, 2025

marketo

ransomware group
INACTIVE

Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or ba

25 victimsSince Dec 7, 2021

Orova

ransomware group
ACTIVE

Emerging actor candidate first observed 2026-07-07; no verified public victim disclosure yet.

25 victimsSince Jul 7, 2026

daixin

ransomware group🇨🇳
INACTIVE

Daixin Team is a ransomware and data extortion group active since mid-2022, primarily targeting the US healthcare and pu...

24 victimsSince Aug 3, 2022

ShadowByt3$

ransomware group

ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communic

24 victimsSince Feb 25, 2026

arvinclub

ransomware group
INACTIVE

Arvin Club first appeared around early to mid-2021, debuting on its Tor leak site with posts dating back to May 5, 2021....

23 victimsSince Sep 9, 2021

cephalus

ransomware group
INACTIVE

Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomwar

23 victimsSince Aug 26, 2025

orion

ransomware group
ACTIVE

Jan13, 2026: We believe the group might be related to Babuk-Bjorka.

22 victimsSince Jan 14, 2026

trinity

ransomware group
INACTIVE

Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaC

22 victimsSince Jun 11, 2024

vect

ransomware groupNot trustworthy
INACTIVE

VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a f

22 victimsSince Jan 6, 2026

madliberator

ransomware group
INACTIVE

Group is also currently known as MADDLL32 and Metatron.

21 victimsSince Jul 17, 2024

ALP-001

ransomware group
INACTIVE

⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified. WE HAVE DECIDED TO REMOVE

20 victimsSince Mar 21, 2026

global

ransomware groupRaaS
INACTIVE

Now a RaaS by BlackLock ($$$). <br/>Global Group is a newly emerged Ransomware-as-a-Service (RaaS) platform that debuted...

20 victimsSince Jun 4, 2025

leaknet

ransomware group
ACTIVE

<br/> <br/>In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside infor...

19 victimsSince Aug 18, 2025

suncrypt

ransomware group🇷🇺
INACTIVE

SunCrypt is a ransomware group active since 2019 that joined the Maze ransomware cartel in 2020, adopting the double-ext...

19 victimsSince Aug 24, 2020

xinglocker

ransomware group
INACTIVE

xing use a custom mountlocker exe

19 victimsSince Apr 29, 2021

dunghill

ransomware group
INACTIVE

Dunghill Leak is the publicly branded data leak site (DLS) operated by the Dark Angels ransomware group, established cir...

18 victimsSince Apr 10, 2023

ralord

ransomware group
ACTIVE

RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, edu

18 victimsSince Mar 26, 2025

bavacai

ransomware group
17 victims

brotherhood

ransomware group
INACTIVE

Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia ac

17 victimsSince Nov 15, 2025

cyclops

ransomware groupRaaS
INACTIVE

Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023. It operates as a Ransomwar...

17 victimsSince Jul 1, 2023

d4rk4rmy

ransomware group
INACTIVE

D4rk4rmy is a data-extortion focused threat actor that emerged in mid-2025, targeting high-profile organizations across ...

17 victimsSince Jul 7, 2025

doppelpaymer

ransomware group🇷🇺
INACTIVE

DoppelPaymer ransomware is attributed to the Russia-based Evil Corp cybercriminal organization and is a successor to Bit...

17 victimsSince May 25, 2019

kelvinsecurity

ransomware group
INACTIVE

Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and web...

17 victimsSince Apr 1, 2022

netwalker

ransomware group🇨🇦
INACTIVE

NetWalker (also known as Mailto) was a ransomware operation active from 2019 to January 2021, when US and Bulgarian auth...

17 victimsSince Jan 31, 2020

leaktheanalyst

ransomware group
INACTIVE

LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims,

16 victimsSince Jan 1, 2022

tridentlocker

ransomware group
ACTIVE

TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of r

16 victimsSince Nov 29, 2025

unsafe

ransomware group
ACTIVE

A group which seems to recycle leak from other ransomware groups

16 victimsSince Dec 21, 2022

VanHelsing

ransomware groupRaaS
INACTIVE

VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and s

16 victimsSince Mar 17, 2025

sabbath

ransomware group

Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebran

15 victimsSince Nov 22, 2021

siegedsec

ransomware group
INACTIVE

Not a ransomware group but a hacktivist group that appeared coincidentally days before Russia’s invasion of Ukraine

15 victimsSince Dec 8, 2023

weyhro

ransomware group
INACTIVE

Appears to be a Data Extortion group with no encryption.

15 victimsSince Mar 6, 2025

atomsilo

ransomware groupRaaS

AtomSilo emerged in September 2021 and ceased operations by year-end 2021. It functioned with a double‑extortion model, ...

14 victimsSince Dec 21, 2021

booba team

ransomware group
ACTIVE
14 victimsSince Jul 23, 2026

cheers

ransomware group
INACTIVE

Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi ...

14 victimsSince May 29, 2022

LeakBazaar

ransomware group
INACTIVE
14 victimsSince May 10, 2026

mogilevich

ransomware group
INACTIVE

Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, bu

14 victimsSince Feb 20, 2024

payloadbin

ransomware group
INACTIVE

PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix line

14 victimsSince Sep 9, 2021

teamxxx

ransomware group
INACTIVE

TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, ag

14 victimsSince Jun 10, 2025

benzona

ransomware group
INACTIVE

Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organization

13 victimsSince Nov 26, 2025

cryptbb

ransomware group
INACTIVE

CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to

13 victimsSince Sep 15, 2023

flocker

ransomware group
INACTIVE

Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows

13 victimsSince May 3, 2024

hellcat

ransomware group🇯🇴RaaS
INACTIVE

HellCat is a ransomware-as-a-service operation that emerged in late 2024, with KELA researchers identifying core operato...

13 victimsSince Oct 25, 2024

mountlocker

ransomware group
INACTIVE

MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and

13 victimsSince Feb 7, 2021

underground

ransomware group🇷🇺

Underground ransomware (also known as Underground Team) is a Russia-linked group associated with the RomCom RAT threat c...

13 victimsSince May 1, 2024

cipherforce

ransomware group
INACTIVE

For those out of the loop, you may already know us as TeamPCP or Shellforce, we have been active a while publishing data...

12 victimsSince Feb 23, 2026

datacarry

ransomware group
INACTIVE

DataCarry is a newly observed ransomware and data-extortion operation, first seen in May 2025. It operates a double-exto...

12 victimsSince May 26, 2025

freecivilian

ransomware group
INACTIVE

FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukr

12 victimsSince Dec 31, 2022

groove

ransomware group
INACTIVE

Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its agg...

12 victimsSince Sep 9, 2021

icarus

ransomware group
12 victimsSince May 5, 2026

samsam

ransomware group
12 victims

azroteam

ransomware group
INACTIVE
11 victims

darkrace

ransomware group
INACTIVE

DarkRace is a moderately destructive ransomware strain observed since 2024. It encrypts files and appends a randomized e...

11 victimsSince May 31, 2023

RunSomeWares

ransomware group
INACTIVE

RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain ser

11 victimsSince Feb 27, 2025

secp0

ransomware group

Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only

11 victimsSince Mar 14, 2025

skira

ransomware group
INACTIVE

Skira is a small ransomware group that emerged around late 2024, claiming responsibility for the breach of Carruth Compl

11 victimsSince Mar 6, 2025

apos

ransomware groupRaaS
INACTIVE

Apos ransomware surfaced in April 2024 and is best characterized as a data‑broker or leak‑only operation, rather than a ...

10 victimsSince Apr 29, 2024

arkana

ransomware group
INACTIVE

Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband pro

10 victimsSince Mar 25, 2025

blackout

ransomware group🇷🇺
ACTIVE

Blackout surfaced in February 2024, using a variant based on DarkSide and BlackMatter ransomware source code, establishi...

10 victimsSince Feb 26, 2024

nefilim

ransomware group
INACTIVE

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is remov...

10 victimsSince May 5, 2020

redransomware

ransomware group
INACTIVE

Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across

10 victimsSince Mar 28, 2024

sparta

ransomware group
INACTIVE

Sparta is a short-lived ransomware group first observed in September 2022 that conducted double-extortion attacks primar

10 victimsSince Sep 13, 2022

darkside

ransomware group
INACTIVE

FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable dis...

9 victimsSince Aug 1, 2020

linkc

ransomware group
INACTIVE

Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based

9 victimsSince Feb 19, 2025

malekteam

ransomware group
INACTIVE

Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel),

9 victimsSince Dec 24, 2023

mosesstaff

ransomware group
INACTIVE

Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation a

9 victimsSince Dec 18, 2021

ms13089

ransomware group
ACTIVE

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Secu

9 victimsSince Dec 18, 2025

storm

ransomware group
ACTIVE
9 victimsSince Aug 7, 2026

Black X

ransomware group
ACTIVE
8 victimsSince Jun 2, 2026

crazyhunter

ransomware group
INACTIVE

CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, ex

8 victimsSince Mar 9, 2025

doommageddon

ransomware group
ACTIVE

Direct Extortion Double Extortion

8 victimsSince Jul 6, 2026

qiulong

ransomware group
INACTIVE

Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double ex

8 victimsSince Apr 22, 2024

radiant

ransomware group
INACTIVE

Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extort

8 victimsSince Oct 12, 2025

secpo

ransomware group
8 victims

0day Syndicate

ransomware group
INACTIVE
7 victimsSince May 28, 2026

bitpaymer

ransomware group
7 victims

blackwater

ransomware group
ACTIVE

Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and target

7 victimsSince Apr 12, 2026

cryp70n1c0d3

ransomware group
INACTIVE

Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology,

7 victimsSince Dec 18, 2021

dataleak

ransomware group
INACTIVE

Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited

7 victimsSince Dec 2, 2022

donex

ransomware groupRaaS
INACTIVE

Donex is a ransomware family that emerged in early 2022 as a rebrand of the older Muse ransomware. It uses a double-exto...

7 victimsSince Mar 8, 2024

icefire

ransomware group
INACTIVE

IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability

7 victimsSince Aug 20, 2022

l group

ransomware group
ACTIVE
7 victimsSince Aug 7, 2026

mindware

ransomware group
INACTIVE

Ransomware, potential rebranding of win.sfile.

7 victimsSince May 5, 2022

netrunner

ransomware group

NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunicat

7 victimsSince Apr 3, 2026

onyx

ransomware group
INACTIVE

Onyx is a ransomware group first observed in April 2022, based on the Chaos ransomware builder, that is notably destruct

7 victimsSince Apr 29, 2022

osiris

ransomware group
INACTIVE

Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driv

7 victimsSince Dec 18, 2025

panzer

ransomware group
ACTIVE
7 victimsSince Aug 5, 2026

3am

ransomware group

3AM, also known as ThreeAM, is a relatively new ransomware family that emerged in late 2023, initially deployed as a fal...

6 victimsSince Jan 9, 2025

AuditTeam

ransomware group

AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and

6 victimsSince Apr 8, 2026

babuk

ransomware groupNot trustworthy
INACTIVE

Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most us

6 victimsSince Oct 25, 2020

chort

ransomware group
INACTIVE

Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning ...

6 victimsSince Nov 17, 2024

cryptnet

ransomware group
INACTIVE

CryptNet is a newer Ransomware-as-a-Service (RaaS) operation first identified in April 2023. It follows a double-extorti...

6 victimsSince Apr 19, 2023

cryptolocker

ransomware group
6 victims

ethics

ransomware group
ACTIVE
6 victims

kraken

ransomware groupRaaS
ACTIVE

Kraken leak blog (hellokitty) <br/>Kraken is a ransomware family first observed in August 2018 as a Ransomware-as-a-Serv...

6 victimsSince Feb 9, 2025

mnt6

ransomware group
INACTIVE

MNT6 is a lower-profile ransomware group claiming victims across legal, manufacturing, construction, healthcare, and log

6 victimsSince Apr 30, 2026

pay2key

ransomware group
INACTIVE

Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, tar

6 victimsSince Dec 13, 2020

projectrelic

ransomware group
INACTIVE

Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-b

6 victimsSince Nov 11, 2022

rebornvc

ransomware group
ACTIVE

RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion

6 victimsSince Jul 8, 2025

rook

ransomware group
INACTIVE

Ransomware.

6 victimsSince Dec 7, 2021

silent

ransomware groupRaaS
INACTIVE

Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own...

6 victimsSince Apr 23, 2025

TiMc

ransomware group

TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader S

6 victimsSince Apr 9, 2026

argonauts

ransomware group
INACTIVE

Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics,

5 victimsSince Nov 27, 2024

bert

ransomware group
INACTIVE

BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux sy...

5 victimsSince Apr 6, 2025

darkpower

ransomware group
INACTIVE

Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations ac...

5 victimsSince Mar 11, 2023

helix

ransomware group
ACTIVE
5 victimsSince Aug 7, 2026

raznatovic

ransomware group
INACTIVE

RANSOMED.VC aka Raznatovic

5 victimsSince Dec 17, 2023

ValenciaLeaks

ransomware group
INACTIVE

Official twitter account: https://x.com/ValenciaLeaks72

5 victimsSince Sep 10, 2024

wallstreet

ransomware group
5 victimsSince Jun 26, 2026

xp95

ransomware group
INACTIVE

XP95 is a cyber-extortion group that emerged in March 2026, using a pure data-theft-and-extortion model with a Windows X

5 victimsSince Mar 17, 2026

yanluowang

ransomware group
INACTIVE

Ransomware.

5 victimsSince Jul 2, 2022

0mega

ransomware group
INACTIVE

0mega is a ransomware group first observed in May 2022, operating with a double extortion model: <br/>* Encrypting victi...

4 victimsSince Jul 14, 2022

barracuda

ransomware group
ACTIVE
4 victimsSince Aug 6, 2026

Booba Project

ransomware group
ACTIVE

Booba

4 victimsSince Jul 6, 2026

bqtlock

ransomware groupRaaS
INACTIVE

aka BaqiyatLock <br/>BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a...

4 victimsSince Jul 31, 2025

cryptowall

ransomware group
4 victims

d1r

ransomware group
ACTIVE

D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion

4 victimsSince Jul 13, 2026

exitium

ransomware group

Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targetin

4 victimsSince Mar 17, 2026

gammax

ransomware group
ACTIVE
4 victimsSince Jul 30, 2026

karma

ransomware group
INACTIVE

Karma is a ransomware group first observed in November 2021, operating a double-extortion model that combines data theft...

4 victimsSince Oct 4, 2021

kawa4096

ransomware group
INACTIVE

Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education

4 victimsSince Jun 27, 2025

lunalock

ransomware group
INACTIVE

LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplac

4 victimsSince Sep 2, 2025

minteye

ransomware group
INACTIVE

MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction

4 victimsSince Dec 12, 2025

orca

ransomware group
INACTIVE

Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targe

4 victimsSince Sep 16, 2024

redalert

ransomware group
INACTIVE

RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware

4 victimsSince Jul 14, 2022

scarab

ransomware group
4 victims

snake

ransomware group
INACTIVE
4 victims

thegreenbloodgroup

ransomware group
4 victimsSince Feb 4, 2026

blackbyte-crux

ransomware group
INACTIVE

Crux is a newly identified ransomware variant active since July 2025, which claims affiliation with the established Blac...

3 victimsSince Nov 17, 2025

blackshadow

ransomware group
INACTIVE

BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2...

3 victimsSince Dec 18, 2021

desolator

ransomware group
INACTIVE

Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America

3 victimsSince Aug 30, 2025

dharma

ransomware groupRaaSRecovery risk
INACTIVE

Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It opera...

3 victims

GDLockerSec

ransomware group
INACTIVE

Our team members are from different countries and we are not interested in anything else, we are only interested in doll...

3 victimsSince Jan 24, 2025

hellogookie

ransomware group
INACTIVE

HelloGookie is a rebrand of the HelloKitty ransomware group announced in April 2024, releasing previously stolen data fr

3 victimsSince Apr 19, 2024

insane

ransomware group
INACTIVE

Insane is a short-lived ransomware group that briefly surfaced in early 2024, claiming a single victim in Thailand befor

3 victimsSince Jan 17, 2024

kittykatkrew

ransomware group
INACTIVE

KittyKatKrew is a newly emerged ransomware group first identified in early 2026, using both direct and double-extortion

3 victimsSince Feb 19, 2026

lockdata

ransomware group
INACTIVE

LockData Auction is a dark web marketplace that emerged around May 2021 operating an invite-only stolen data auction por

3 victimsSince Sep 9, 2021

pandora

ransomware group
INACTIVE

Pandora ransomware was obtained by vx-underground at 2022-03-14.

3 victimsSince Mar 17, 2022

PrinzEugen

ransomware group
3 victimsSince May 4, 2026

ragnarok

ransomware group
INACTIVE

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes...

3 victimsSince Mar 31, 2021

robinhood

ransomware group
INACTIVE

RobbinHood is a ransomware group first observed in April–May 2019, responsible for high-profile attacks on US cities inc

3 victimsSince Dec 6, 2021

slug

ransomware group
INACTIVE

Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing

3 victimsSince Jan 18, 2024

0day

ransomware group
ACTIVE
2 victimsSince Jul 23, 2026

agelocker

ransomware group
INACTIVE
2 victims

astroteam

ransomware group
INACTIVE
2 victims

bitlocker

ransomware group
INACTIVE
2 victims

blacktor

ransomware group
INACTIVE

Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victim

2 victimsSince Dec 30, 2021

bonacigroup

ransomware group
INACTIVE

Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going off

2 victimsSince Oct 4, 2021

cry0

ransomware group
ACTIVE

Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payloa

2 victimsSince Jan 19, 2026

dark project

ransomware group
ACTIVE

Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortio

2 victimsSince Aug 5, 2026

datakeeper

ransomware group

DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "

2 victimsSince Jan 14, 2026

egregor

ransomware group

Egregor is a ransomware strain that appeared in September 2020, widely believed to be a rebrand or successor to the Maze...

2 victims

gandcrab

ransomware groupRaaSReported reliable
INACTIVE

GandCrab was a prolific Ransomware-as-a-Service (RaaS) operation active from January 2018 to mid-2019. It quickly became...

2 victimsSince Dec 9, 2024

hermes

ransomware groupRaaS

Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group op...

2 victims

kazu

ransomware group

Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting govern

2 victimsSince Nov 11, 2025

locky

ransomware group
INACTIVE
2 victimsSince Dec 10, 2024

memedusalockerdusa

ransomware group
INACTIVE
2 victims

nasirsecurity

ransomware group

Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organiz

2 victimsSince Oct 11, 2025

netflim

ransomware group
INACTIVE
2 victims

nightsky

ransomware group
INACTIVE

Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, g

2 victimsSince Jan 4, 2022

noname

ransomware group
INACTIVE

NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized bu

2 victimsSince Jan 16, 2024

rancoz

ransomware group
INACTIVE

Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension t

2 victimsSince May 5, 2023

robbinhood

ransomware group
2 victims

ronggolawe

ransomware group
INACTIVE
2 victims

satanlock

ransomware group

Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages).

2 victimsSince Apr 8, 2025

satanlockv2

ransomware group

SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after

2 victimsSince Jul 4, 2025

sekhmet

ransomware group
INACTIVE
2 victims

sensayq

ransomware group
INACTIVE

SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortio

2 victims

sovcali

ransomware group
ACTIVE
2 victimsSince Aug 9, 2026

teslacrypt

ransomware group
2 victims

triple x

ransomware group
ACTIVE
2 victimsSince Jun 13, 2026

walocker

ransomware group
INACTIVE

WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and g

2 victimsSince Jun 10, 2025

blogxx

ransomware group
INACTIVE
1 victims

bluebox

ransomware group
INACTIVE

Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims prim

1 victimsSince Dec 11, 2024

cerber

ransomware group
1 victims

ContFR

ransomware groupRaaS
INACTIVE

RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon...

1 victimsSince Feb 13, 2026

crosslock

ransomware group
INACTIVE

CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion ...

1 victimsSince Apr 17, 2023

cryptomix

ransomware group
1 victims

cryptoware

ransomware group
1 victims

deathkitty

ransomware group
INACTIVE
1 victims

erebus

ransomware group
1 victims

global3

ransomware group
1 victims

goznym

ransomware group
1 victims

hades

ransomware group
INACTIVE

Hades is a ransomware group first observed in December 2020, believed by several threat intelligence firms to be operate...

1 victimsSince Dec 15, 2020

hddcryptor

ransomware group
1 victims

keyholder

ransomware group
1 victims

kryptos

ransomware groupRaaS
INACTIVE

Kryptos is a small ransomware group first observed in October 2025, conducting simultaneous attacks across North America

1 victimsSince Oct 8, 2025

lechiffre

ransomware group
1 victims

macaw

ransomware group
INACTIVE
1 victims

majinahanashi

ransomware group
ACTIVE
1 victims

megacode

ransomware group
1 victims

nullbulge

ransomware group

A hacktivist group protecting artists' rights and ensuring fair compensation for their work.

1 victims

pewcrypt

ransomware group
1 victims

playboy

ransomware group
INACTIVE

PlayBoy Locker is a ransomware-as-a-service operation that emerged in September 2024, targeting Windows, NAS, and ESXi s

1 victimsSince Oct 28, 2024

prolock

ransomware group
INACTIVE

PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and loc...

1 victimsSince Feb 23, 2020

ransomcortex

ransomware group
INACTIVE

RansomCortex emerged in July 2024 with a narrow focus on healthcare facilities, claiming four victims within days of its

1 victimsSince Jul 12, 2024

ranstreet

ransomware group
INACTIVE

Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lis

1 victimsSince Dec 21, 2023

roadsweep

ransomware group
INACTIVE
1 victims

samas

ransomware group
1 victims

shaoleaks

ransomware group
INACTIVE

SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but la

1 victimsSince Nov 1, 2022

sicarii

ransomware groupNot trustworthy
INACTIVE

Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targetin

1 victimsSince Dec 30, 2025

synack

ransomware group
INACTIVE

SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Do

1 victimsSince Mar 21, 2021

triplem

ransomware group
1 victims

trisec

ransomware group
INACTIVE

Trisec is a Tunisian-origin ransomware group that emerged in February 2024, claiming affiliation with the Tunisian gover

1 victimsSince Feb 16, 2024

vendetta

ransomware group
INACTIVE

Ransomware, which appears to be a rebranding of win.cuba.

1 victimsSince Feb 12, 2023

wastedlocker

ransomware group
INACTIVE
1 victims

yurei

ransomware group
INACTIVE

Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-sour

1 victimsSince Sep 5, 2025

0apt

ransomware groupRaaS

The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele...

0 victimsSince Jan 28, 2026

0xFFF

ransomware group
INACTIVE
0 victims

2023lock

ransomware group

2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus fa...

0 victims

a1project

ransomware groupRaaS

The locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for E...

0 victims

Abrahams_Ax

ransomware group
INACTIVE

Abrahams_Ax, first observed in November 2022, is not a Ransomware-as-a-Service (RaaS) operation but a politically motiva...

0 victimsSince Dec 31, 2024

adminlocker

ransomware group
INACTIVE

AdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear Rans...

0 victims

againstthewest

ransomware group
INACTIVE

AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived

0 victims

aGl0bGVyCg

ransomware group
INACTIVE

This ransomware group (notably stylized as aGl0bGVyCg) has extremely limited publicly available information. No confirme...

0 victims

ako

ransomware groupRaaS
INACTIVE

First observed in early January 2020 (initial victim post on January 9, 2020), Ako (also known as MedusaReborn) operates...

0 victims

amnesia

ransomware group

Amnesia ransomware was first identified in May 2017, particularly affecting enterprise cloud environments. It does not a...

0 victims

ank

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

antefrigus

ransomware group
INACTIVE
0 victimsSince Apr 23, 2026

antibrok3rs

ransomware group

Antibrok3rs emerged as an access broker (not a ransomware operator itself) linked to the aftermath of the 2023 MOVEit su...

0 victimsSince Dec 25, 2025

aptlock

ransomware group
INACTIVE

Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage. T...

0 victimsSince Jan 1, 2025

arachna leak

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

arcane

ransomware group

Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations aga...

0 victims

arcrypter

ransomware group

ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government en...

0 victims

argonauts group

ransomware group
INACTIVE

Argonauts Group is a data extortion operation that surfaced around September–October 2024, primarily targeting organizat...

0 victimsSince Mar 27, 2025

arkana security

ransomware group
INACTIVE

Arkana Security emerged in early 2025, debuting with a high-profile data-extortion campaign against the U.S. internet pr...

0 victimsSince Jul 6, 2025

astralocker

ransomware group

AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-e...

0 victims

avos

ransomware group
INACTIVE

First observed in July 2021, AvosLocker operates as a Ransomware-as-a-Service (RaaS) platform employing a double-extorti...

0 victims

aware

ransomware group
INACTIVE

Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documenta

0 victimsSince Jan 6, 2026

axxes

ransomware group
INACTIVE

Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing ...

0 victimsSince Jul 8, 2025

aztroteam

ransomware group
INACTIVE

AztroTeam is a ransomware group with very limited public documentation and no confirmed victims, listed as offline on ra

0 victims

azzasec

ransomware groupRaaS
INACTIVE

We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botne...

0 victimsSince Apr 28, 2025

b0 group

ransomware group
INACTIVE

B0 is a relatively obscure ransomware operation with very limited public reporting outside of leak site monitoring. It a...

0 victimsSince May 8, 2025

babuk-bjorka

ransomware groupNot trustworthy
INACTIVE

On January 26th, Babuk's dedicated leak site (DLS) was "relaunched". Bjorka (Telegram: @bjorkanesiaaaa) is the current a...

0 victimsSince Jan 27, 2025

babuk-locker

ransomware groupRaaSNot trustworthy
INACTIVE

Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises ...

0 victimsSince Feb 26, 2024

babyduck

ransomware group
INACTIVE

BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduc

0 victims

babylockerkz

ransomware group

BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023. It operates under a double‑extortion ...

0 victims

backmydata

ransomware group

BackMyData is a variant of the Phobos ransomware family, first observed in early 2024. It follows a double‑extortion mod...

0 victims

balletspistol

ransomware group

BalletsPistol is a Python-based ransomware strain distributed via GitHub. An investigative report from June 2025 reveals...

0 victims

belsen group

ransomware group
INACTIVE

aka Belesn Group. <br/>Belsen Group emerged in January 2025 as a data broker and leak-focused threat actor, not engaging...

0 victimsSince Mar 12, 2025

bidon

ransomware group

BIDON is a variant of the Monti ransomware family, first observed around mid‑2023. It employs a double‑extortion strateg...

0 victims

bitransomware

ransomware group
INACTIVE

BitRansomware (also known as DCryptSoft or ReadMe) surfaced in November 2020, primarily as a widespread cryptolocker tar...

0 victimsSince Dec 9, 2024

bjorka

ransomware group

Hellcome Bjorkanism <br/>Bjorka emerged as a prominent data-extortion actor and hacktivist initially active in 2022, ta...

0 victimsSince Feb 1, 2025

black witch

ransomware group
0 victims

blackberserk

ransomware group

Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023. It operates under a single‑extort...

0 victims

blackbit

ransomware group
INACTIVE

BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and func...

0 victimsSince Aug 9, 2025

blackfield

ransomware group
INACTIVE
0 victimsSince Feb 17, 2026

blackfile

ransomware group
INACTIVE
0 victimsSince May 17, 2026

blackhunt

ransomware group
INACTIVE

Black Hunt ransomware has been active since at least mid-2021 and operates under a double-extortion model, encrypting vi...

0 victimsSince Jul 9, 2025

blacksnake

ransomware groupRaaS

BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began re...

0 victims

bluelocker

ransomware group
INACTIVE

Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum

0 victimsSince Aug 19, 2025

bluesky

ransomware group
INACTIVE

BlueSky ransomware first emerged in July 2022 and is characterized by aggressive, high-speed file encryption using a mul...

0 victims

bluewhale

ransomware group
ACTIVE
0 victims

bober

ransomware group
INACTIVE
0 victimsSince Aug 6, 2025

br0k3r

ransomware group
INACTIVE

Br0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group lever...

0 victimsSince Jan 16, 2025

buddyransome

ransomware group
0 victims

bytesfromheaven

ransomware group
INACTIVE
0 victimsSince Aug 12, 2025

C3RB3R

ransomware group
INACTIVE

Cerber ransomware, active since 2016, has resurfaced occasionally using the name C3RB3R. It operates as a semi-private R...

0 victims

catb

ransomware group

CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distribut...

0 victims

cerberimposter

ransomware group

Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting o...

0 victims

cerbersyslock

ransomware group

CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceiv...

0 victims

chilelocker

ransomware group
INACTIVE

ChileLocker first emerged in August 2022 and is considered part of the broader ARCrypter ransomware family. It employs a...

0 victims

cipherwolf

ransomware groupRaaS
ACTIVE
0 victimsSince Apr 13, 2026

clearwater

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

cloak.su (locker leak)

ransomware group
INACTIVE
0 victimsSince Mar 24, 2026

clop torrents

ransomware group
INACTIVE
0 victimsSince Jul 15, 2024

colossus

ransomware group

Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S...

0 victims

cooming

ransomware group
INACTIVE

previous clearnet domain coomingproject.com

0 victims

core

ransomware group

Core ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion m...

0 victims

crazyhunter team

ransomware group
INACTIVE

CrazyHunter is a rising ransomware threat first detected in early 2025, with particularly dangerous campaigns targeting ...

0 victimsSince Apr 3, 2025

cring

ransomware group
INACTIVE
0 victims

cryakl

ransomware group

also known as “Fantomas”. <br/>Cryakl first appeared in 2014, spreading primarily across Eastern Europe and Russia via p...

0 victims

crylock

ransomware groupRaaS
INACTIVE

CryLock is a ransomware variant that emerged around April 2020, evolving from the Cryakl (Fantomas) ransomware family. I...

0 victims

crynox

ransomware group

Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to...

0 victims

crypt ransomware

ransomware group
INACTIVE

.crYpt <br/>MD5: 54EFAC23D7B524D56BEDBCE887E11849 <br/> <br/>Babuk Variant

0 victimsSince Dec 11, 2024

cryptedpay

ransomware group

CryptedPay is a standalone ransomware strain observed around early 2025, that encrypts files using AES-256 and appends t...

0 victims

cryptxxx

ransomware group
INACTIVE

CryptXXX is a ransomware strain that first appeared in April 2016, developed by the same group behind the Reveton and An...

0 victimsSince Dec 9, 2024

crysis

ransomware groupRecovery risk

Crysis ransomware was first identified in early 2016 and is a long-running family that later evolved into the Dharma ran...

0 victims

cs-137

ransomware group

Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for enc...

0 victims

ctblocker

ransomware group
INACTIVE

aka Critroni <br/>CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve crypt...

0 victimsSince Dec 9, 2024

cyberex

ransomware group
INACTIVE
0 victimsSince May 27, 2025

cylance

ransomware group
0 victims

d0glun

ransomware group
INACTIVE

D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermedia...

0 victimsSince Jan 30, 2025

dagonlocker

ransomware groupRaaS
INACTIVE

Dagon Locker is a double-extortion ransomware family that surfaced around September 2022. It represents an evolution of ...

0 victims

dark shinigami

ransomware group
INACTIVE
0 victimsSince Dec 15, 2025

darkangel

ransomware group
INACTIVE

Dark Angels is a highly targeted ransomware and data-extortion group that emerged in spring 2022. Rather than using an a...

0 victims

darkangels

ransomware group
INACTIVE

Dark Angels is a highly selective ransomware group active since April 2022 that targets a small number of large enterpri

0 victims

darkbit

ransomware group
INACTIVE

DarkBit is an ideologically motivated ransomware group that appeared in February 2023, primarily targeting Israeli entit

0 victimsSince Feb 15, 2023

darkbit01

ransomware group
INACTIVE

DarkBit is a politically motivated ransomware operation active since February 2023, targeting academic and public sector...

0 victims

darkhav0c

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

darkmatter

ransomware group
ACTIVE
0 victimsSince Jul 23, 2026

darkrypt

ransomware group
INACTIVE
0 victimsSince Jan 25, 2025

darkwave

ransomware group
INACTIVE

Written in python

0 victimsSince Feb 19, 2026

darkylock

ransomware group

Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk s...

0 victims

dataf locker

ransomware group
INACTIVE

DataF Locker is a ransomware variant first observed in 2024, closely tied to the Babuk ransomware lineage. It operates u...

0 victimsSince Dec 9, 2024

deadbydawn

ransomware group
0 victims

deathgrip

ransomware groupRaaS

DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked...

0 victims

deathransom

ransomware group

DeathRansom is a ransomware family first seen in the wild in late 2019, initially appearing as a bluff—dropping ransom n...

0 victims

delta

ransomware group
0 victims

desolated

ransomware group
0 victims

devman2

ransomware groupRaaS
INACTIVE

DevMan 2.0 is the evolved iteration of the DevMan ransomware, first documented in July 2025. It enhances the capabilitie...

0 victimsSince Sep 28, 2025

diavol

ransomware group
INACTIVE

Diavol is a ransomware strain first observed in June 2021, associated with the Wizard Spider threat group—best known for...

0 victims

dread

ransomware group
INACTIVE

Dread is a ransomware group that appears in tracking databases but has no publicly documented attacks or confirmed TTPs

0 victims

ech0raix

ransomware group
INACTIVE

The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom not...

0 victims

eclipse

ransomware group
ACTIVE
0 victimsSince Aug 11, 2026

elcometa

ransomware group
0 victims

elonmusknow

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

elpaco

ransomware group

Elpaco is a variant of Mimic ransomware that emerged around August 2023. Designed with significant customization and ste...

0 victims

emperador

ransomware group
ACTIVE
0 victims

enciphered

ransomware group

aka xoriste

0 victims

encrypthub

ransomware group
0 victims

endurance

ransomware group
INACTIVE

Endurance is a destructive ransomware variant first observed in 2023, developed and operated by the threat actor known a...

0 victimsSince Jun 1, 2023

entropy

ransomware group
INACTIVE

Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomw...

0 victims

ep918

ransomware group
INACTIVE

EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly document

0 victims

eruption

ransomware group

Rebranded to Sabbath.

0 victims

esxiargs

ransomware group

ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-202...

0 victimsSince Feb 3, 2023

evolution

ransomware group
INACTIVE
0 victimsSince Jan 25, 2026

exorcist

ransomware group
INACTIVE

Ransomware.

0 victims

fakersa

ransomware group
0 victims

farattack

ransomware group
0 victims

fargo

ransomware group

Fargo is a ransomware variant that surfaced in 2022, primarily targeting Microsoft SQL Server (MSSQL) systems. Believed ...

0 victims

faust

ransomware group

Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since ...

0 victims

fivehands

ransomware groupRaaS

FiveHands is a ransomware family first observed in January 2021, believed to be a successor to the HelloKitty ransomware...

0 victims

fletchen

ransomware group

Fletchen is primarily documented as a sophisticated infostealer-as-a-service written in Rust, targeting browser credenti

0 victimsSince Jan 3, 2026

freeworld

ransomware group

FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomw...

0 victims

frozen

ransomware group
0 victims

fsociety

ransomware groupRaaS
INACTIVE

This group is also known by their malware name, FLOCKER. <br/>FSociety is a modern Ransomware-as-a-Service (RaaS) operat...

0 victimsSince Aug 29, 2025

fsteam

ransomware group
INACTIVE

New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware ...

0 victimsSince Jan 7, 2023

ftcode

ransomware group
INACTIVE

FTCode is a ransomware family first observed in 2013 as a PowerShell-based threat and later resurfaced in September 2019...

0 victimsSince Dec 9, 2024

fusion

ransomware group
0 victims

gangbang

ransomware group
0 victims

gazprom

ransomware group
0 victims

ghost

ransomware group

aka Cring / Ghost (Cring) <br/> <br/>Beginning early 2021, Ghost actors began attacking victims whose internet facing se...

0 victims

globe

ransomware group

Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allow...

0 victims

globeimposter

ransomware group

GlobeImposter is a ransomware family that first appeared in mid-2017, designed to mimic the appearance and naming conven...

0 victims

Goddamn ransomwhere

ransomware group
0 victimsSince Jul 26, 2026

good day

ransomware group
INACTIVE

Good Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to it...

0 victimsSince Jun 24, 2024

grep

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

grief

ransomware groupRaaS
INACTIVE

Grief, also known as Pay or Grief, is a ransomware group that emerged in May 2021 and is widely believed to be operated ...

0 victimsSince May 26, 2021

grinch

ransomware group
0 victims

gwisin

ransomware group
INACTIVE

Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South K...

0 victimsSince Dec 9, 2024

haron

ransomware group
INACTIVE

Haron is a ransomware group that emerged in July 2021 and is believed to share operational similarities with the Avaddon...

0 victims

hellokitty

ransomware group
INACTIVE

HelloKitty is a ransomware family first observed in November 2020, named after a string found in its binary. It operates...

0 victims

help_restoremydata

ransomware group
INACTIVE

Help_restoremydata is a ransomware variant identified around late 2024/early 2025, notable for appending the .help_resto...

0 victimsSince Jan 27, 2025

himalayaa

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

hiveleak

ransomware group
INACTIVE
0 victims

holyghost

ransomware group
INACTIVE

HolyGhost is a ransomware group first publicly reported in July 2022, believed to be operated by a North Korean state-sp...

0 victims

homeland

ransomware group
0 victimsSince Mar 10, 2026

hotarus

ransomware group
INACTIVE

Hotarus is a ransomware and data extortion group first observed in March 2021, believed to be linked to threat actors of...

0 victims

hyflock

ransomware group
INACTIVE
0 victimsSince Apr 7, 2026

inpivx

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

insane ransomware

ransomware group
INACTIVE

Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public thr...

0 victimsSince Feb 12, 2024

invaderx

ransomware group
0 victims

ironchain

ransomware group
INACTIVE
0 victimsSince Feb 22, 2026

izis

ransomware group
INACTIVE
0 victimsSince Sep 13, 2025

j group

ransomware group
INACTIVE
0 victimsSince Dec 15, 2025

jackalock

ransomware group
ACTIVE
0 victimsSince Aug 5, 2026

jaff

ransomware group
INACTIVE

Jaff is a ransomware family first discovered in May 2017, notable for its distribution via large-scale spam campaigns op...

0 victimsSince Dec 10, 2024

jigsaw

ransomware group

Jigsaw is a ransomware family first observed in April 2016, notorious for its psychological intimidation tactics. It enc...

0 victims

jo of satan

ransomware group
INACTIVE
0 victims

jsworm

ransomware group

JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolut...

0 victims

justice_blade

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

kasseika

ransomware group

Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatt...

0 victims

kawa

ransomware group
INACTIVE
0 victimsSince Aug 16, 2025

key group

ransomware group
0 victims

killada

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

kirov

ransomware group
0 victims

krypt

ransomware group
INACTIVE
0 victimsSince Sep 28, 2025

kryptina

ransomware group
0 victims

kuiper

ransomware group

Kuiper is a relatively new ransomware strain first analyzed in April 2023, notable for being written in Rust and designe...

0 victims

kuza

ransomware group
0 victims

kyber

ransomware group

Kyber is a recently identified ransomware group using sophisticated hybrid encryption (AES-256-CTR with X25519 and Kyber

0 victimsSince Oct 8, 2025

la_piovra

ransomware group
INACTIVE

ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)

0 victimsSince Jun 10, 2023

lambda

ransomware group
INACTIVE
0 victims

lamialocker

ransomware group
0 victims

late.lol

ransomware group

Affiliates: <br/>@Mr.C <br/>@Empathy <br/>@jayze <br/>@Widow <br/>@Memory <br/> <br/>

0 victimsSince Apr 13, 2026

lcryptorx

ransomware group
INACTIVE
0 victimsSince May 9, 2025

leak bazaar

ransomware group
0 victims

lilith

ransomware group
INACTIVE

Lilith is a C/C++-based double-extortion ransomware that emerged in July 2022, targeting 64-bit Windows systems and shar

0 victims

lockbit

ransomware groupRaaS
INACTIVE

LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak acc

0 victimsSince Oct 21, 2020

lockbit3_fs

ransomware group

LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating

0 victims

lockbit4

ransomware groupRaaS
INACTIVE
0 victimsSince Jun 3, 2025

lockergoga

ransomware group
0 victims

locus

ransomware group
INACTIVE
0 victimsSince Jan 1, 2026

loki

ransomware group
INACTIVE
0 victimsSince Apr 12, 2026

lokilocker

ransomware group
0 victims

lolnek

ransomware group
INACTIVE

Lolnek (also known as Lolkek/GlobeImposter) is a commodity ransomware strain primarily targeting small and medium-sized

0 victims

lsd

ransomware group
0 victimsSince Apr 13, 2026

luckbit

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

lulzsec muslims

ransomware group
INACTIVE
0 victimsSince Jun 4, 2025

lynxr

ransomware group
0 victims

lyrix

ransomware group
INACTIVE
0 victimsSince Dec 23, 2025

madcat

ransomware group
INACTIVE

MadCat is a suspected fraudulent ransomware operation that surfaced briefly in late 2023, apparently linked to scammers

0 victimsSince Nov 27, 2023

mailto

ransomware group
0 victims

makop

ransomware group
0 victims

malphas

ransomware group
0 victims

mamona

ransomware groupRaaS
INACTIVE

Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed be

0 victimsSince Mar 12, 2025

mario esxi

ransomware group
0 victims

maui

ransomware group
INACTIVE
0 victims

mbc

ransomware group
INACTIVE

MBC is a very obscure ransomware group with minimal public documentation and no significant threat intelligence reports

0 victims

mcafee

ransomware group
0 victims

mcrypt2019

ransomware group
0 victims

megacortex

ransomware group
0 victims

megazord

ransomware group
0 victims

mespinoza

ransomware groupRecovery risk
0 victims

miga

ransomware group
INACTIVE

#MakeIsraelGreatAgain

0 victimsSince Sep 29, 2025

miliphen

ransomware group
0 victims

mimic

ransomware group
0 victims

mimic-guram

ransomware groupRaaS

Mimic v.10 Ransomware-as-a-Service (RaaS). The malware is designed to target various operating systems (Windows, ESXi, N...

0 victims

moisha

ransomware group
INACTIVE
0 victims

monolock

ransomware group
INACTIVE
0 victimsSince Jan 23, 2026

montage

ransomware group
ACTIVE
0 victimsSince Aug 13, 2026

monte

ransomware group
INACTIVE
0 victimsSince Sep 28, 2022

mortalkombat

ransomware group
0 victims

MORTAR

ransomware group
INACTIVE

Encrypting ransomware with a Tor negotiation portal; no verified public victim disclosure yet.

0 victimsSince May 31, 2026

muliaka

ransomware group
0 victims

mydata

ransomware group
INACTIVE
0 victimsSince Dec 9, 2024

mydecryptor

ransomware group
INACTIVE

MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platfo

0 victims

n3tworm

ransomware group
INACTIVE

N3tw0rm ransomware group is linked to Iran by many security researchers especially for the fact that the group targeting

0 victims

naga

ransomware group
INACTIVE
0 victimsSince Jun 2, 2025

nblock

ransomware group
INACTIVE
0 victimsSince Apr 10, 2026

nemesis

ransomware group
INACTIVE
0 victimsSince Aug 13, 2025

nemty

ransomware group
INACTIVE

Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed throug...

0 victims

networm

ransomware group
INACTIVE
0 victims

nevada

ransomware group
INACTIVE

Nevada Ransomware is a RaaS operation written in Rust that emerged on the RAMP dark web forum in late 2022, offering aff

0 victims

Notpetya

ransomware group
0 victimsSince Jan 1, 2017

nozelesn

ransomware group
0 victims

nvrmre

ransomware group
INACTIVE

AKA Lemon

0 victimsSince Mar 6, 2025

obsidian orb

ransomware group
0 victims

oceans

ransomware group
0 victims

octovillan

ransomware group
INACTIVE
0 victimsSince Sep 18, 2025

offwhite

ransomware group
0 victims

onepercent

ransomware group
INACTIVE

OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using p

0 victims

osyolorz collective

ransomware group
0 victimsSince Apr 13, 2026

ox thief

ransomware group
INACTIVE
0 victimsSince Mar 13, 2025

paradise

ransomware group
0 victims

paradise2

ransomware group
0 victims

Payday

ransomware group
0 victims

petya

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

phalcon

ransomware group
0 victims

phantom

ransomware group
0 victims

phobos

ransomware groupRecovery risk
0 victims

phoenixcryptolocker

ransomware group
INACTIVE
0 victims

pink

ransomware group
ACTIVE
0 victims

piratelock

ransomware groupRaaS
0 victims

polyvice

ransomware group
0 victims

prinz eugen

ransomware group
ACTIVE
0 victims

prometheus

ransomware group
INACTIVE

Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.

0 victims

promptlock

ransomware group
INACTIVE

First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama ...

0 victimsSince Aug 26, 2025

proton

ransomware group
0 victims

providence

ransomware group
0 victims

proxima

ransomware group
0 victims

pryx

ransomware group
0 victims

punisher

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

pyrx

ransomware group
INACTIVE
0 victimsSince Apr 17, 2025

qilin-securotrop

ransomware group
0 victimsSince Apr 13, 2026

qlocker

ransomware group
INACTIVE

login page, no posts

0 victims

quicklock

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

quoter

ransomware group
0 victims

ra group

ransomware group
INACTIVE
0 victimsSince Aug 25, 2023

rabbithole

ransomware group
INACTIVE

RabbitHole is a low-profile ransomware group with limited publicly available threat intelligence, not appearing prominen

0 victimsSince Dec 31, 2024

radiant group

ransomware group
INACTIVE
0 victimsSince Nov 12, 2025

RAMP

ransomware group
INACTIVE

RAMP (Russian Anonymous Marketplace) was a Russian-speaking dark web forum founded in 2021 that served as a central mark

0 victims

ranion

ransomware groupRaaS
INACTIVE

Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model

0 victims

ransom corp

ransomware group
INACTIVE
0 victims

ransombay

ransomware group
INACTIVE

Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative

0 victimsSince May 13, 2025

ransomcartel

ransomware group
INACTIVE

Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to sh

0 victims

ransomedvc2

ransomware groupRaaS
ACTIVE

RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.

0 victimsSince Mar 27, 2026

ransomware blog

ransomware group
INACTIVE

Also known as MedusaLocker

0 victimsSince Nov 18, 2025

ranzy

ransomware group
INACTIVE

Ranzy Locker, Former known as ThunderX. The group hosting a data leak site in the darknet where they posting sensitive i

0 victims

raptum

ransomware group
ACTIVE
0 victimsSince Aug 5, 2026

rapture

ransomware group
0 victims

redact

ransomware group
0 victimsSince Jun 28, 2026

relic

ransomware group
INACTIVE
0 victimsSince Jun 3, 2023

reynolds

ransomware group
INACTIVE

Reynolds is a ransomware family first identified in early 2026, notable for embedding BYOVD (Bring Your Own Vulnerable D

0 victimsSince Feb 11, 2026

risen

ransomware group
INACTIVE

Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malwa...

0 victimsSince Jun 5, 2024

robbing hood

ransomware group
INACTIVE
0 victimsSince Jun 15, 2025

root

ransomware group
0 victims

rransom

ransomware group
INACTIVE

RRansom is a low-profile ransomware group whose dark web leak site has been listed as offline in tracking directories, w

0 victims

rtm locker

ransomware group
INACTIVE
0 victimsSince Nov 5, 2025

rustylocker

ransomware groupRaaS
INACTIVE
0 victimsSince Dec 10, 2025

satancd

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

scattered lapsus$ hunters

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

schoolboys

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

section9

ransomware group
INACTIVE

🚨 This is a fake group with fake victims.

0 victimsSince Jul 26, 2026

SevyWare

ransomware group
INACTIVE

Direct Extortion Double Extortion

0 victims

shade

ransomware group
INACTIVE
0 victimsSince Dec 12, 2024

shadow

ransomware group
INACTIVE

Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; s

0 victims

sharpboys

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

shiba

ransomware group
ACTIVE
0 victimsSince Jul 27, 2026

ShinySp1d3r

ransomware group
INACTIVE

Likely associated with the cybercrime group BlingLibra (ShinyHunters)

0 victimsSince Nov 15, 2025

sicari

ransomware group
INACTIVE
0 victimsSince Jan 19, 2026

sifrecikis

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

silent ransom

ransomware group
0 victims

skira team

ransomware group
INACTIVE
0 victimsSince Nov 29, 2025

slam

ransomware group
INACTIVE
0 victimsSince Jun 4, 2025

soleenya

ransomware group
INACTIVE
0 victimsSince Jun 15, 2025

solidbit

ransomware group
INACTIVE

Ransomware, written in .NET.

0 victims

spectre

ransomware group
0 victims

sphinx

ransomware group
INACTIVE
0 victimsSince Sep 2, 2025

spirigatito

ransomware group
0 victims

spring

ransomware group
0 victims

spy corporate

ransomware group
ACTIVE
0 victims

sugar

ransomware group
INACTIVE

Ransomware, written in Delphi.

0 victims

sundawn

ransomware group
0 victims

superblack

ransomware group
0 victims

synapse

ransomware group
INACTIVE
0 victimsSince Jun 17, 2024

syndicate

ransomware group
0 victims

targetcompany

ransomware group
0 victims

taronis

ransomware group
0 victims

team underground

ransomware group
0 victimsSince Sep 30, 2023

telegram

ransomware group
0 victims

thanos

ransomware group
INACTIVE
0 victims

The syndicate

ransomware group

Data Broker

0 victims

thor

ransomware group
INACTIVE
0 victimsSince Jun 6, 2025

threatmarket

ransomware group
0 victimsSince Apr 13, 2026

thunder x

ransomware group
0 victims

thundercrypt

ransomware group
0 victims

tommyleaks

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

tooda

ransomware group
INACTIVE

Members: <br/>Eco <br/>Ego <br/>emo <br/>elo <br/>user <br/>Dante <br/>Sevy

0 victimsSince Apr 13, 2026

toxic

ransomware group
INACTIVE
0 victimsSince Feb 22, 2025

tssxx25

ransomware group
INACTIVE
0 victimsSince Aug 28, 2025

tuborg

ransomware group
0 victims

turkish crypter

ransomware group
INACTIVE
0 victimsSince Apr 7, 2026

tycoon

ransomware group
0 victims

u-bomb

ransomware group
INACTIVE

U-Bomb is a low-profile ransomware operation discovered in March 2023 that arrives via phishing emails and uses third-pa

0 victimsSince Dec 31, 2024

ulose

ransomware group
INACTIVE
0 victimsSince Jun 9, 2026

umbra

ransomware group
ACTIVE
0 victims

unknown

ransomware group
INACTIVE

"Unknown" is a catch-all tracking label used on ransomware monitoring platforms for attacks where the responsible threat

0 victims

unsafeleak

ransomware group
INACTIVE
0 victims

v is vendetta

ransomware group
0 victimsSince Feb 8, 2024

vandev

ransomware group
0 victims

vanirgroup

ransomware group

VanirGroup is an Eastern European ransomware group composed of former affiliates from Karakurt, LockBit, and Knight rans

0 victimsSince Jul 10, 2024

vasalocker

ransomware group
0 victims

vaultcrypt

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

vegalocker

ransomware group
0 victims

vfokx

ransomware group
INACTIVE

VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentatio

0 victims

vsop

ransomware group
INACTIVE

aka Onix/Onyx

0 victimsSince Jan 2, 2023

vulcan

ransomware groupRaaS
INACTIVE
0 victimsSince Apr 13, 2026

vurten

ransomware group
0 victims

w3crypto

ransomware group
INACTIVE
0 victimsSince Jun 16, 2025

waissbein

ransomware group
0 victimsSince Apr 9, 2026

weaxor

ransomware group
INACTIVE
0 victimsSince Dec 18, 2024

white lock

ransomware group
INACTIVE
0 victimsSince Nov 4, 2025

wiki ransomware

ransomware group
0 victims

wikileaksv2

ransomware group
INACTIVE

Group is connected to Qilin.

0 victimsSince Jul 9, 2024

wiper leak

ransomware group
0 victimsSince Apr 13, 2026

x001xs

ransomware group
INACTIVE

X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing st

0 victims

xelera

ransomware group
0 victims

xinof

ransomware group
INACTIVE

XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and

0 victims

xleaks

ransomware group
INACTIVE
0 victimsSince Oct 12, 2025

xollam

ransomware group
0 victims

xpl0itrs

ransomware group
ACTIVE
0 victimsSince Aug 16, 2026

yashma

ransomware group
0 victims

ymir

ransomware group
0 victims

zeon

ransomware group
INACTIVE

Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of forme

0 victims

zeoticus

ransomware group
0 victims

zeoticus2

ransomware group
0 victims

zeppelin

ransomware groupRaaS
INACTIVE

Zeppelin ransomware is a derivative of the Delphi-based Vega malware family and functions as a Ransomware as a Service (...

0 victims

zero tolerance gang (ztg)

ransomware group
INACTIVE
0 victimsSince May 20, 2024

zerolockersec

ransomware group
INACTIVE

ZeroLockerSec is a small ransomware group with very limited public documentation that became inactive by Q2 2025 with no

0 victimsSince Apr 28, 2025

zerotolerance

ransomware group
INACTIVE

ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles,

0 victimsSince May 9, 2024

zeta leaks

ransomware group
INACTIVE
0 victimsSince Aug 7, 2025

zetarink

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

zircon

ransomware group
INACTIVE
0 victimsSince Oct 30, 2025

zixer2

ransomware group
0 victims

zola

ransomware group
0 victims