Threat Groups

668 tracked groups

qilin

ransomware group🇷🇺RaaSNot trustworthy
ACTIVE

Qilin (also known as Agenda) is a ransomware-as-a-service operation that emerged in 2022, initially targeting healthcare...

2402 victims

lockbit3

ransomware group🇷🇺RaaS
ACTIVE

LockBit 3.0 (also known as LockBit Black) is the third major iteration of the LockBit ransomware-as-a-service platform, ...

2164 victims

play

ransomware group
ACTIVE

Play ransomware (also known as PlayCrypt) emerged in mid-2022 and is characterized by its use of the ".play" file extens...

1504 victims

akira

ransomware group🇷🇺Recovery risk
ACTIVE

Akira ransomware first appeared in March 2023 and quickly became one of the most active groups of that year, targeting s...

1324 victims

lockbit2

ransomware group🇷🇺RaaS
INACTIVE

LockBit 2.0 (also known as LockBit Red) was the second major version of the LockBit ransomware-as-a-service platform, ac...

1073 victims

clop

ransomware group🇷🇺
ACTIVE

Clop (also spelled Cl0p) is a financially motivated ransomware group attributed to the FIN11/TA505 threat cluster with a...

1000 victims

medusa

ransomware groupRaaS
ACTIVE

Medusa ransomware (not to be confused with MedusaLocker) is a ransomware-as-a-service operation that became highly activ...

712 victims

incransom

ransomware group
ACTIVE

INC Ransom (INCransom) is a double-extortion ransomware group that emerged in mid-2023, targeting healthcare, education,...

702 victims

alphv

ransomware group🇷🇺RaaSNot trustworthy
ACTIVE

ALPHV (also known as BlackCat or Noberus) was a sophisticated ransomware-as-a-service operation launched in November 202...

698 victims

blackbasta

ransomware group🇷🇺Recovery risk
INACTIVE

Black Basta emerged in April 2022 and is widely assessed by researchers and law enforcement to be composed of former Con...

467 victims

8base

ransomware group
INACTIVE

8Base is a double-extortion ransomware group that first appeared in early 2022 but dramatically escalated activity in mi...

462 victims

bianlian

ransomware group🇨🇳
INACTIVE

BianLian ransomware first appeared in June 2022 and is attributed by multiple researchers and the FBI/CISA to a China-ba...

447 victims

ransomhub

ransomware group🇷🇺RaaS
INACTIVE

RansomHub is a ransomware-as-a-service operation that launched in February 2024 and rapidly became one of the most activ...

401 victims

thegentlemen

ransomware group🇷🇺RaaS
ACTIVE

The Gentlemen is a ransomware-as-a-service group that emerged in mid-2024 and rapidly accumulated victims across North A...

398 victims

dispossessor

ransomware group🇤🇤
INACTIVE

Dispossessor (also tracked as Radar) was a ransomware-adjacent data extortion operation active from August 2023 until it...

391 victims

conti

ransomware group🇷🇺Reported reliable
INACTIVE

Conti was one of the most prolific and financially damaging ransomware operations in history, attributed by the FBI and ...

383 victims

safepay

ransomware group
ACTIVE

SafePay is a double-extortion ransomware group that emerged in late 2024, quickly attracting attention for its professio...

381 victimsSince Dec 31, 2024

dragonforce

ransomware group🇲🇾RaaS
ACTIVE

DragonForce is a ransomware-as-a-service operation with roots in a Malaysian hacktivist group of the same name that was ...

354 victims

hunters

ransomware group🇷🇺RaaS
INACTIVE

Hunters International emerged in October 2023 and is widely assessed to be a rebrand or direct continuation of the Hive ...

336 victims

pysa

ransomware group🇫🇷Recovery risk
INACTIVE

PYSA (also known as Mespinoza) is a ransomware group active since 2019 that has primarily targeted education, healthcare...

322 victims

everest

ransomware group🇷🇺
ACTIVE

Everest is a Russian-speaking ransomware and data extortion group active since at least 2020, known for targeting critic...

315 victims

sinobi

ransomware group🇷🇺
ACTIVE

Sinobi is a data extortion and ransomware group that emerged in 2024 and is assessed to have inherited personnel and cod...

302 victims

nightspire

ransomware group
ACTIVE

Nightspire is a relatively new double-extortion ransomware group that emerged in early 2025 and has quickly accumulated ...

299 victimsSince Apr 27, 2025

FOG

ransomware group
INACTIVE

FOG ransomware is a sophisticated strain first observed in May 2024, initially targeting US educational institutions bef...

276 victims

lockbit5

ransomware group🇷🇺RaaS
ACTIVE

LockBit 5.0 (also referred to as LockBit Nation-State) is a claimed successor to LockBit 3.0 that emerged after Operatio...

274 victimsSince Feb 12, 2026

rhysida

ransomware group
ACTIVE

Rhysida is a ransomware group that emerged in May 2023, quickly gaining notoriety for attacking healthcare providers and...

260 victims

lynx

ransomware group🇷🇺RaaS
ACTIVE

Lynx is a ransomware-as-a-service operation that emerged in mid-2024 and is assessed to be a rebrand or direct successor...

258 victims

killsec

ransomware group🇮🇳RaaS
ACTIVE

KillSec (Kill Security) is a hacktivist-turned-cybercriminal group that emerged in late 2023, linked by researchers to I...

255 victimsSince Dec 31, 2024

cactus

ransomware group
INACTIVE

Cactus ransomware surfaced in March 2023 and quickly gained attention for exploiting vulnerabilities in Qlik Sense analy...

249 victims

hive

ransomware group🇷🇺
INACTIVE

Hive was a major ransomware-as-a-service operation active from June 2021 until January 2023, targeting over 1,500 organi...

225 victimsSince Jun 1, 2021

ransomhouse

ransomware group🇷🇺
ACTIVE

RansomHouse is a data extortion group and marketplace active since December 2021 that focuses on stealing data without n...

224 victims

malas

ransomware group
INACTIVE
221 victims

sarcoma

ransomware group

Sarcoma is a double-extortion ransomware group that emerged in mid-2024, primarily targeting manufacturing, professional...

206 victims

vicesociety

ransomware group🇷🇺
INACTIVE

Vice Society is a ransomware group that was active from mid-2021 to 2023, distinguished by its heavy focus on the educat...

200 victims

handala

ransomware group🇮🇷
ACTIVE

Handala (also known as Handala Hack Team or Hatef) is an Iran-linked hacktivist group that emerged during the Israel-Ham...

190 victims

stormous

ransomware group🇤🇤
ACTIVE

Stormous is a pro-Russian hacktivist and ransomware group that emerged around mid-2021, believed to include members from...

190 victims

nova

ransomware group🇷🇺RaaS
ACTIVE

Nova (formerly known as RALord) is a ransomware-as-a-service operation that rebranded from RALord in late 2024. The grou...

185 victimsSince Oct 1, 2025

meow

ransomware group
INACTIVE

Meow ransomware is a strain that emerged in 2022, appending the ".MEOW" extension to encrypted files and primarily targe...

184 victims

royal

ransomware group🇷🇺
INACTIVE

Royal ransomware was active from September 2022 to mid-2023 and is believed to have been formed by former members of the...

183 victims

coinbasecartel

ransomware group🇷🇺RaaS
ACTIVE

CoinbaseCartel (also known as CoinBase Cartel) is a financially motivated cybercrime group that operates a data acquisit...

180 victimsSince Feb 13, 2026

babuk2

ransomware group🇷🇺Not trustworthy
INACTIVE

Babuk 2.0 (also styled as Babuk Locker 2.0 or SatanLock) is a group that impersonates the original Babuk ransomware oper...

174 victimsSince Jan 27, 2025

spacebears

ransomware group
ACTIVE

SpaceBears is a data extortion group that emerged in 2024, focusing on stealing and publishing sensitive corporate data ...

171 victims

avaddon

ransomware group🇷🇺
INACTIVE

Avaddon was a ransomware-as-a-service operation active from June 2020 to June 2021, when the operators unexpectedly shut...

170 victims

blacksuit

ransomware group🇷🇺RaaS
INACTIVE

BlackSuit is the rebranded continuation of the Royal ransomware operation, confirmed by CISA and FBI in an August 2024 j...

170 victims

ragnarlocker

ransomware group🇷🇺
INACTIVE

RagnarLocker was a Russia-linked ransomware group active from 2019 to 2023, known for conducting its own intrusions with...

167 victims

deadlock

ransomware group
ACTIVE
149 victims

funksec

ransomware group🇩🇿
ACTIVE

FunkSec is an Algerian ransomware group that emerged in late 2024 and quickly generated a high victim count through a co...

148 victimsSince Dec 31, 2024

snatch

ransomware group🇷🇺
ACTIVE

Snatch ransomware (not to be confused with the 2022 data extortion group reusing the brand) is a Russia-linked operation...

146 victims

worldleaks

ransomware group🇷🇺RaaS
ACTIVE

WorldLeaks is the rebranded continuation of Hunters International, launched in January 2025 after the group ceased file-...

141 victims

abyss

ransomware group
ACTIVE

Abyss (Abyss Data) is a data extortion group that emerged in early 2023, focusing on stealing and publishing sensitive c...

135 victimsSince Oct 17, 2024

noescape

ransomware group🇷🇺RaaS
INACTIVE

NoEscape was a ransomware-as-a-service operation that launched in June 2023 and is assessed by multiple researchers to b...

135 victims

monti

ransomware group🇷🇺
INACTIVE

Monti is a ransomware group that emerged in June 2022, widely assessed to be a copycat or offshoot of the Conti operatio...

133 victims

SilentRansomGroup

ransomware group🇷🇺

SilentRansomGroup (SRG) is a former Conti team that continued operating independently following Conti's dissolution in 2...

131 victimsSince Feb 13, 2026

toufan

ransomware group🇮🇷
ACTIVE

Toufan (also known as Toufan Al-Aqsa) is an Iran-linked hacktivist group that emerged during the Israel-Hamas conflict i...

130 victimsSince Dec 31, 2024

blackbyte

ransomware group🇷🇺RaaS
ACTIVE

BlackByte is a ransomware-as-a-service operation first observed in July 2021, assessed to be Russia-linked and notable f...

127 victims

apt73

ransomware group🇷🇺
ACTIVE

APT73 is a ransomware group that operated under the "eraleign" identity before rebranding as Bashe in October 2024. Some...

120 victims

arcusmedia

ransomware groupRaaS
INACTIVE

Arcus Media is a ransomware-as-a-service operation that first emerged in May 2024, offering affiliates a Linux and Windo...

120 victims

interlock

ransomware group
ACTIVE

Interlock ransomware emerged in late 2024 and is notable for deploying a custom ransomware variant that targets both Win...

118 victims

pear

ransomware group
ACTIVE

PEAR (Pure Extraction And Ransom) Team is a data extortion group that emerged in 2024, focusing on publishing stolen cor...

118 victimsSince Feb 13, 2026

eldorado

ransomware group🇷🇺RaaS
INACTIVE

Eldorado is a ransomware-as-a-service operation that emerged in early 2024, offering both Windows and VMware ESXi encryp...

116 victims

threeam

ransomware group🇷🇺
ACTIVE

3AM (ThreeAM) is a ransomware group discovered in September 2023, first observed being deployed as a fallback when LockB...

116 victims

ransomexx

ransomware group🇷🇺
ACTIVE

RansomExx (also known as Defray777) is a ransomware family that targeted multiple high-profile organizations including K...

113 victims

shinyhunters

ransomware group🇤🇤
ACTIVE

ShinyHunters is a prolific data theft and extortion group responsible for numerous high-profile breaches including the 2...

110 victimsSince Nov 4, 2025

cuba

ransomware group🇷🇺RaaS
INACTIVE

Cuba ransomware is a ransomware-as-a-service operation active since at least 2019, assessed to be Russia-linked despite ...

109 victims

devman

ransomware group🇷🇺RaaS
INACTIVE

Devman is a former RansomHub and INC Ransom affiliate that began operating independently as a ransomware-as-a-service pl...

108 victimsSince Jun 16, 2025

beast

ransomware groupRaaS
ACTIVE

Beast ransomware operates as a ransomware-as-a-service platform targeting Windows, Linux, and VMware ESXi environments. ...

106 victims

revil

ransomware group🇷🇺RaaSReported reliable
INACTIVE

REvil (also known as Sodinokibi) was one of the most financially damaging ransomware-as-a-service operations in history,...

105 victims

genesis

ransomware group
ACTIVE

Financial interests only. <br/> We do not provide or work with affiliate programs, no collaborations either. <br/...

92 victimsSince Feb 13, 2026

kairos

ransomware group🇷🇺
ACTIVE

Kairos is a double-extortion ransomware group that emerged in 2024, operating a dark web leak site and targeting organiz...

92 victims

warlock

ransomware group🇨🇳RaaS
ACTIVE

Warlock ransomware emerged in mid-2025 and has been attributed by Microsoft, Sophos, and Trend Micro with moderate-to-hi...

90 victimsSince Jun 11, 2025

cloak

ransomware group
ACTIVE

Cloak is a cybercriminal ransomware group that first emerged in late 2023, targeting small to mid-size businesses across...

85 victims

anubis

ransomware group🇷🇺
ACTIVE

Anubis ransomware emerged in 2024 as a data extortion and ransomware-as-a-service platform that distinguishes itself wit...

81 victims

direwolf

ransomware group
ACTIVE

DirewWolf is a recently emerged double-extortion ransomware group that conducts targeted attacks against medium to large...

81 victimsSince Feb 13, 2026

wannacry

ransomware group🇰🇵
INACTIVE

WannaCry was a destructive ransomware worm deployed in May 2017 that infected over 200,000 computers across 150 countrie...

81 victims

embargo

ransomware group🇷🇺RaaS
ACTIVE

Embargo is a ransomware-as-a-service operation that emerged in mid-2024, utilizing Rust-based encryptors for both Window...

75 victims

lorenz

ransomware group
INACTIVE

Lorenz is a ransomware group active since early 2021, known for an unusual tactic of selling access to victim networks t...

73 victims

karakurt

ransomware group🇷🇺

Karakurt is a data extortion group established in 2021 as an offshoot of the Conti ransomware operation (Wizard Spider),...

72 victims

ransomed

ransomware group
INACTIVE
71 victimsSince Sep 1, 2023

cicada3301

ransomware group🇷🇺RaaS
INACTIVE

Cicada3301 (unrelated to the 2012 internet puzzle) is a ransomware-as-a-service operation that emerged in June 2024 with...

70 victims

raworld

ransomware group🇨🇳
INACTIVE

RA World (formerly known as RA Group, active since April 2023) is a ransomware operation linked by Symantec and Palo Alt...

70 victimsSince Dec 31, 2024

mallox

ransomware group🇨🇳RaaS
INACTIVE

Mallox (also known as TargetCompany, Fargo, or Tohnichi) is a ransomware-as-a-service operation assessed to be China-lin...

69 victims

payload

ransomware group
ACTIVE

Payload is a ransomware group that emerged in 2024, primarily targeting organizations in North America and Europe throug...

68 victims

quantum

ransomware group🇷🇺
INACTIVE

Quantum ransomware emerged in August 2021 as a rebrand of the MountLocker operation and was subsequently linked to the C...

68 victims

medusalocker

ransomware group
ACTIVE

Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predec...

67 victimsSince Mar 1, 2024

avoslocker

ransomware group
INACTIVE

AvosLocker is a ransomware-as-a-service operation that launched in mid-2021, known for targeting critical infrastructure...

65 victims

lv

ransomware group
INACTIVE

parser needs to be built

64 victims

blacklock

ransomware group🇷🇺
INACTIVE

BlackLock (also known as Mamona) is a ransomware-as-a-service operation that emerged in late 2023 as an evolution of the...

63 victimsSince Aug 25, 2025

braincipher

ransomware group
ACTIVE

BrainCipher ransomware surfaced in mid-2024, initially gaining attention for a major attack against Indonesia's National...

62 victims

donutleaks

ransomware group
INACTIVE

DonutLeaks is a data extortion group that emerged in 2022, publishing stolen data from organizations that refused to pay...

54 victims

payoutsking

ransomware group
ACTIVE

Payouts King Group is a data extortion collective that explicitly states it does not operate as a RaaS and does not use ...

53 victimsSince Feb 13, 2026

darkvault

ransomware group
ACTIVE

DarkVault is a versatile threat actor that emerged in 2024, conducting both ransomware and data extortion operations aga...

52 victims

AiLock

ransomware group🇷🇺RaaS
ACTIVE

AiLock is a ransomware-as-a-service group that emerged in early 2025, marketing itself as AI-assisted and suspected by r...

51 victimsSince Mar 7, 2026

krybit

ransomware group
ACTIVE
51 victimsSince Apr 3, 2026

tengu

ransomware group
INACTIVE

Ransomware group active in data extortion.

51 victims

losttrust

ransomware group
INACTIVE
50 victims

ryuk

ransomware group🇷🇺Recovery risk
INACTIVE

Ryuk ransomware is attributed to the Russia-based Wizard Spider cybercriminal group and was one of the most damaging ran...

50 victims

gunra

ransomware group
ACTIVE

Gunra is an emerging ransomware group first identified in April 2025. It employs a classic double-extortion model—encryp...

49 victimsSince Feb 3, 2026

maze

ransomware group🇷🇺
ACTIVE

Maze ransomware pioneered the double-extortion model in late 2019, becoming the first major group to combine file encryp...

49 victims

J

ransomware group
INACTIVE
48 victimsSince Dec 15, 2025

securotrop

ransomware group
ACTIVE
48 victimsSince Feb 13, 2026

arvinclub

ransomware group
INACTIVE

Arvin Club first appeared around early to mid-2021, debuting on its Tor leak site with posts dating back to May 5, 2021....

47 victims

obscura

ransomware groupNot trustworthy
INACTIVE
47 victimsSince Jan 21, 2026

crypto24

ransomware groupRaaS

aka Public Data Storage <br/>Crypto24 emerged in early 2025 as a fast-growing double-extortion ransomware-as-a-service ...

44 victimsSince Feb 13, 2026

knight

ransomware groupRaaS
INACTIVE

Knight is a Ransomware-as-a-Service (RaaS) operation first observed in August 2023, believed to be a rebrand or evolutio...

44 victims

ciphbit

ransomware group🇷🇺
ACTIVE

CiphBit is a ransomware operation first detected in early 2024, using a custom encryptor targeting Windows and network s...

43 victims

marketo

ransomware group
INACTIVE
43 victims

midas

ransomware group
INACTIVE

Midas ransomware is a data extortion group active since late 2021 that shares significant technical similarities with th...

43 victims

nitrogen

ransomware groupNot trustworthy
ACTIVE

Nitrogen is a data extortion group that emerged in 2023, primarily conducting data theft without encryption to pressure ...

43 victims

global

ransomware groupRaaS
INACTIVE

Now a RaaS by BlackLock ($$$). <br/>Global Group is a newly emerged Ransomware-as-a-Service (RaaS) platform that debuted...

42 victimsSince Sep 17, 2025

helldown

ransomware group
INACTIVE

Helldown is a double-extortion ransomware group that emerged in late 2024, known for exploiting vulnerabilities in Zyxel...

40 victims

spook

ransomware group
INACTIVE
40 victims

blackshrantac

ransomware group
INACTIVE

aka black shrantac

39 victimsSince Jan 15, 2026

metaencryptor

ransomware group
ACTIVE

We are a group of young people who identify themselves as specialists in the field of network security with at least 15 ...

39 victims

suncrypt

ransomware group🇷🇺
INACTIVE

SunCrypt is a ransomware group active since 2019 that joined the Maze ransomware cartel in 2020, adopting the double-ext...

39 victims

darkleakmarket

ransomware group
INACTIVE
38 victims

flocker

ransomware group
INACTIVE
38 victims

termite

ransomware group
ACTIVE

Termite is a ransomware group that emerged in late 2024, gaining attention for exploiting a zero-day vulnerability in Cl...

38 victims

nokoyawa

ransomware group
INACTIVE

Nokoyawa ransomware is a strain active from early 2022 that shares significant code and infrastructure with the Karma an...

34 victims

doppelpaymer

ransomware group🇷🇺
INACTIVE

DoppelPaymer ransomware is attributed to the Russia-based Evil Corp cybercriminal organization and is a successor to Bit...

32 victims

dragonransomware

ransomware group
INACTIVE

Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a...

32 victimsSince Dec 31, 2024

lamashtu

ransomware group
ACTIVE
32 victimsSince Apr 13, 2026

trigona

ransomware group
INACTIVE

Trigona ransomware was active from late 2022 to 2023, targeting businesses across multiple sectors with AES encryption a...

31 victims

blackmatter

ransomware group🇷🇺
INACTIVE

BlackMatter was a ransomware-as-a-service operation active from July to November 2021, widely assessed as a direct rebra...

30 victims

dAn0n

ransomware group
INACTIVE

dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model...

29 victims

leaktheanalyst

ransomware group
INACTIVE
29 victims

morpheus

ransomware group
ACTIVE
29 victimsSince Aug 3, 2025

siegedsec

ransomware group
ACTIVE
29 victims

cephalus

ransomware group
ACTIVE
28 victimsSince Aug 29, 2025

chaos

ransomware groupRaaS
ACTIVE

Chaos ransomware operates as a ransomware-as-a-service builder that has been widely distributed on underground forums si...

28 victimsSince Feb 13, 2026

orion

ransomware group
ACTIVE

Jan13, 2026: We believe the group might be related to Babuk-Bjorka.

28 victimsSince Feb 13, 2026

brotherhood

ransomware group
INACTIVE
26 victimsSince Jan 21, 2026

fulcrumsec

ransomware group
26 victimsSince Oct 30, 2025

kelvinsecurity

ransomware group
INACTIVE

Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and web...

26 victims

payloadbin

ransomware group
INACTIVE
26 victims

underground

ransomware group🇷🇺
ACTIVE

Underground ransomware (also known as Underground Team) is a Russia-linked group associated with the RomCom RAT threat c...

26 victims

groove

ransomware group
INACTIVE

Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its agg...

25 victims

blacknevas

ransomware group

BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct deriv...

24 victimsSince Feb 13, 2026

CMDOrganization

ransomware group
ACTIVE

CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all...

24 victims

moneymessage

ransomware group
ACTIVE
24 victims

daixin

ransomware group🇨🇳
ACTIVE

Daixin Team is a ransomware and data extortion group active since mid-2022, primarily targeting the US healthcare and pu...

23 victims

datacarry

ransomware group
INACTIVE

DataCarry is a newly observed ransomware and data-extortion operation, first seen in May 2025. It operates a double-exto...

23 victimsSince Feb 13, 2026

alphalocker

ransomware group
ACTIVE
22 victims

crazyhunter

ransomware group
INACTIVE
22 victimsSince Apr 3, 2025

lapsus$

ransomware group🇬🇧
ACTIVE

Lapsus$ is a data extortion group that emerged in late 2021, known for social engineering, SIM-swapping, and insider rec...

22 victims

netwalker

ransomware group🇨🇦
INACTIVE

NetWalker (also known as Mailto) was a ransomware operation active from 2019 to January 2021, when US and Bulgarian auth...

22 victims

IMNCrew

ransomware group
INACTIVE
21 victimsSince Oct 27, 2025

sabbath

ransomware group
ACTIVE
21 victims

bravox

ransomware group
ACTIVE

Ransomware group active in data extortion.

20 victims

m3rx

ransomware group
ACTIVE
20 victims

mountlocker

ransomware group
INACTIVE
20 victimsSince Sep 8, 2021

ralord

ransomware group
ACTIVE
20 victimsSince Jul 11, 2025

d4rk4rmy

ransomware group
INACTIVE

D4rk4rmy is a data-extortion focused threat actor that emerged in mid-2025, targeting high-profile organizations across ...

19 victimsSince Aug 30, 2025

hellcat

ransomware group🇯🇴RaaS
INACTIVE

HellCat is a ransomware-as-a-service operation that emerged in late 2024, with KELA researchers identifying core operato...

19 victims

xinglocker

ransomware group
INACTIVE

xing use a custom mountlocker exe

19 victims

mosesstaff

ransomware group
INACTIVE
18 victims

tridentlocker

ransomware group
ACTIVE
18 victimsSince Feb 13, 2026

ALP-001

ransomware group
ACTIVE
17 victimsSince Mar 21, 2026

benzona

ransomware group
ACTIVE
17 victimsSince Feb 13, 2026

insomnia

ransomware group
ACTIVE
17 victimsSince Feb 13, 2026

nefilim

ransomware group
INACTIVE

According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is remov...

17 victims

onyx

ransomware group
INACTIVE
17 victims

ShadowByt3$

ransomware group
ACTIVE
17 victimsSince Feb 28, 2026

unsafe

ransomware group
ACTIVE

A group which seems to recycle leak from other ransomware groups

17 victimsSince Dec 31, 2024

dunghill

ransomware group
INACTIVE

Dunghill Leak is the publicly branded data leak site (DLS) operated by the Dark Angels ransomware group, established cir...

16 victimsSince Dec 31, 2024

redransomware

ransomware group
INACTIVE
16 victims

trinity

ransomware group
INACTIVE
16 victims

apos

ransomware groupRaaS
INACTIVE

Apos ransomware surfaced in April 2024 and is best characterized as a data‑broker or leak‑only operation, rather than a ...

15 victimsSince Oct 8, 2025

aurora

ransomware group
ACTIVE
15 victims

eraleign (apt73)

ransomware group🇷🇺
ACTIVE

Eraleign (APT73) rebranded as Bashe in October 2024 after operating under the Eraleign name, with the transition coincid...

15 victimsSince Jun 22, 2024

radar

ransomware group
15 victimsSince Feb 13, 2026

secp0

ransomware group
ACTIVE

Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only

15 victimsSince Feb 13, 2026

teamxxx

ransomware group
INACTIVE
15 victimsSince Sep 1, 2025

werewolves

ransomware group🇷🇺
ACTIVE

Werewolves is a Russia-linked ransomware group that emerged in mid-2023, using a modified version of the LockBit 3.0 sou...

15 victims

argonauts

ransomware group
INACTIVE
14 victimsSince Mar 27, 2025

azroteam

ransomware group
INACTIVE
14 victims

freecivilian

ransomware group
INACTIVE
14 victims

pay2key

ransomware group
INACTIVE
14 victims

RunSomeWares

ransomware group
INACTIVE
14 victimsSince Apr 19, 2025

bavacai

ransomware group
ACTIVE
13 victims

blackout

ransomware group🇷🇺
ACTIVE

Blackout surfaced in February 2024, using a variant based on DarkSide and BlackMatter ransomware source code, establishi...

13 victims

darkside

ransomware group
INACTIVE

FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable dis...

13 victims

kazu

ransomware group
ACTIVE
13 victimsSince Feb 13, 2026

vect

ransomware groupNot trustworthy
INACTIVE
13 victimsSince Jan 21, 2026

weyhro

ransomware group
ACTIVE

Appears to be a Data Extortion group with no encryption.

13 victimsSince Mar 7, 2025

cheers

ransomware group
INACTIVE

Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi ...

12 victims

cipherforce

ransomware group
ACTIVE

For those out of the loop, you may already know us as TeamPCP or Shellforce, we have been active a while publishing data...

12 victimsSince Feb 23, 2026

frag

ransomware group
INACTIVE

Frag ransomware emerged in late 2024, primarily observed exploiting Veeam Backup & Replication vulnerabilities (CVE-2024...

12 victimsSince Sep 12, 2025

titan

ransomware group
ACTIVE
12 victims

0mega

ransomware group
ACTIVE

0mega is a ransomware group first observed in May 2022, operating with a double extortion model: <br/>* Encrypting victi...

11 victims

cryp70n1c0d3

ransomware group
INACTIVE
11 victims

mindware

ransomware group
INACTIVE
11 victims

settra

ransomware group
ACTIVE
11 victims

skira

ransomware group
INACTIVE
11 victimsSince Dec 1, 2025

atomsilo

ransomware groupRaaS
ACTIVE

AtomSilo emerged in September 2021 and ceased operations by year-end 2021. It functioned with a double‑extortion model, ...

10 victims

babuk

ransomware groupNot trustworthy
INACTIVE
10 victims

chort

ransomware group
INACTIVE

Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning ...

10 victimsSince Dec 31, 2024

egregor

ransomware group

Egregor is a ransomware strain that appeared in September 2020, widely believed to be a rebrand or successor to the Maze...

10 victims

kawa4096

ransomware group
INACTIVE
10 victimsSince Aug 16, 2025

madliberator

ransomware group
INACTIVE

Group is also currently known as MADDLL32 and Metatron.

10 victims

redalert

ransomware group
INACTIVE
10 victims

bert

ransomware group
INACTIVE

BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux sy...

9 victimsSince Aug 2, 2025

LeakBazaar

ransomware group
ACTIVE
9 victims

nasirsecurity

ransomware group
ACTIVE
9 victimsSince Oct 14, 2025

rook

ransomware group
INACTIVE

Ransomware.

9 victims

darkpower

ransomware group
INACTIVE

Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations ac...

8 victims

karma

ransomware group
INACTIVE

Karma is a ransomware group first observed in November 2021, operating a double-extortion model that combines data theft...

8 victims

projectrelic

ransomware group
INACTIVE
8 victims

shaoleaks

ransomware group
INACTIVE
8 victims

sparta

ransomware group
INACTIVE
8 victims

bqtlock

ransomware groupRaaS
INACTIVE

aka BaqiyatLock <br/>BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a...

7 victimsSince Aug 21, 2025

cyclops

ransomware groupRaaS
INACTIVE

Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023. It operates as a Ransomwar...

7 victimsSince Oct 13, 2023

desolator

ransomware group
INACTIVE
7 victimsSince Oct 19, 2025

icefire

ransomware group
INACTIVE
7 victims

linkc

ransomware group
ACTIVE
7 victimsSince Apr 26, 2025

lockbit

ransomware groupRaaS
INACTIVE
7 victims

minteye

ransomware group
ACTIVE
7 victimsSince Dec 24, 2025

rebornvc

ransomware group
ACTIVE
7 victimsSince Oct 19, 2025

samsam

ransomware group
7 victims

blackwater

ransomware group
ACTIVE
6 victimsSince Apr 12, 2026

radiant

ransomware group
INACTIVE
6 victimsSince Nov 12, 2025

rancoz

ransomware group
INACTIVE
6 victims

satanlockv2

ransomware group
ACTIVE
6 victimsSince Feb 13, 2026

cryptbb

ransomware group
INACTIVE
5 victims

darkrace

ransomware group
INACTIVE

DarkRace is a moderately destructive ransomware strain observed since 2024. It encrypts files and appends a randomized e...

5 victims

dataleak

ransomware group
INACTIVE
5 victims

exitium

ransomware group
ACTIVE
5 victimsSince Mar 17, 2026

hellogookie

ransomware group
INACTIVE
5 victims

killsec3

ransomware group
ACTIVE
5 victimsSince Apr 13, 2026

kittykatkrew

ransomware group
INACTIVE
5 victims

leaknet

ransomware group
ACTIVE

<br/> <br/>In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside infor...

5 victimsSince Aug 18, 2025

mogilevich

ransomware group
INACTIVE
5 victims

netrunner

ransomware group
5 victimsSince Apr 3, 2026

pandora

ransomware group
INACTIVE

Pandora ransomware was obtained by vx-underground at 2022-03-14.

5 victims

raznatovic

ransomware group
INACTIVE

RANSOMED.VC aka Raznatovic

5 victimsSince May 28, 2024

robinhood

ransomware group
ACTIVE
5 victims

yanluowang

ransomware group
INACTIVE

Ransomware.

5 victims

0day Syndicate

ransomware group
ACTIVE
4 victims

Black X

ransomware group
ACTIVE
4 victims

blackshadow

ransomware group
INACTIVE

BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2...

4 victims

blacktor

ransomware group
INACTIVE
4 victims

kraken

ransomware groupRaaS
INACTIVE

Kraken leak blog (hellokitty) <br/>Kraken is a ransomware family first observed in August 2018 as a Ransomware-as-a-Serv...

4 victimsSince Feb 13, 2026

ms13089

ransomware group
ACTIVE
4 victimsSince Feb 13, 2026

nightsky

ransomware group
INACTIVE
4 victims

prolock

ransomware group
INACTIVE

PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and loc...

4 victims

secpo

ransomware group
4 victims

sensayq

ransomware group
INACTIVE
4 victims

silent

ransomware groupRaaS
INACTIVE

Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own...

4 victimsSince Nov 20, 2025

trisec

ransomware group
INACTIVE
4 victimsSince Feb 21, 2024

ValenciaLeaks

ransomware group
INACTIVE

Official twitter account: https://x.com/ValenciaLeaks72

4 victimsSince Dec 31, 2024

VanHelsing

ransomware groupRaaS
INACTIVE
4 victimsSince May 13, 2025

vendetta

ransomware group
INACTIVE
4 victims

wastedlocker

ransomware group
INACTIVE
4 victims

xp95

ransomware group
ACTIVE
4 victims

AuditTeam

ransomware group
ACTIVE
3 victimsSince Apr 8, 2026

bonacigroup

ransomware group
INACTIVE
3 victims

dharma

ransomware groupRaaSRecovery risk
INACTIVE

Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It opera...

3 victims

GDLockerSec

ransomware group
INACTIVE

Our team members are from different countries and we are not interested in anything else, we are only interested in doll...

3 victimsSince Jan 27, 2025

grief

ransomware groupRaaS
INACTIVE

Grief, also known as Pay or Grief, is a ransomware group that emerged in May 2021 and is widely believed to be operated ...

3 victims

noname

ransomware group
INACTIVE
3 victimsSince Dec 31, 2024

nozelesn

ransomware group
3 victims

PrinzEugen

ransomware group
3 victims

qiulong

ransomware group
INACTIVE
3 victims

ragnarok

ransomware group
INACTIVE

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes...

3 victims

ranstreet

ransomware group
INACTIVE
3 victimsSince Dec 27, 2023

slug

ransomware group
INACTIVE
3 victims

snake

ransomware group
INACTIVE
3 victims

vanirgroup

ransomware group
INACTIVE
3 victims

wallstreet

ransomware group
ACTIVE
3 victims

arkana

ransomware group
INACTIVE
2 victimsSince Jul 6, 2025

astroteam

ransomware group
INACTIVE
2 victims

bitpaymer

ransomware group
2 victims

bjorka

ransomware group

Hellcome Bjorkanism <br/>Bjorka emerged as a prominent data-extortion actor and hacktivist initially active in 2022, ta...

2 victimsSince Feb 1, 2025

cryptnet

ransomware group
INACTIVE

CryptNet is a newer Ransomware-as-a-Service (RaaS) operation first identified in April 2023. It follows a double-extorti...

2 victims

cryptolocker

ransomware group
2 victims

donex

ransomware groupRaaS
INACTIVE

Donex is a ransomware family that emerged in early 2022 as a rebrand of the older Muse ransomware. It uses a double-exto...

2 victims

hades

ransomware group
INACTIVE

Hades is a ransomware group first observed in December 2020, believed by several threat intelligence firms to be operate...

2 victims

lockdata

ransomware group
INACTIVE
2 victims

lunalock

ransomware group
INACTIVE
2 victimsSince Feb 5, 2026

memedusalockerdusa

ransomware group
INACTIVE
2 victims

netflim

ransomware group
INACTIVE
2 victims

orca

ransomware group
INACTIVE
2 victims

osiris

ransomware group
ACTIVE
2 victimsSince Jan 14, 2026

redact

ransomware group
ACTIVE
2 victims

ronggolawe

ransomware group
INACTIVE
2 victims

satanlock

ransomware group

Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages).

2 victimsSince Apr 8, 2025

sicarii

ransomware groupNot trustworthy
INACTIVE
2 victimsSince Jan 19, 2026

zeppelin

ransomware groupRaaS
INACTIVE

Zeppelin ransomware is a derivative of the Delphi-based Vega malware family and functions as a Ransomware as a Service (...

2 victims

3am

ransomware group
INACTIVE

3AM, also known as ThreeAM, is a relatively new ransomware family that emerged in late 2023, initially deployed as a fal...

1 victimsSince Jan 9, 2025

agelocker

ransomware group
INACTIVE
1 victims

bitlocker

ransomware group
INACTIVE
1 victims

blogxx

ransomware group
INACTIVE
1 victims

bluebox

ransomware group
INACTIVE
1 victimsSince Dec 31, 2024

ContFR

ransomware groupRaaS
ACTIVE

RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon...

1 victimsSince Feb 13, 2026

cring

ransomware group
INACTIVE
1 victims

cryptowall

ransomware group
1 victims

deathkitty

ransomware group
INACTIVE
1 victims

gandcrab

ransomware groupRaaSReported reliable
INACTIVE

GandCrab was a prolific Ransomware-as-a-Service (RaaS) operation active from January 2018 to mid-2019. It quickly became...

1 victimsSince Dec 9, 2024

goznym

ransomware group
1 victims

insane

ransomware group
INACTIVE
1 victims

kyber

ransomware group
ACTIVE
1 victimsSince Feb 13, 2026

locky

ransomware group
INACTIVE
1 victimsSince Dec 10, 2024

malekteam

ransomware group
1 victims

networm

ransomware group
INACTIVE
1 victims

nullbulge

ransomware group

A hacktivist group protecting artists' rights and ensuring fair compensation for their work.

1 victims

pryx

ransomware group
1 victims

ransomcortex

ransomware group
INACTIVE
1 victims

roadsweep

ransomware group
INACTIVE
1 victims

sekhmet

ransomware group
1 victims

walocker

ransomware group
INACTIVE
1 victimsSince Aug 22, 2025

yurei

ransomware group
INACTIVE
1 victimsSince Sep 12, 2025

0apt

ransomware groupRaaS
INACTIVE

The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele...

0 victimsSince Feb 13, 2026

0xFFF

ransomware group
INACTIVE
0 victims

2023lock

ransomware group

2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus fa...

0 victims

a1project

ransomware groupRaaS

The locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for E...

0 victims

Abrahams_Ax

ransomware group
ACTIVE

Abrahams_Ax, first observed in November 2022, is not a Ransomware-as-a-Service (RaaS) operation but a politically motiva...

0 victimsSince Dec 31, 2024

adminlocker

ransomware group
INACTIVE

AdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear Rans...

0 victims

againstthewest

ransomware group
INACTIVE
0 victims

aGl0bGVyCg

ransomware group
ACTIVE

This ransomware group (notably stylized as aGl0bGVyCg) has extremely limited publicly available information. No confirme...

0 victims

ako

ransomware groupRaaS
INACTIVE

First observed in early January 2020 (initial victim post on January 9, 2020), Ako (also known as MedusaReborn) operates...

0 victims

amnesia

ransomware group

Amnesia ransomware was first identified in May 2017, particularly affecting enterprise cloud environments. It does not a...

0 victims

ank

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

antibrok3rs

ransomware group

Antibrok3rs emerged as an access broker (not a ransomware operator itself) linked to the aftermath of the 2023 MOVEit su...

0 victimsSince Dec 25, 2025

aptlock

ransomware group
INACTIVE

Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage. T...

0 victimsSince Mar 24, 2025

arachna leak

ransomware group
0 victimsSince Apr 13, 2026

arcane

ransomware group

Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations aga...

0 victims

arcrypter

ransomware group

ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government en...

0 victims

argonauts group

ransomware group
INACTIVE

Argonauts Group is a data extortion operation that surfaced around September–October 2024, primarily targeting organizat...

0 victimsSince Mar 27, 2025

arkana security

ransomware group
INACTIVE

Arkana Security emerged in early 2025, debuting with a high-profile data-extortion campaign against the U.S. internet pr...

0 victimsSince Jul 6, 2025

astralocker

ransomware group

AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-e...

0 victims

avos

ransomware group
INACTIVE

First observed in July 2021, AvosLocker operates as a Ransomware-as-a-Service (RaaS) platform employing a double-extorti...

0 victims

aware

ransomware group
INACTIVE
0 victimsSince Jan 25, 2026

axxes

ransomware group
INACTIVE

Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing ...

0 victimsSince Jul 8, 2025

aztroteam

ransomware group
INACTIVE
0 victims

azzasec

ransomware groupRaaS
INACTIVE

We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botne...

0 victimsSince Apr 28, 2025

b0 group

ransomware group
INACTIVE

B0 is a relatively obscure ransomware operation with very limited public reporting outside of leak site monitoring. It a...

0 victimsSince May 8, 2025

babuk-bjorka

ransomware groupNot trustworthy
INACTIVE

On January 26th, Babuk's dedicated leak site (DLS) was "relaunched". Bjorka (Telegram: @bjorkanesiaaaa) is the current a...

0 victimsSince Jan 27, 2025

babuk-locker

ransomware groupRaaSNot trustworthy
INACTIVE

Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises ...

0 victimsSince Feb 26, 2024

babyduck

ransomware group
INACTIVE
0 victims

babylockerkz

ransomware group

BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023. It operates under a double‑extortion ...

0 victims

backmydata

ransomware group

BackMyData is a variant of the Phobos ransomware family, first observed in early 2024. It follows a double‑extortion mod...

0 victims

balletspistol

ransomware group

BalletsPistol is a Python-based ransomware strain distributed via GitHub. An investigative report from June 2025 reveals...

0 victims

belsen group

ransomware group
INACTIVE

aka Belesn Group. <br/>Belsen Group emerged in January 2025 as a data broker and leak-focused threat actor, not engaging...

0 victimsSince Mar 12, 2025

bidon

ransomware group

BIDON is a variant of the Monti ransomware family, first observed around mid‑2023. It employs a double‑extortion strateg...

0 victims

bitransomware

ransomware group
INACTIVE

BitRansomware (also known as DCryptSoft or ReadMe) surfaced in November 2020, primarily as a widespread cryptolocker tar...

0 victimsSince Dec 9, 2024

black witch

ransomware group
0 victims

blackberserk

ransomware group

Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023. It operates under a single‑extort...

0 victims

blackbit

ransomware group
INACTIVE

BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and func...

0 victimsSince Aug 9, 2025

blackbyte-crux

ransomware group
ACTIVE

Crux is a newly identified ransomware variant active since July 2025, which claims affiliation with the established Blac...

0 victimsSince Nov 17, 2025

blackfield

ransomware group
INACTIVE
0 victimsSince Feb 17, 2026

blackhunt

ransomware group
INACTIVE

Black Hunt ransomware has been active since at least mid-2021 and operates under a double-extortion model, encrypting vi...

0 victimsSince Jul 9, 2025

blacksnake

ransomware groupRaaS

BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began re...

0 victims

bluelocker

ransomware group
INACTIVE

Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum

0 victims

bluesky

ransomware group
INACTIVE

BlueSky ransomware first emerged in July 2022 and is characterized by aggressive, high-speed file encryption using a mul...

0 victims

bober

ransomware group
INACTIVE
0 victimsSince Aug 6, 2025

br0k3r

ransomware group
INACTIVE

Br0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group lever...

0 victimsSince Jan 16, 2025

buddyransome

ransomware group
0 victims

bytesfromheaven

ransomware group
INACTIVE
0 victimsSince Aug 12, 2025

C3RB3R

ransomware group
INACTIVE

Cerber ransomware, active since 2016, has resurfaced occasionally using the name C3RB3R. It operates as a semi-private R...

0 victims

catb

ransomware group

CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distribut...

0 victims

cerber

ransomware group
0 victims

cerberimposter

ransomware group

Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting o...

0 victims

cerbersyslock

ransomware group

CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceiv...

0 victims

chilelocker

ransomware group
INACTIVE

ChileLocker first emerged in August 2022 and is considered part of the broader ARCrypter ransomware family. It employs a...

0 victims

cipherwolf

ransomware groupRaaS
0 victimsSince Apr 13, 2026

clearwater

ransomware group
0 victimsSince Apr 13, 2026

cloak.su (locker leak)

ransomware group
0 victimsSince Mar 24, 2026

clop torrents

ransomware group
INACTIVE
0 victimsSince Jul 15, 2024

colossus

ransomware group

Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S...

0 victims

cooming

ransomware group
INACTIVE

previous clearnet domain coomingproject.com

0 victims

core

ransomware group

Core ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion m...

0 victims

crazyhunter team

ransomware group

CrazyHunter is a rising ransomware threat first detected in early 2025, with particularly dangerous campaigns targeting ...

0 victimsSince Apr 3, 2025

crosslock

ransomware group
INACTIVE

CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion ...

0 victims

cry0

ransomware group
ACTIVE
0 victimsSince Feb 13, 2026

cryakl

ransomware group

also known as “Fantomas”. <br/>Cryakl first appeared in 2014, spreading primarily across Eastern Europe and Russia via p...

0 victims

crylock

ransomware groupRaaS
INACTIVE

CryLock is a ransomware variant that emerged around April 2020, evolving from the Cryakl (Fantomas) ransomware family. I...

0 victims

crynox

ransomware group

Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to...

0 victims

crypt ransomware

ransomware group
INACTIVE

.crYpt <br/>MD5: 54EFAC23D7B524D56BEDBCE887E11849 <br/> <br/>Babuk Variant

0 victimsSince Dec 11, 2024

cryptedpay

ransomware group

CryptedPay is a standalone ransomware strain observed around early 2025, that encrypts files using AES-256 and appends t...

0 victims

cryptomix

ransomware group
0 victims

cryptoware

ransomware group
0 victims

cryptxxx

ransomware group
INACTIVE

CryptXXX is a ransomware strain that first appeared in April 2016, developed by the same group behind the Reveton and An...

0 victimsSince Dec 9, 2024

crysis

ransomware groupRecovery risk

Crysis ransomware was first identified in early 2016 and is a long-running family that later evolved into the Dharma ran...

0 victims

cs-137

ransomware group

Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for enc...

0 victims

ctblocker

ransomware group
INACTIVE

aka Critroni <br/>CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve crypt...

0 victimsSince Dec 9, 2024

cyberex

ransomware group
INACTIVE
0 victimsSince May 27, 2025

cylance

ransomware group
0 victims

d0glun

ransomware group
INACTIVE

D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermedia...

0 victimsSince Jan 30, 2025

dagonlocker

ransomware groupRaaS
INACTIVE

Dagon Locker is a double-extortion ransomware family that surfaced around September 2022. It represents an evolution of ...

0 victims

dark shinigami

ransomware group
INACTIVE
0 victimsSince Dec 15, 2025

darkangel

ransomware group
INACTIVE

Dark Angels is a highly targeted ransomware and data-extortion group that emerged in spring 2022. Rather than using an a...

0 victims

darkangels

ransomware group
INACTIVE
0 victims

darkbit

ransomware group
INACTIVE
0 victimsSince Feb 15, 2023

darkbit01

ransomware group
INACTIVE

DarkBit is a politically motivated ransomware operation active since February 2023, targeting academic and public sector...

0 victims

darkhav0c

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

darkrypt

ransomware group
0 victimsSince Jan 25, 2025

darkwave

ransomware group
INACTIVE

Written in python

0 victimsSince Feb 19, 2026

darkylock

ransomware group

Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk s...

0 victims

dataf locker

ransomware group
INACTIVE

DataF Locker is a ransomware variant first observed in 2024, closely tied to the Babuk ransomware lineage. It operates u...

0 victimsSince Dec 9, 2024

datakeeper

ransomware group
INACTIVE
0 victimsSince Feb 13, 2026

deadbydawn

ransomware group
0 victims

deathgrip

ransomware groupRaaS

DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked...

0 victims

deathransom

ransomware group

DeathRansom is a ransomware family first seen in the wild in late 2019, initially appearing as a bluff—dropping ransom n...

0 victims

delta

ransomware group
0 victims

desolated

ransomware group
0 victims

devman2

ransomware groupRaaS
INACTIVE

DevMan 2.0 is the evolved iteration of the DevMan ransomware, first documented in July 2025. It enhances the capabilitie...

0 victimsSince Sep 28, 2025

diavol

ransomware group
INACTIVE

Diavol is a ransomware strain first observed in June 2021, associated with the Wizard Spider threat group—best known for...

0 victims

dread

ransomware group
INACTIVE
0 victims

ech0raix

ransomware group
INACTIVE

The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom not...

0 victims

elcometa

ransomware group
0 victims

elonmusknow

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

elpaco

ransomware group

Elpaco is a variant of Mimic ransomware that emerged around August 2023. Designed with significant customization and ste...

0 victims

enciphered

ransomware group

aka xoriste

0 victims

encrypthub

ransomware group
0 victims

endurance

ransomware group
INACTIVE

Endurance is a destructive ransomware variant first observed in 2023, developed and operated by the threat actor known a...

0 victimsSince Jun 1, 2023

entropy

ransomware group
INACTIVE

Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomw...

0 victims

ep918

ransomware group
INACTIVE
0 victims

erebus

ransomware group
0 victims

eruption

ransomware group

Rebranded to Sabbath.

0 victims

esxiargs

ransomware group
ACTIVE

ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-202...

0 victims

evolution

ransomware group
0 victimsSince Jan 25, 2026

exorcist

ransomware group
INACTIVE

Ransomware.

0 victims

fakersa

ransomware group
0 victims

farattack

ransomware group
0 victims

fargo

ransomware group

Fargo is a ransomware variant that surfaced in 2022, primarily targeting Microsoft SQL Server (MSSQL) systems. Believed ...

0 victims

faust

ransomware group

Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since ...

0 victims

fivehands

ransomware groupRaaS

FiveHands is a ransomware family first observed in January 2021, believed to be a successor to the HelloKitty ransomware...

0 victims

fletchen

ransomware group
ACTIVE
0 victimsSince Jan 24, 2026

freeworld

ransomware group

FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomw...

0 victims

frozen

ransomware group
0 victims

fsociety

ransomware groupRaaS
INACTIVE

This group is also known by their malware name, FLOCKER. <br/>FSociety is a modern Ransomware-as-a-Service (RaaS) operat...

0 victimsSince Aug 29, 2025

fsteam

ransomware group
INACTIVE

New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware ...

0 victimsSince Jan 7, 2023

ftcode

ransomware group
INACTIVE

FTCode is a ransomware family first observed in 2013 as a PowerShell-based threat and later resurfaced in September 2019...

0 victimsSince Dec 9, 2024

fusion

ransomware group
0 victims

gangbang

ransomware group
0 victims

gazprom

ransomware group
0 victims

ghost

ransomware group

aka Cring / Ghost (Cring) <br/> <br/>Beginning early 2021, Ghost actors began attacking victims whose internet facing se...

0 victims

global3

ransomware group
0 victims

globe

ransomware group

Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allow...

0 victims

globeimposter

ransomware group

GlobeImposter is a ransomware family that first appeared in mid-2017, designed to mimic the appearance and naming conven...

0 victims

good day

ransomware group
INACTIVE

Good Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to it...

0 victimsSince Jun 24, 2024

grep

ransomware group
0 victimsSince Apr 13, 2026

grinch

ransomware group
0 victims

gwisin

ransomware group
INACTIVE

Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South K...

0 victimsSince Dec 9, 2024

haron

ransomware group
INACTIVE

Haron is a ransomware group that emerged in July 2021 and is believed to share operational similarities with the Avaddon...

0 victims

hddcryptor

ransomware group
0 victims

hellokitty

ransomware group
INACTIVE

HelloKitty is a ransomware family first observed in November 2020, named after a string found in its binary. It operates...

0 victims

help_restoremydata

ransomware group
INACTIVE

Help_restoremydata is a ransomware variant identified around late 2024/early 2025, notable for appending the .help_resto...

0 victimsSince Jan 27, 2025

hermes

ransomware groupRaaS

Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group op...

0 victims

himalayaa

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

hiveleak

ransomware group
INACTIVE
0 victims

holyghost

ransomware group
INACTIVE

HolyGhost is a ransomware group first publicly reported in July 2022, believed to be operated by a North Korean state-sp...

0 victims

homeland

ransomware group
0 victimsSince Mar 10, 2026

hotarus

ransomware group
INACTIVE

Hotarus is a ransomware and data extortion group first observed in March 2021, believed to be linked to threat actors of...

0 victims

hyflock

ransomware group
INACTIVE
0 victimsSince Apr 7, 2026

icarus

ransomware group
ACTIVE
0 victims

inpivx

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

insane ransomware

ransomware group
INACTIVE

Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public thr...

0 victimsSince Feb 12, 2024

invaderx

ransomware group
0 victims

ironchain

ransomware group
INACTIVE
0 victimsSince Feb 22, 2026

izis

ransomware group
INACTIVE
0 victimsSince Sep 13, 2025

j group

ransomware group
0 victimsSince Dec 15, 2025

jaff

ransomware group
INACTIVE

Jaff is a ransomware family first discovered in May 2017, notable for its distribution via large-scale spam campaigns op...

0 victimsSince Dec 10, 2024

jigsaw

ransomware group

Jigsaw is a ransomware family first observed in April 2016, notorious for its psychological intimidation tactics. It enc...

0 victims

jo of satan

ransomware group
INACTIVE
0 victims

jsworm

ransomware group

JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolut...

0 victims

justice_blade

ransomware group
0 victimsSince Apr 13, 2026

kasseika

ransomware group

Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatt...

0 victims

kawa

ransomware group
0 victimsSince Aug 16, 2025

key group

ransomware group
0 victims

keyholder

ransomware group
0 victims

killada

ransomware group
0 victimsSince Apr 13, 2026

kirov

ransomware group
0 victims

krypt

ransomware group
INACTIVE
0 victimsSince Sep 28, 2025

kryptina

ransomware group
0 victims

kryptos

ransomware groupRaaS
INACTIVE
0 victimsSince Dec 11, 2025

kuiper

ransomware group

Kuiper is a relatively new ransomware strain first analyzed in April 2023, notable for being written in Rust and designe...

0 victims

kuza

ransomware group
0 victims

la_piovra

ransomware group
INACTIVE

ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)

0 victimsSince Jun 14, 2023

lambda

ransomware group
INACTIVE
0 victims

lamialocker

ransomware group
0 victims

late.lol

ransomware group

Affiliates: <br/>@Mr.C <br/>@Empathy <br/>@jayze <br/>@Widow <br/>@Memory <br/> <br/>

0 victimsSince Apr 13, 2026

lcryptorx

ransomware group
INACTIVE
0 victimsSince May 9, 2025

leak bazaar

ransomware group
0 victims

leakeddata

ransomware group
0 victimsSince Feb 24, 2026

lechiffre

ransomware group
0 victims

lilith

ransomware group
INACTIVE
0 victims

lockbit3_fs

ransomware group
ACTIVE
0 victims

lockbit4

ransomware groupRaaS
0 victimsSince Jun 3, 2025

lockergoga

ransomware group
0 victims

locus

ransomware group
INACTIVE
0 victimsSince Jan 1, 2026

loki

ransomware group
INACTIVE
0 victimsSince Apr 12, 2026

lokilocker

ransomware group
0 victims

lolnek

ransomware group
INACTIVE
0 victims

lsd

ransomware group
0 victimsSince Apr 13, 2026

luckbit

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

lulzsec muslims

ransomware group
INACTIVE
0 victimsSince Jun 4, 2025

lynxr

ransomware group
0 victims

lyrix

ransomware group
INACTIVE
0 victimsSince Dec 23, 2025

macaw

ransomware group
INACTIVE
0 victims

madcat

ransomware group
INACTIVE
0 victimsSince Nov 27, 2023

mailto

ransomware group
0 victims

makop

ransomware group
0 victims

malphas

ransomware group
0 victims

mamona

ransomware groupRaaS
INACTIVE
0 victimsSince Mar 19, 2025

mario esxi

ransomware group
0 victims

maui

ransomware group
INACTIVE
0 victims

mbc

ransomware group
INACTIVE
0 victims

mcafee

ransomware group
0 victims

mcrypt2019

ransomware group
0 victims

megacode

ransomware group
0 victims

megacortex

ransomware group
0 victims

megazord

ransomware group
0 victims

mespinoza

ransomware groupRecovery risk
0 victims

miga

ransomware group
INACTIVE

#MakeIsraelGreatAgain

0 victimsSince Sep 29, 2025

miliphen

ransomware group
0 victims

mimic

ransomware group
0 victims

mimic-guram

ransomware groupRaaS

Mimic v.10 Ransomware-as-a-Service (RaaS). The malware is designed to target various operating systems (Windows, ESXi, N...

0 victims

mnt6

ransomware group
ACTIVE
0 victims

moisha

ransomware group
INACTIVE
0 victims

monolock

ransomware group
INACTIVE
0 victimsSince Jan 23, 2026

monte

ransomware group
INACTIVE
0 victimsSince Sep 28, 2022

mortalkombat

ransomware group
0 victims

muliaka

ransomware group
0 victims

mydata

ransomware group
INACTIVE
0 victimsSince Dec 9, 2024

mydecryptor

ransomware group
INACTIVE
0 victims

n3tworm

ransomware group
INACTIVE
0 victims

naga

ransomware group
INACTIVE
0 victimsSince Jun 2, 2025

nblock

ransomware group
INACTIVE
0 victimsSince Apr 10, 2026

nemesis

ransomware group
INACTIVE
0 victimsSince Aug 13, 2025

nemty

ransomware group
INACTIVE

Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed throug...

0 victims

nevada

ransomware group
INACTIVE
0 victims

nvrmre

ransomware group
INACTIVE

AKA Lemon

0 victimsSince Mar 6, 2025

obsidian orb

ransomware group
0 victims

oceans

ransomware group
0 victims

octovillan

ransomware group
INACTIVE
0 victimsSince Sep 18, 2025

offwhite

ransomware group
0 victims

onepercent

ransomware group
INACTIVE
0 victims

osyolorz collective

ransomware group
0 victimsSince Apr 13, 2026

ox thief

ransomware group
INACTIVE
0 victimsSince Mar 13, 2025

paradise

ransomware group
0 victims

paradise2

ransomware group
0 victims

Payday

ransomware group
ACTIVE
0 victims

petya

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

pewcrypt

ransomware group
0 victims

phalcon

ransomware group
0 victims

phantom

ransomware group
0 victims

phobos

ransomware groupRecovery risk
0 victims

phoenixcryptolocker

ransomware group
INACTIVE
0 victims

piratelock

ransomware groupRaaS
0 victims

playboy

ransomware group
INACTIVE
0 victimsSince Dec 31, 2024

polyvice

ransomware group
0 victims

prinz eugen

ransomware group
ACTIVE
0 victims

prometheus

ransomware group
INACTIVE

Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.

0 victims

promptlock

ransomware group
INACTIVE

First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama ...

0 victims

proton

ransomware group
0 victims

providence

ransomware group
0 victims

proxima

ransomware group
0 victims

punisher

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

pyrx

ransomware group
INACTIVE
0 victimsSince Apr 17, 2025

qilin-securotrop

ransomware group
0 victimsSince Apr 13, 2026

qlocker

ransomware group
INACTIVE

login page, no posts

0 victims

quicklock

ransomware group
INACTIVE
0 victimsSince Apr 13, 2026

quoter

ransomware group
0 victims

ra group

ransomware group
INACTIVE
0 victimsSince Aug 25, 2023

rabbithole

ransomware group
INACTIVE
0 victimsSince Dec 31, 2024

radiant group

ransomware group
INACTIVE
0 victimsSince Nov 12, 2025

RAMP

ransomware group
INACTIVE
0 victims

ranion

ransomware groupRaaS
INACTIVE
0 victims

ransom corp

ransomware group
INACTIVE
0 victims

ransombay

ransomware group
INACTIVE

Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative

0 victimsSince May 13, 2025

ransomcartel

ransomware group
INACTIVE
0 victims

ransomedvc2

ransomware groupRaaS
INACTIVE

RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.

0 victimsSince Mar 27, 2026

ransomware blog

ransomware group
INACTIVE

Also known as MedusaLocker

0 victimsSince Nov 18, 2025

ranzy

ransomware group
INACTIVE
0 victims

rapture

ransomware group
0 victims

relic

ransomware group
INACTIVE
0 victimsSince Jun 3, 2023

reynolds

ransomware group
ACTIVE
0 victimsSince Feb 13, 2026

risen

ransomware group
INACTIVE

Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malwa...

0 victimsSince Jun 5, 2024

robbing hood

ransomware group
INACTIVE
0 victimsSince Jun 15, 2025

robbinhood

ransomware group
0 victims

root

ransomware group
0 victims

rransom

ransomware group
INACTIVE
0 victims

rtm locker

ransomware group
INACTIVE
0 victimsSince Nov 5, 2025

rustylocker

ransomware groupRaaS
INACTIVE
0 victimsSince Dec 10, 2025

samas

ransomware group
0 victims

satancd

ransomware group
0 victimsSince Apr 13, 2026

scarab

ransomware group
0 victims

scattered lapsus$ hunters

ransomware group
0 victimsSince Apr 13, 2026

schoolboys

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

shade

ransomware group
INACTIVE
0 victimsSince Dec 12, 2024

shadow

ransomware group
INACTIVE
0 victims

sharpboys

ransomware group
0 victimsSince Jul 8, 2025

ShinySp1d3r

ransomware group
INACTIVE

Likely associated with the cybercrime group BlingLibra (ShinyHunters)

0 victims

sicari

ransomware group
INACTIVE
0 victimsSince Jan 19, 2026

sifrecikis

ransomware group
INACTIVE
0 victimsSince Jul 8, 2025

silent ransom

ransomware group
0 victims

skira team

ransomware group
0 victimsSince Nov 29, 2025

slam

ransomware group
INACTIVE
0 victimsSince Jun 4, 2025

soleenya

ransomware group
INACTIVE
0 victimsSince Jun 15, 2025

solidbit

ransomware group
INACTIVE

Ransomware, written in .NET.

0 victims

spectre

ransomware group
0 victims

sphinx

ransomware group
INACTIVE
0 victimsSince Sep 2, 2025

spirigatito

ransomware group
0 victims

spring

ransomware group
0 victims

spy corporate

ransomware group
ACTIVE
0 victims

sugar

ransomware group
INACTIVE
0 victims

sundawn

ransomware group
0 victims

superblack

ransomware group
0 victims

synack

ransomware group
INACTIVE
0 victims

synapse

ransomware group
INACTIVE
0 victimsSince Jun 17, 2024

targetcompany

ransomware group
0 victims

taronis

ransomware group
0 victims

team underground

ransomware group
0 victimsSince Sep 30, 2023

telegram

ransomware group
0 victims

teslacrypt

ransomware group
0 victims

thanos

ransomware group
INACTIVE
0 victims

thegreenbloodgroup

ransomware group
ACTIVE
0 victimsSince Feb 13, 2026

thor

ransomware group
INACTIVE
0 victimsSince Jun 6, 2025

threatmarket

ransomware group
0 victimsSince Apr 13, 2026

thunder x

ransomware group
0 victims

thundercrypt

ransomware group
0 victims

TiMc

ransomware group
ACTIVE
0 victims

tommyleaks

ransomware group
INACTIVE
0 victimsSince Dec 10, 2024

tooda

ransomware group

Members: <br/>Eco <br/>Ego <br/>emo <br/>elo <br/>user <br/>Dante <br/>Sevy

0 victimsSince Apr 13, 2026

toxic

ransomware group
INACTIVE
0 victimsSince Feb 22, 2025

triple x

ransomware group
ACTIVE
0 victims

triplem

ransomware group
0 victims

tssxx25

ransomware group
INACTIVE
0 victimsSince Aug 28, 2025

tuborg

ransomware group
0 victims

turkish crypter

ransomware group
INACTIVE
0 victimsSince Apr 7, 2026

tycoon

ransomware group
0 victims

u-bomb

ransomware group
INACTIVE
0 victimsSince Dec 31, 2024

unknown

ransomware group
INACTIVE
0 victims

unsafeleak

ransomware group
INACTIVE
0 victims

v is vendetta

ransomware group
0 victimsSince Feb 8, 2024

vandev

ransomware group
0 victims

vasalocker

ransomware group
0 victims

vaultcrypt

ransomware group
INACTIVE
0 victimsSince Feb 27, 2025

vegalocker

ransomware group
0 victims

vfokx

ransomware group
INACTIVE
0 victims

vsop

ransomware group
INACTIVE

aka Onix/Onyx

0 victimsSince Jan 2, 2023

vulcan

ransomware groupRaaS
0 victimsSince Apr 13, 2026

vurten

ransomware group
0 victims

w3crypto

ransomware group
INACTIVE
0 victimsSince Jun 16, 2025

waissbein

ransomware group
0 victimsSince Apr 9, 2026

weaxor

ransomware group
0 victimsSince Dec 18, 2024

white lock

ransomware group
INACTIVE
0 victimsSince Nov 4, 2025

wiki ransomware

ransomware group
0 victims

wikileaksv2

ransomware group

Group is connected to Qilin.

0 victimsSince Jul 9, 2024

wiper leak

ransomware group
0 victimsSince Apr 13, 2026

x001xs

ransomware group
INACTIVE
0 victims

xelera

ransomware group
0 victims

xinof

ransomware group
INACTIVE
0 victims

xleaks

ransomware group
INACTIVE
0 victimsSince Oct 12, 2025

xollam

ransomware group
0 victims

yashma

ransomware group
0 victims

ymir

ransomware group
0 victims

zeon

ransomware group
INACTIVE
0 victims

zeoticus

ransomware group
0 victims

zeoticus2

ransomware group
0 victims

zero tolerance gang (ztg)

ransomware group
INACTIVE
0 victimsSince May 20, 2024

zerolockersec

ransomware group
ACTIVE
0 victimsSince Feb 13, 2026

zerotolerance

ransomware group
INACTIVE
0 victimsSince Dec 31, 2024

zeta leaks

ransomware group
INACTIVE
0 victimsSince Aug 7, 2025

zetarink

ransomware group
0 victimsSince Apr 13, 2026

zircon

ransomware group
INACTIVE
0 victimsSince Oct 30, 2025

zixer2

ransomware group
0 victims

zola

ransomware group
0 victims