One moment, our live darknet feed is loading
Once the feed arrives, the most active ransomware groups appear here.
By default this layer shows potential victims from the last 3 days. Use search to query the stored history.
Once the feed arrives, the most active ransomware groups appear here.
Browse the locally documented actors, aliases and available intelligence. Profiles distinguish documented findings from research gaps.
401 actors found
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Ransomware.live source assessment: The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly selected organizations.
Added to the source registry: 2026-01-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
0day Syndicate was added to Ransomware.live on 2026-05-28. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-05-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: 0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.
Added to the source registry: 2022-07-14 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: ThreeAM, 3AM ransomware
3AM is a ransomware family that stood out as an alternative to failing other payloads, with post-exploitation via Cobalt Strike, privilege use and classic impact preparation.
Added to the source registry: 2023-09-14 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: 8Base ransomware
8Base is a double-extortion group with strong activity since 2023, often discussed in relation to Phobos-like ransomware and RansomHouse-like communication.
Added to the source registry: 2023-05-23 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily targeting Saudi Arabian government institutions for geopolitical reasons related to Saudi-Israeli normalization, using destructive wiper malware and data leak tactics rather than financial ransomware.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Abyss, Abyss Locker ransomware
Abyss Locker shows how Windows and Linux/ESXi ransomware can jointly affect business continuity.
Added to the source registry: 2023-03-21 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files and demanding Bitcoin ransom via a Tor-based portal, operated by a lone actor or small closed group with no evidence of an affiliate model.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: "aGl0bGVyCg" (Base64 for "hitler") is a reference to the Hitler-Ransomware (2016), a German-origin proof-of-concept that displayed a Hitler image, did not actually encrypt files, and demanded a 25-euro Vodafone card payment; assessed as an amateur test project rather than a serious criminal operation.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid.
Added to the source registry: 2026-03-03 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Akira ransomware, Akira RaaS
Akira is an active ransomware and extortion operation in which remote access, valid accounts, virtualisation, backups and data theft are central.
Added to the source registry: 2023-04-26 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Ako ransomware, Ako Ransomware
AKO is historically relevant as a double-extortion group from the early leak-site period.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: ⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified.
Added to the source registry: 2026-03-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin panel, ransomware executable, and decryption key generator, lowering the barrier for entry-level cybercriminals using double-extortion tactics.
Added to the source registry: 2024-01-24 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: ALPHV, BlackCat, Noberus
ALPHV is the feed name for BlackCat/Noberus: a Rust-based RaaS operation known for double extortion, affiliates and FBI/CISA/DOJ context.
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates a flexible revenue split model and an optional destructive "wipe mode" alongside standard encryption.
Added to the source registry: 2025-02-25 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or sell stolen information rather than encrypting files, targeting technology, healthcare, manufacturing, telecom, and government sectors across multiple countries.
Added to the source registry: 2024-04-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the group reportedly self-proclaimed as an APT, which stands for 'Advanced Persistent Threat' in the cybersecurity field. According to research, much of the available information about the aforementioned group came from another ransomware group known as LockBit.
Added to the source registry: 2024-04-22 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aptlock was added to Ransomware.live on 2025-01-01. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2025-01-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.
Added to the source registry: 2024-05-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, healthcare, energy, and telecom sectors, with approximately 13 claimed victims tracked via a TOR-based leak site.
Added to the source registry: 2024-11-27 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband provider WideOpenWest (WOW!), operating a three-phase ransom/sale/leak extortion model primarily focused on telecom and internet service providers.
Added to the source registry: 2025-03-25 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via a TOR site and Telegram rather than deploying file-encrypting ransomware, targeting government, education, and banking sectors globally including Iranian government entities.
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access and demanding ransoms up to $1 million, attributed to the Chinese state-linked threat actor BRONZE STARLIGHT.
Added to the source registry: 2021-12-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and Southeast Asia across technology and manufacturing sectors, operating a data leak site consistent with double-extortion methodology.
Added to the source registry: 2026-04-08 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.
Added to the source registry: 2026-04-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Avaddon ransomware
Avaddon was a RaaS operation using double extortion and DDoS pressure; researchers published technical analysis and decryption context.
Added to the source registry: 2021-02-01 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Avos, AvosLocker alias
Avos is a short feed alias that usually points to AvosLocker and should remain clickable for feed history and search.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: AvosLocker ransomware, Avos
AvosLocker is a RaaS operation that FBI/CISA says affects Windows, Linux and VMware ESXi, abuses legitimate remote administration tools and uses exfiltration-based extortion.
Added to the source registry: 2021-06-13 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documentation and no publicly catalogued victims, tools, or TTPs in major threat intelligence databases.
Added to the source registry: 2026-01-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: AztroTeam is a ransomware group with very limited public documentation and no confirmed victims, listed as offline on ransomware tracking platforms.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Babuk Locker, Babuk ransomware
Babuk is historically important because of leaked source code, ESXi/Linux impact and reuse of code in later ransomware variants.
Added to the source registry: 2020-10-25 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on forums, decided to impersonate Babuk Ransomware group. He launched a blog where he claimed multiple public breaches from BreachForums as ransomware attacks
Added to the source registry: 2025-01-27 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduck extension to encrypted files, distinct from the better-known Babuk group.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Barracuda was added to Ransomware.live on 2026-08-06. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.
Added to the source registry: 2025-07-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Added to the source registry: 2025-11-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
Added to the source registry: 2025-04-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: BianLian ransomware, BianLian extortion
BianLian is a data-extortion group that, according to CISA/FBI/ACSC, shifted from ransomware to primarily exfiltration-based extortion.
Added to the source registry: 2022-07-14 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: BlackBasta, Black Basta ransomware
Black Basta is a professional ransomware operation with strong focus on enterprise impact, data theft, lateral movement and disruption of recovery.
Added to the source registry: 2022-04-26 · Source snapshot: 2026-09-15
Loading stored claims…
Black X was added to Ransomware.live on 2026-06-02. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-02 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: BlackByte ransomware
BlackByte is a ransomware group linked by FBI/USSS to attacks on US critical infrastructure sectors and known IOCs around encryption and ransom notes.
Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: ALPHV, BlackCat, Noberus
BlackCat/ALPHV is a mature RaaS profile that combined affiliate operations, social engineering, data theft, encryption and aggressive extortion.
Loading stored claims…
Blackfield was added to Ransomware.live on 2026-06-29. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: BlackLock ransomware
BlackLock shows how young ransomware brands can appear quickly in feeds and mainly build pressure through double-extortion claims.
Added to the source registry: 2025-05-16 · Source snapshot: 2026-09-15
Loading stored claims…
BlackLocks was added to Ransomware.live on 2026-09-04. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-09-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: BlackMatter ransomware
BlackMatter was a ransomware group that CISA/FBI/NSA linked to critical infrastructure attacks and TTPs around SMB, LDAP, PowerShell and encryption of shared resources.
Added to the source registry: 2021-09-08 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.
Added to the source registry: 2025-08-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.
Added to the source registry: 2024-02-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: BlackShadow ransomware
BlackShadow is mainly known from Israel-focused ransomware and data-leak claims and should therefore be read with geopolitical context.
Added to the source registry: 2021-12-18 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: BlackShrantac is a ransomware group that emerged in late 2025, targeting organizations in manufacturing, financial services, technology, and the public sector globally, employing double-extortion combined with living-off-the-land techniques to weaponize legitimate tools and disable defenses before encrypting files.
Added to the source registry: 2025-09-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Royal, Royal ransomware, BlackSuit ransomware
BlackSuit is the successor or rebrand line around Royal and remains relevant through enterprise attacks, callback phishing, RDP, data exfiltration and high impact on healthcare and critical sectors.
Added to the source registry: 2023-06-12 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.
Added to the source registry: 2021-12-30 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and targeting healthcare organizations, with known victims including Minidoka Memorial Hospital in Idaho.
Added to the source registry: 2026-04-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.
Added to the source registry: 2024-12-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum
Added to the source registry: 2025-08-19 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/Curve25519 encryption for fast file locking on Windows hosts, with code sharing significant overlap with Conti v2/v3 and Babuk, attributed with high confidence to Russian-origin threat actors.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
BlueWhale was added to Ransomware.live on 2026-08-14. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-14 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Bolt Team was added to Ransomware.live on 2026-08-01. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going offline, with very little public documentation about their tactics, targets, or tooling.
Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Booba
Added to the source registry: 2026-07-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.
Added to the source registry: 2025-07-31 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Brain Cipher ransomware
Brain Cipher became publicly visible through the attack on Indonesian national data-centre services and claims around LockBit-like code.
Added to the source registry: 2024-07-01 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.
Added to the source registry: 2026-02-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.
Added to the source registry: 2025-11-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Cactus ransomware
Cactus is a known double-extortion group notable for VPN/edge access, encryptor self-protection and attacks where data exfiltration and recovery disruption are central.
Added to the source registry: 2023-07-20 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.
Added to the source registry: 2025-08-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Chaos ransomware, Chaos RaaS
Chaos is described in recent reporting as a possible successor or splinter of BlackSuit/Royal that continues double extortion.
Added to the source registry: 2025-03-31 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks against VMware ESXi servers, running a double-extortion leak site with four documented victims.
Added to the source registry: 2022-05-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: ChileLocker (also known as ARCrypter) first appeared in August 2022 after attacking a Chilean government agency and quickly expanded globally, appending a ".crypt" extension to encrypted files and recruiting affiliates under a RaaS model on criminal forums.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance.
Added to the source registry: 2024-11-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Cicada3301 ransomware, Cicada 3301
Cicada3301 is a modern Rust-based ransomware group with Linux/ESXi-like impact and public discussion about overlap with ALPHV-like techniques.
Added to the source registry: 2024-06-20 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion.
Added to the source registry: 2023-09-14 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeting technology, business services, and logistics companies across the US, China, Vietnam, India, and UAE, with at least 6 claimed victims.
Added to the source registry: 2026-02-23 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Clop, Cl0p, TA505 linked CL0P
CL0P is especially relevant as a data-extortion group that abuses vulnerabilities in data-rich enterprise and file-transfer platforms at scale.
Added to the source registry: 2020-03-13 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Cloak ransomware
Cloak is mainly known through leak-site claims and is therefore useful as a data-focused claim-triage profile.
Added to the source registry: 2023-08-24 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company. CMD operates on a global scale recognizing the critical importance of timeliness and confidentiality.
Added to the source registry: 2026-05-02 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve system encryption or operational disruption.
Added to the source registry: 2025-09-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fonctionne pas sur Linux. Tableau de vitcimes et récupération de données possible depuis votre espace abonné.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Conti ransomware
Conti was a large RaaS operation that CISA/FBI/NSA/USSS linked to TrickBot, IcedID, Cobalt Strike, malicious Word attachments and hundreds of attacks.
Added to the source registry: 2020-07-31 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: CoomingProject is a ransomware group that emerged around 2021 and operated a double-extortion scheme with multiple Tor-based leak sites; six members were identified by French authorities in February 2022, after which the group's infrastructure went offline.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
Added to the source registry: 2025-03-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.
Added to the source registry: 2023-04-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: CRPxO is actively recruiting affiliates, offering: 🔹 70% revenue share 🔹 XMR/BTC payouts 🔹 Claimed payouts within 24 hours 🔹 $333 one-time affiliate access
Added to the source registry: 2026-07-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payload with blockchain-based (Internet Computer Protocol) negotiation infrastructure to resist law enforcement takedowns and offering affiliates a 90/10 revenue split.
Added to the source registry: 2026-01-19 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: CryLock ransomware
CryLock appears historically as a ransomware family and is mainly useful for retro-hunting and older incidents.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology, and operational model remain poorly documented in open sources.
Added to the source registry: 2021-12-18 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to encrypted files and whose data leak site copied 8Base's source code, listing approximately 8 victims as of September 2023.
Added to the source registry: 2023-09-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: CryptNet ransomware
CryptNet is a smaller double-extortion name that is mainly relevant for historical feed and claim triage.
Added to the source registry: 2023-04-19 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate.
Added to the source registry: 2025-04-08 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Cuba ransomware, Cuba ransomware actors
Cuba ransomware actors use vulnerabilities, phishing, compromised credentials, RDP and Hancitor-related access to perform data extortion and encryption.
Added to the source registry: 2021-02-03 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Cyclops emerged in May 2023 as a cross-platform RaaS operation targeting Windows, macOS, and Linux systems; it rebranded as "Knight" in August 2023 and its codebase was ultimately sold, with affiliates largely migrating to RansomHub.
Added to the source registry: 2023-07-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion
Added to the source registry: 2026-07-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: D4rk4rmy is a ransomware and data extortion group active since at least 2025, targeting financial services, hospitality, technology, and logistics sectors, operating a RaaS model with notable claimed victims including the Monte Carlo casino resort.
Added to the source registry: 2025-07-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Dagon Locker is a ransomware strain that first appeared in early 2023, evolved from the MountLocker/Quantum ransomware lineage, and uses IcedID as an initial access vector before deploying double-extortion attacks with ChaCha20+RSA-2048 encryption.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Daixin, Daixin Team ransomware
Daixin Team focuses, according to CISA/FBI/HHS, mainly on healthcare and public health, using VPN access, credential abuse, RDP/SSH, data exfiltration and ransomware.
Added to the source registry: 2022-08-03 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.
Added to the source registry: 2024-04-25 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Dark Angels ransomware, Dunghill Leak
Dark Angels is known for highly targeted big-game extortion and sometimes quiet negotiations without broad publicity.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: DarkPower ransomware
Dark Power is a smaller double-extortion name in ransomware feeds and mainly requires careful claim validation.
Added to the source registry: 2023-03-11 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortion model (stealing sensitive data before encrypting local systems and threatening to leak it on their dark web portal).
Added to the source registry: 2026-08-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: DarkBit ransomware
DarkBit is mainly known for politically motivated or hacktivist-style ransomware claims against Israeli targets.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransomware groups and hacking forums, with 39 known victim organizations; it operates more as a data resale market than a traditional ransomware operator.
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
DarkMatter was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: DarkRace ransomware
DarkRace is a smaller ransomware feed name with limited public technical detail but useful claim-triage value.
Added to the source registry: 2023-05-31 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: DarkSide ransomware
DarkSide is the ransomware group confirmed by the FBI in the Colonial Pipeline attack and remains a core case for IT/OT segmentation and business disruption.
Added to the source registry: 2020-08-01 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: DarkVault is a data-exfiltration and double-extortion group first identified in late 2023, targeting medium-to-large organizations in finance, professional services, legal, and technology sectors across Europe, the UK, and North America, with a suspected connection to LockBit.
Added to the source registry: 2024-04-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.
Added to the source registry: 2025-05-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "CrystalPartnership RaaS," offering a Windows-focused ransomware toolkit with hybrid RSA-4096 encryption, open dark web registration, and an innovative split-payment mechanism to build affiliate trust.
Added to the source registry: 2026-01-14 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited public threat intelligence exists on this group's tools, TTPs, or origins.
Added to the source registry: 2022-12-02 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Deadlock was added to Ransomware.live on 2026-06-15. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.
Added to the source registry: 2025-08-30 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Former RansomHub and INC Ransom affiliate.
Added to the source registry: 2025-04-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Diavol ransomware
Diavol has been linked in public CTI to TrickBot-ecosystem-style methods and fast ransomware deployment.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
Added to the source registry: 2025-05-22 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: This is not a ransomware group but a data broker
Added to the source registry: 2024-04-19 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Donex ransomware
Donex is known mainly as a modern extortion name through leak-site claims and limited technical reporting.
Added to the source registry: 2024-03-08 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.
Added to the source registry: 2022-08-24 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Direct Extortion Double Extortion
Added to the source registry: 2026-07-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: DoppelPaymer ransomware, DopplePaymer
DoppelPaymer was a double-extortion ransomware operation known for leak-site pressure and attacks on large organisations and public services.
Added to the source registry: 2019-05-25 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: DragonForce ransomware
DragonForce is an active ransomware and extortion operation that stands out by affiliate action, cartel-like positioning and technically creative abuse of normal business communications.
Added to the source registry: 2023-12-13 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a compact 50KB file size, ultra-fast encryption speed, and a builder tool that allows users to personalize ransomware configurations.
Added to the source registry: 2024-12-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Dread is a ransomware group that appears in tracking databases but has no publicly documented attacks or confirmed TTPs from major security vendors.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Dunghill Leak, Dunghill
Dunghill especially if leak-site/extortion name appears and therefore has value for data breach claim
Added to the source registry: 2023-04-10 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Suspicious group. We did not manage to confirm any victims.
Added to the source registry: 2026-08-20 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: eCh0raix, QNAPCrypt
eCh0raix specifically NAS- devices such as QNAP and Synology hit storage layers and thereby underlined ransomware target
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Eclipse was added to Ransomware.live on 2026-08-11. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Eldorado ransomware
Eldorado is a modern RaaS operation with Windows- and Linux variants and Go-based payload context in public CTI
Added to the source registry: 2024-06-06 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Embargo ransomware
Embargo is a modern Rust-based ransomware family that is paired in public CTI to double extortion and tooling like MDeployer/MDeleter
Added to the source registry: 2024-04-21 · Source snapshot: 2026-09-15
Loading stored claims…
emperador was added to Ransomware.live on 2026-08-12. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
EndZone is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Entropy ransomware
Entropy was linked by Sophos to attacks where Dridex/IcedID-like access preceded ransomware
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly documented attacks or operational details.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: ESXiArgs ransomware
vulnerable VMware ESXi systems could be hit massively and CISA recovery guide published
Added to the source registry: 2023-02-03 · Source snapshot: 2026-09-15
Loading stored claims…
Ethics was added to Ransomware.live on 2026-08-12. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Everest ransomware, Everest extortion
Everest developed from ransomware/extortion to broader data extortion and initial access-broker-like activity.
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Only exfiltration
Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targeting victims via bulk data exfiltration followed by public naming-and-shaming, with known victims including a Brazilian agro-industrial firm and a US county appraisal district.
Added to the source registry: 2026-03-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Falcon was added to Ransomware.live on 2026-08-28. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Fletchen is primarily documented as a sophisticated infostealer-as-a-service written in Rust, targeting browser credentials, cryptocurrency wallets, and financial data, used by groups including Hunters International; its developer also advertises ransomware services on underground forums.
Added to the source registry: 2026-01-03 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via phishing, compromised RDP, and exploit kits using a double extortion model, and observed collaborating with FunkSec.
Added to the source registry: 2024-05-03 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Fog ransomware
Fog is a ransomware variant that Arctic Wolf saw in 2024 in U.S. education and recreation sectors, with later reporting around SonicWall SSL VPN- activity.
Added to the source registry: 2024-07-16 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Frag is a ransomware group that emerged in late 2024, exploiting a critical Veeam Backup & Replication vulnerability (CVE-2024-40711) to compromise targets in industrial sectors, with blockchain analysis linking it to a shared wallet cluster with the Akira group.
Added to the source registry: 2025-03-24 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukrainian government websites — including sites offering surrender guidance to Russian troops — blending cybercrime with apparent state-aligned political objectives.
Added to the source registry: 2022-12-31 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware or extortion group
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.
Added to the source registry: 2026-05-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: FunkSec ransomware
FunkSec is a young ransomware and extortion name that stands out by fast claim growth, low ransoms, hacktivist tone and claims around AI-supported tooling.
Added to the source registry: 2024-12-04 · Source snapshot: 2026-09-15
Loading stored claims…
Galago is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Gammax was added to Ransomware.live on 2026-07-30. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-07-30 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Our team members are from different countries and we are not interested in anything else, we are only interested in dollars. We do not allow CIS, Cuba, North Korea and China to be targeted.
Added to the source registry: 2025-01-24 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, focusing heavily on data exfiltration and public leaking.
Added to the source registry: 2025-10-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.
Added to the source registry: 2025-06-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: GSG
Global Secret Group was added to Ransomware.live on 2026-07-26. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
GodDamn ransomwhere was added to Ransomware.live on 2026-07-26. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Grief ransomware, PayOrGrief
Grief historically is considered to be DoppelPaymer-like extortion operation with leak site publication
Added to the source registry: 2021-05-26 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Groove ransomware
Groove especially if ransomware/ecosystem name around former Babuk- or RAMP--like context occurred and less as a highly technically documented family
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and manufacturing sectors across Japan, Egypt, Panama, Italy, and Argentina, deploying separate Windows and Linux variants with a strict five-day payment deadline.
Added to the source registry: 2025-04-23 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension.
Added to the source registry: 2020-12-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Handala Hack Team, Handala ransomware
Handala especially if politically motivated hacktivist extortion name is used and therefore must be read differently than purely financial RaaS
Added to the source registry: 2024-05-26 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Helix was added to Ransomware.live on 2026-08-07. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: HellCat ransomware
HellCat as modern extortion name appears in feeds and is especially relevant via claims and data breach printing
Added to the source registry: 2024-10-25 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.
Added to the source registry: 2024-08-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: HelloGookie is a rebrand of the HelloKitty ransomware group announced in April 2024, releasing previously stolen data from CD Projekt Red and Cisco; HelloKitty/HelloGookie has been active since 2020 with its highest-profile attack being the 2021 breach of CD Projekt Red.
Added to the source registry: 2024-04-19 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: HelloKitty ransomware, FiveHands
HelloKitty historically known by attacks on large organizations and later source code leaks, with server and ESXi risk
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Hive ransomware
Hive was a large RaaS operation with broad sector impact, known for phishing, RDP/VPN, credential theft, log removal, data steal and double extortion.
Added to the source registry: 2021-08-14 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: HolyGhost ransomware, DEV-0530
Microsoft HolyGhost paired to DEV-0530 and North Korean cyberactivity, with attacks on small businesses and ransomware extortion
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Hotarus Corp is a ransomware group that came to attention in early 2021 after attacking Ecuador's Ministry of Finance and Banco Pichincha — the country's largest private bank — deploying PHP-based ransomware and claiming to have stolen tens of millions of customer records.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Hunters, Hunters International ransomware, World Leaks
Hunters International was an active double-extortion group that later was linked to shift towards World Leaks; the lessons remain relevant for data diary and affiliate transition.
Added to the source registry: 2023-10-20 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Archive without group name
Added to the source registry: 2026-08-20 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Icarus was added to Ransomware.live on 2026-05-05. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-05-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: IceFire ransomware
IceFire is known for Windows- and Linux variants and consequently explicitly touches server environments and Linux workloads
Added to the source registry: 2022-08-20 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.
Added to the source registry: 2025-05-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: INC, INC Ransomware
INC Ransom is an active extortion group that is mainly relevant due to data diode, leak site claims and attacks on organizations where continuity and sensitive data weigh heavily.
Added to the source registry: 2023-08-09 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Insane is a short-lived ransomware group that briefly surfaced in early 2024, claiming a single victim in Thailand before going quiet, with minimal documented activity or technical details available.
Added to the source registry: 2024-01-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient files and threatening public exposure rather than encrypting files — and avoiding former Soviet states, consistent with Russian-speaking cybercrime norms.
Added to the source registry: 2026-02-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Interlock ransomware
Interlock has become a rapidly mature ransomware group that combines social engineering, ClickFix/FileFix-like techniques, RATs, cloud tools and multi-platform encryption.
Added to the source registry: 2024-10-13 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 including FAI Aviation Group (Germany), operating primarily as a leak-site-centric extortion identity with limited public technical analysis.
Added to the source registry: 2025-05-02 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments.
Added to the source registry: 2024-11-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Karakurt Team, Karakurt Lair
Karakurt is a data extortion group that mainly pressures on stolen data and according to CISA/FBI/Treasury/FinCEN sometimes hits victims alongside other ransomware incidents.
Added to the source registry: 2022-12-11 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating double-extortion attacks against enterprises in healthcare, manufacturing, and technology; the group was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains. Platforms: Windows and Linux
Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
Added to the source registry: 2025-06-27 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations primarily in Southeast Asia, the Middle East, and Latin America, with notable claimed breaches including Dubai's Ports, Customs and Free Zone Corporation with 1.94 TB exfiltrated.
Added to the source registry: 2025-11-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: KelvinSecurity is a financially motivated hacking group active since at least 2015, primarily engaged in stealing and selling databases from telecommunications, healthcare, and political organizations worldwide, with notable breaches including Vodafone Italia and Frost & Sullivan; the group's leader was arrested by Spanish police.
Added to the source registry: 2022-04-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split, primarily targeting healthcare, financial services, and government sectors with over 250 documented victims as of late 2025.
Added to the source registry: 2024-03-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: KittyKatKrew is a newly emerged ransomware group first identified in early 2026, using both direct and double-extortion methods against US targets including the Arkansas State Crime Laboratory, operating under the alias KKK with Telegram and X/Twitter communication channels.
Added to the source registry: 2026-02-19 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Knight ransomware, Cyclops successor
Knight as successor/continue development of Cyclops-like ransomware was described and used phishing/stealer like access
Added to the source registry: 2023-09-06 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Kraken is a Russian-speaking ransomware group that emerged in February 2025, believed to have links to the HelloKitty operation, employing a RaaS model notable for a benchmarking step that measures victim machine speed to optimize encryption, and in September 2025 launched an underground criminal forum called "The Last Haven Board."
Added to the source registry: 2025-02-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.
Added to the source registry: 2026-04-03 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Kryptos is a small ransomware group first observed in October 2025, conducting simultaneous attacks across North America and Oceania on its debut day with a focus on professional, technical, and legal service sectors, with only 3 known documented victims.
Added to the source registry: 2025-10-08 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Kyber is a recently identified ransomware group using sophisticated hybrid encryption (AES-256-CTR with X25519 and Kyber1024), operating Tor-based communication channels and employing double-extortion with free partial decryption offered to build negotiation trust, discovered through underground forum monitoring in 2025.
Added to the source registry: 2025-10-08 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
L Group was added to Ransomware.live on 2026-08-07. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
Added to the source registry: 2023-06-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Romania, and Thailand across energy, pharmaceutical, and film sectors; it has not yet been confirmed as operating actual file-encrypting ransomware rather than pure data-theft extortion.
Added to the source registry: 2026-04-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: LAPSUS$, DEV-0537
the group showed how identity attacks, social engineering, MFA-fatigue and insider recruitment without classic ransomware can cause enormous damage
Added to the source registry: 2026-03-01 · Source snapshot: 2026-09-15
Loading stored claims…
LeakBazaar was added to Ransomware.live on 2026-05-10. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-05-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Leaknet is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims, notable for a 2017 operation targeting a Mandiant security researcher; the group focuses on stealing and publishing sensitive corporate data rather than deploying file-encrypting ransomware.
Added to the source registry: 2022-01-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Lilith ransomware
Lilith is a smaller double-extortion group with limited technical resources but clear leak-site value
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI, cloud, aerospace, and manufacturing companies — including H2O.ai — demanding ransoms as high as $15 million using double-extortion tactics.
Added to the source registry: 2025-02-19 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: LockBit 3.0, LockBit Black
LockBit is an industrialized ransomware-as-a-service ecosystem with large affiliate variation, broad victim base and strong publication pressure.
Added to the source registry: 2020-10-21 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: LockBit2, LockBit 2.0 ransomware
LockBit 2.0 professionalisation of LockBit as RaaS made visible with StealBit data exfiltration and broad affiliate effect
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: LockBit Black, LockBit 3.0
LockBit 3.0 a mature RaaS version was with bug bounty, fast adjustment and great global impact
Added to the source registry: 2022-06-29 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: LockBit5, LockBit 5.0
LockBit 5.0 especially if new or claimed version/feed name is relevant after disruption of main operation
Added to the source registry: 2025-12-04 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: LockData ransomware
LockData as smaller feed name has especially value for claim triage and historical searchability
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Loki was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Lolnek (also known as Lolkek/GlobeImposter) is a commodity ransomware strain primarily targeting small and medium-sized businesses with relatively low ransom demands, associated with the TZW ransomware family, and unsophisticated compared to major RaaS operations with no formal affiliate program.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Lorenz ransomware
Lorenz is a historical double-extortion group, often linked to targeted attacks and leak site publication.
Added to the source registry: 2020-01-12 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US.
Added to the source registry: 2023-09-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid.
Added to the source registry: 2025-09-02 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: LV ransomware
LV historically discussed as a REvil-like or LockBit-like extortion line and is especially relevant by leak-site claims
Added to the source registry: 2021-11-22 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Lynx ransomware
Lynx is a modern double-extortion group that is mainly relevant due to fast claim growth, data diary and similarities with older ransomware code or operator patterns.
Added to the source registry: 2024-07-29 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.
Added to the source registry: 2026-04-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: MadCat is a suspected fraudulent ransomware operation that surfaced briefly in late 2023, apparently linked to scammers targeting other criminals on the dark web with fake stolen passport offers; its leak site appeared dead shortly after announcement, casting doubt on whether it ever operated as a genuine ransomware group.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption patterns, targeting government entities including the Italian Ministry of Culture and using a data leak site to post exfiltrated files.
Added to the source registry: 2024-07-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
majinahanashi was added to Ransomware.live on 2026-08-12. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its targets, victims, or operational model is limited in public reporting.
Added to the source registry: 2023-04-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel), believed to be tied to Iranian military intelligence, primarily targeting Israeli organizations using data exfiltration and extortion, with notable attacks on Ziv Medical Center and Ono Academic College.
Added to the source registry: 2023-12-24 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Mallox ransomware, TargetCompany
Mallox is a ransomware family that is often linked to exposed MS-SQL servers, brutal force and opportunistic enterprise extortion in public CTI.
Added to the source registry: 2022-11-04 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed before reverting; as a standalone strain it operates entirely offline with no C2 communication, uses custom encryption, and targets Windows systems.
Added to the source registry: 2025-03-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or back to victims without encrypting files, applying aggressive pressure by emailing victims' competitors with sample data packs.
Added to the source registry: 2021-12-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Maze ransomware
Maze was an early double-extortion group that published data to put pressure on and thus co-formulated the modern ransomware model.
Added to the source registry: 2019-10-21 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: MBC is a very obscure ransomware group with minimal public documentation and no significant threat intelligence reports available from mainstream security vendors.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Medusa ransomware, Medusa RaaS
Medusa is a RaaS operation with double extortion,IAB- use,Rclone -exfiltration, gaze.exe deployment and a countdown leak site.
Added to the source registry: 2023-01-11 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: MedusaLocker ransomware
this family has been coming back in incidents for years and should not be confused with the separate Medusa RaaS operation
Added to the source registry: 2022-11-15 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning to a data-extortion-only model — selling stolen data rather than encrypting files — with a heavy focus on US healthcare and medical research organizations.
Added to the source registry: 2023-11-24 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Meowciety403 was added to Ransomware.live on 2026-08-27. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-27 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: MetaEncryptor ransomware
MetaEncryptor especially if modern feed name and double-extortion claim occurs with limited hard technical advice
Added to the source registry: 2023-08-16 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler).
Added to the source registry: 2021-11-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Ransomware, potential rebranding of win.sfile.
Added to the source registry: 2022-05-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction, engineering, architecture, and logistics sectors, with victims documented in the US and Chile; limited public technical analysis is available.
Added to the source registry: 2025-12-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: MNT6 is a lower-profile ransomware group claiming victims across legal, manufacturing, construction, healthcare, and logistics sectors in the US, Canada, New Zealand, and Spain, with notable claimed targets including Silfab Solar; some victim listings have been flagged as potentially unverified.
Added to the source registry: 2026-04-30 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, but was quickly exposed as a fraud — the group's operator admitted they were "professional fraudsters" who sold fake breach data and access to a non-existent RaaS panel.
Added to the source registry: 2024-02-20 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Money Message ransomware
Money Message is a ransomware variant that Sophos examined step by step; the Windows version was seen as windows.exe and writes among others C:\money_message.log.
Added to the source registry: 2023-03-29 · Source snapshot: 2026-09-15
Loading stored claims…
Montage was added to Ransomware.live on 2026-08-13. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Monti ransomware
Monti is a ransomware group that is often discussed by similarities with Conti and later deviations in encryption tooling.
Added to the source registry: 2022-12-07 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).
Added to the source registry: 2025-01-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
mortar was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: MosesStaff, Moses Staff
Moses Staff more destructive/hacktivistic pressure used than classic financially motivated ransomware
Added to the source registry: 2021-12-18 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: MountLocker ransomware
MountLocker historically a RaaS operation that later came back in multiple rebrands/ecosystems
Added to the source registry: 2021-02-07 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
Added to the source registry: 2025-12-18 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: N3tw0rm ransomware group is linked to Iran by many security researchers especially for the fact that the group targeting only Israeli companies. Like other ransomware groups, N3tw0rm has a data leak site in the darknet.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle East (UAE, Oman, Saudi Arabia, Iraq) and Israeli IT supply chain firms, using spear-phishing, BEC, and exploitation of public-facing applications.
Added to the source registry: 2025-10-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
nblock was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Nefilim ransomware, Nephilim
Nefilim was a ransomware operation linked to major corporate attacks;DOJ /FBI- context around LockerGoga/MegaCortex/Nefilim underlines enterprise impact.
Added to the source registry: 2020-05-05 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Nemty ransomware
Nemty historically relevant as RaaS/ransomware family from the pre-modern double-extortion period
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital.
Added to the source registry: 2026-04-03 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: NetWalker ransomware, Mailto
NetWalker was a RaaS operation that linked FBI/CISA to attacks on education, care and public sector, with phishing, COVID-19-theme raptures and double extortion.
Added to the source registry: 2020-01-31 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Nevada ransomware
Nevada if Rust-based ransomware-as-a-service was announced and is especially relevant as cross-platform server risk
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: NightSky ransomware, Night Sky
Night Sky was known by double extortion and public analyses on human-operated ransomware
Added to the source registry: 2022-01-04 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.
Added to the source registry: 2025-03-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Nitrogen ransomware, Nitrogen campaign
Nitrogen is particularly relevant as initial access campaign that can result in ransomware such as BlackCat, Black Basta or other payloads via malvertising, SEO-poisoning and software imitation.
Added to the source registry: 2024-09-30 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: NoEscape ransomware
NoEscape is a 2023 RaaS operation with Windows and Linux payloads, multi-extortion and TOR- based affiliate and leaksite infrastructure.
Added to the source registry: 2023-06-12 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Nokoyawa ransomware
Nokoyawa appeared in 2022 and was compared by researchers to Hive; later Nokoyawa was associated with zero-day exploitation chains such as CVE-2023-28252.
Added to the source registry: 2022-12-09 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: NoName ransomware, NoName057(16) context
NoName claims sometimes are hacktivist or DDoS-like and therefore need to be read differently than financial RaaS
Added to the source registry: 2024-01-16 · Source snapshot: 2026-09-15
Loading stored claims…
NotPetya was added to Ransomware.live on 2017-01-01. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2017-01-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
Added to the source registry: 2025-04-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.
Added to the source registry: 2025-09-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: OnePercent, OnePercent ransomware
FBI /CISA This group was linked to long-term access,Cobalt Strike and ransomware extortion against American organizations
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Onyx ransomware
Onyx historically known as ransomware that could destroy files instead of reliable encryption
Added to the source registry: 2022-04-29 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
Added to the source registry: 2024-09-16 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Orion is a ransomware operation first observed in October 2025 that listed 13 alleged victims on a dark web leak site across financial services, manufacturing, and healthcare, though analysts determined its victim list was recycled from prior LockBit and BlackCat disclosures rather than fresh compromises.
Added to the source registry: 2026-01-14 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: First seen 2026-07-07
Added to the source registry: 2026-07-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates.
Added to the source registry: 2025-12-18 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Pandora ransomware
Pandora especially if dual-extortion name occurs in feeds and requires claim triage around leak site publication
Added to the source registry: 2022-03-17 · Source snapshot: 2026-09-15
Loading stored claims…
Panzer was added to Ransomware.live on 2026-08-05. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Pay2Key ransomware
Pay2Key was linked by Check Point to targeted attacks on Israeli organizations with rapid lateral movement
Added to the source registry: 2020-12-13 · Source snapshot: 2026-09-15
Loading stored claims…
Payday was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.
Added to the source registry: 2026-02-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: PayloadBIN ransomware
PayloadBIN is a Babuk-like ransomware name that was discussed in public reporting as successor/variant after the Babuk leak.
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics.
Added to the source registry: 2025-07-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors.
Added to the source registry: 2025-08-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Play ransomware, PlayCrypt, Playcrypt
Play is a ransomware group in which valid accounts, public applications, edge vulnerabilities, log removal and unique binaries per attack are important.
Added to the source registry: 2022-11-26 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: PlayBoy Locker is a ransomware-as-a-service operation that emerged in September 2024, targeting Windows, NAS, and ESXi systems across multiple sectors on an 85/15 affiliate revenue split; its source code was reportedly sold underground by late 2024.
Added to the source registry: 2024-10-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
PrinzEugen was added to Ransomware.live on 2026-05-04. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-05-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-based data leak site and using double-extortion tactics, with operators dwelling in networks for days or weeks before encrypting.
Added to the source registry: 2022-11-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: ProLock ransomware
ProLock historically linked to QakBot access and thus gives a strong lesson about botnet-to-ransomware chains
Added to the source registry: 2020-02-23 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Prometheus ransomware
Prometheus was a historical double-extortion group that presented itself as Conti partner but is technically documented in limited detail
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly
Added to the source registry: 2025-08-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: PYSA, Mespinoza ransomware
PYSA/Mespinoza is known for attacks on educational institutions and double extortion, with FBI- warnings about schools, higher education and seminars.
Added to the source registry: 2020-07-01 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Agenda, Qilin ransomware, Agenda ransomware
Qilin, previously also called Agenda, is a RaaS operation with strong emphasis on double extortion, care impact, Linux/ESXi payloads and defense avoidance.
Added to the source registry: 2022-10-08 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double extortion and unique tactics such as publishing identity documents of victims' family members to pressure payment.
Added to the source registry: 2024-04-22 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Qlocker ransomware, QNAP Qlocker
Qlocker massive QNAP NAS-systems hit by plugging files into password protected 7z archives
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Quantum ransomware
Quantum is known from DFIR-cases in which IcedID access quickly resulted in ransomware, often within short dwell time.
Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: RA Group, RA World ransomware
RA World, previously often referred to as RA Group, is a double-extortion operation that is mainly relevant by enterprise targets, data digs and publication via leak infrastructure.
Added to the source registry: 2023-05-06 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: RabbitHole is a low-profile ransomware group with limited publicly available threat intelligence, not appearing prominently in major threat intelligence reports, suggesting it operates at a small scale or under limited visibility.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Radar (also known as Dispossessor), active since August 2023 and led by an actor called "Brain," was a RaaS group targeting small-to-mid-sized businesses across healthcare, education, finance, and transportation in over 14 countries; it was dismantled by an FBI-led international operation in August 2024 that seized 24 servers and 9 criminal domains.
Added to the source registry: 2025-09-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children.
Added to the source registry: 2025-10-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: RagnarLocker, Ragnar Locker ransomware
Ragnar Locker is a big-game ransomware group that was linked to critical infrastructure by FBI/CISA-alerts and later disrupted by international actions.
Added to the source registry: 2020-04-01 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Ragnarok ransomware
Ragnarok historically was a ransomware group that later released decryption keys and therefore has mostly historical and recovery value
Added to the source registry: 2021-03-31 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and IT sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split; it later rebranded as "Nova."
Added to the source registry: 2025-03-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: RAMP ransomware forum, RAMP ecosystem
RAMP more a ransomware forum/ecosystem name is than one locker, but it is relevant to affiliate and threat context
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.
Added to the source registry: 2023-05-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model where affiliates keep 100% of ransom payments, with packages ranging from $150 to $1,900, making it a popular entry point for less experienced attackers.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: RansomCartel
Ransom Cartel is a ransomware group that is often discussed by similarities with REvil-like ecosystems and double extortion.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative
Added to the source registry: 2025-05-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: RansomCortex emerged in July 2024 with a narrow focus on healthcare facilities, claiming four victims within days of its first appearance including hospitals in Brazil and Canada, operating as a relatively small and niche group.
Added to the source registry: 2024-07-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims including Sony, innovating by threatening GDPR regulatory fines as an additional extortion lever; it briefly operated as a RaaS before shutting down in an apparent exit scam following reported arrests of six members.
Added to the source registry: 2023-08-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: RansomEXX, Defray777
RansomEXX is a targeted ransomware family known by Windows- and Linux variants for large organizations.
Added to the source registry: 2020-05-14 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: RansomHouse
RansomHouse is mainly a data extortion group that deviates from classic ransomware by emphasising data ditadestal instead of encryption.
Added to the source registry: 2021-06-01 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: RansomHub ransomware, RansomHub RaaS
RansomHub is an active RaaS ecosystem with affiliate-driven attacks, broad victim claims, data digs and strong publication pressure.
Added to the source registry: 2024-02-10 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Ranstreet
Ranstreet is a low-confidence feed name. There is little reliable public technical information, which essentially helps with source validation, victim interpretation and defensive triage.
Added to the source registry: 2023-12-21 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Ranzy Locker, Ranzy
Ranzy Locker historically originated from the ThunderX/Ranzy line and has especially value as a double-extortion case
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Raznatovic
Raznatovic is a low-confidence ransomware feed name with little reliable technical explanation. Treat claims as signals that first need source and victim verification.
Added to the source registry: 2023-12-17 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Reborn VC, RebornVC
RebornVC is a limited documented feed name. The profile is aimed at validating claims and defense against general data extortion.
Added to the source registry: 2025-07-08 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: RedRansomware, Red ransomware
Red Ransomware is a name that should be interpreted with caution: there is limited public technical detail information, but it fits the broader pattern of extortion through access, data and publication printing.
Added to the source registry: 2024-03-28 · Source snapshot: 2026-09-15
Loading stored claims…
Redact was added to Ransomware.live on 2026-06-28. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: RedAlert ransomware, N13V
RedAlert/N13V is known by Linux/VMware ESXi-like ransomware context and consequently hits server layers
Added to the source registry: 2022-07-14 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: REvil, Sodinokibi, Sodin
REvil/Sodinokibi was a major RaaS operation known for double extortion, MSP/supply-chain impact and the Kaseya VSA- campaign.
Added to the source registry: 2019-08-26 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Reynolds ransomware
Reynolds is a limited documented ransomware feed name. The profile value is in structured claim validation and practical hunts on access, data and recovery.
Added to the source registry: 2026-02-11 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Rhysida ransomware
Rhysida is a RaaS operation that hits targets of opportunity and often uses VPN- access with valid credentials, RDP, PowerShell and log removal.
Added to the source registry: 2023-06-05 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: RobbinHood ransomware, RobinHood ransomware
RobbinHood's Baltimore case showed how ransomware can disrupt municipal services for months
Added to the source registry: 2021-12-06 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Rook ransomware
Rook was a ransomware group that became visible at the end of 2021 and was linked to code overlap with Babuk. The profile is especially useful for lessons around reused ransomware code and enterprise impact.
Added to the source registry: 2021-12-07 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Royal ransomware, BlackSuit, Royal ransomware group
Royal, later publicly linked to BlackSuit, is a double-extortion operation that combines phishing, remote access, legitimate tools and targeted encryption.
Added to the source registry: 2022-11-04 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Rransom
Rransom is a low-trust feed name without solid public technical file. The profile monitors mainly source validation and generic defense value.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Runsomewares
Runsomewares is a limited documented feed name. Use claims under this name for triage, victim history and defensive controls against data diode and encryption.
Added to the source registry: 2025-02-27 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Sabbath ransomware, UNC2190, Arcane
Sabbath is a ransomware/extortion operation that is linked to UNC2190 and Arcane-like activity in public analysis. The profile is relevant through hands-on intrusions, data diary and printing via publication.
Added to the source registry: 2021-11-22 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: SafePay ransomware
SafePay is a rapidly growing double-extortion group that affects organizations through access, data diary, disruption and pressure via a leak site.
Added to the source registry: 2024-11-19 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Sarcoma ransomware
Sarcoma is a double-extortion group in which data diary, leak-site claims and pressure on organizations with sensitive data are central.
Added to the source registry: 2024-10-09 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after claiming attacks against roughly 67 organizations — though over 65% of listed victims were duplicates from other groups — leaking all stolen data publicly upon shutdown.
Added to the source registry: 2025-07-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only
Added to the source registry: 2025-03-14 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: 🚨 This is a fake group with fake victims.
Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while maintaining an independent public identity, focusing exclusively on commercial targets and deliberately avoiding healthcare and government entities, with approximately 32 documented victims.
Added to the source registry: 2025-07-22 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortion attacks; Group-IB links it operationally to the Brain Cipher group and its siblings EstateRansomware and "Noname," suggesting a shared operator.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
settra was added to Ransomware.live on 2026-06-28. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Direct Extortion Double Extortion
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; specific attribution details regarding its targets, origin, or scale remain sparse in published threat intelligence reports.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.
Added to the source registry: 2026-02-25 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but lacking detailed analysis by major threat intelligence firms, suggesting a very limited or short-lived operation.
Added to the source registry: 2022-11-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Shiba was added to Ransomware.live on 2026-07-27. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-07-27 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: UNC6040, UNC6240, Scattered Lapsus$ Hunters
ShinyHunters is not a classic encryption group but a data diode and extortion brand that leans heavily on SaaS, social engineering, tokens and cloud data.
Added to the source registry: 2025-10-03 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Likely associated with the cybercrime group BlingLibra (ShinyHunters)
Added to the source registry: 2025-11-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targeting Arab and Muslim-majority organizations while avoiding Israeli systems, exploiting exposed RDP services and Fortinet devices, with its admin later instructing operators to migrate to the BQTLock platform.
Added to the source registry: 2025-12-30 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Not a ransomware group but a hacktivist group that appeared coincidentally days before Russia’s invasion of Ukraine
Added to the source registry: 2023-12-08 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own statement, they avoid public negotiations and encrypt minimal data.
Added to the source registry: 2025-04-23 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: SRG, Luna Moth, Chatty Spider, UNC3753
Silent Ransom Group mainly uses callback phishing and social engineering to abuse support or management relationships and steal data without classical encryption.
Added to the source registry: 2025-05-06 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware lineage, claiming 176 victims by end of 2025 through double-extortion attacks primarily against mid-market US organizations via compromised SonicWall VPN credentials.
Added to the source registry: 2025-07-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Skira is a small ransomware group that emerged around late 2024, claiming responsibility for the breach of Carruth Compliance Consulting that exposed SSNs, W-2s, and financial records of employees across 36 US school districts, with five total claimed victims across the US, Turkey, and India.
Added to the source registry: 2025-03-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing company) recorded on ransomware tracking platforms; no detailed threat intelligence reports exist for this group.
Added to the source registry: 2024-01-18 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Snatch ransomware, Team Truniger
Snatch is a RaaS operation known for RDP- abuse, long dwell time, data exfiltration and encryption from Windows Safe Mode.
Added to the source registry: 2021-11-29 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Ransomware, written in .NET.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Sovcali was added to Ransomware.live on 2026-08-09. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Space Bears ransomware
Space Bears is a double-extortion name with public victim claims but limited hard technical publications; treat claims as extortion information that needs to be technically validated.
Added to the source registry: 2024-04-29 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Sparta is a short-lived ransomware group first observed in September 2022 that conducted double-extortion attacks primarily targeting organizations in Spain before ceasing activity, gaining initial access via phishing and exploitation of unpatched systems.
Added to the source registry: 2022-09-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Spirals is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on the Thanos builder), conducting double-extortion attacks against global targets with a concentration in manufacturing and unusually publishing all victim names regardless of ransom payment.
Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Storm was added to Ransomware.live on 2026-08-07. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-07 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: STORMOUS, Stormous ransomware
Stormous is a politically coloured extortion and ransomware name known primarily by claims, publication print and opportunistic data breach communication.
Added to the source registry: 2022-03-22 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: Ransomware, written in Delphi.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: SunCrypt ransomware
SunCrypt was a ransomware group known by double extortion, data diary and printing media such as publication and sometimes DDoS threat.
Added to the source registry: 2020-08-24 · Source snapshot: 2026-09-15
Loading stored claims…
Ransomware.live source assessment: SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process injection technique to evade detection; in August 2021 the group rebranded as El_Cometa, transitioning to a full RaaS model and releasing master decryption keys for prior victims.
Added to the source registry: 2021-03-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, agriculture, hospitality, financial services, and shipping sectors in the US, UK, Norway, Ireland, and Europe within its first months.
Added to the source registry: 2025-06-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.
Added to the source registry: 2025-10-23 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Termite ransomware
Termite is a ransomware group that became visible at the end of 2024/2025 and is linked to Babuk-like code, supply-chain impact and large data exfil claims.
Added to the source registry: 2024-11-17 · Source snapshot: 2026-09-15
Loading stored claims…
Aliases: Gentlemen ransomware, TheGentlemen
The Gentlemen is a rapid-on-the-spot RaaS operation from 2025/2026 that is particularly relevant due to speed, proxy infrastructure and industrial victim claims.
Added to the source registry: 2025-09-09 · Source snapshot: 2026-09-15
Loading stored claims…
The Green Blood Group was added to Ransomware.live on 2026-02-04. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-02-04 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Data Broker
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.
Added to the source registry: 2026-01-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.
Added to the source registry: 2026-04-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Founded 4 April 2026
Added to the source registry: 2026-05-18 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Tommyleaks was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Pro-Palestinian Group
Added to the source registry: 2023-12-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of regulated or third-party data — including government services, telecom, and engineering firms — across the US, Canada, UK, and Asia using double-extortion tactics.
Added to the source registry: 2025-11-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note.
Added to the source registry: 2023-04-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.
Added to the source registry: 2024-06-11 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Triple X was added to Ransomware.live on 2026-06-13. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-13 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Trisec is a Tunisian-origin ransomware group that emerged in February 2024, claiming affiliation with the Tunisian government and operating as both a financially motivated and state-sponsored mercenary group, exclusively recruiting Tunisian members and reporting nine victims in the first half of 2024.
Added to the source registry: 2024-02-16 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: U-Bomb is a low-profile ransomware operation discovered in March 2023 that arrives via phishing emails and uses third-party offensive frameworks (BRC4, Sliver, Cobalt Strike) for lateral movement before deploying its encryptor, likely becoming inactive in the second half of 2023.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
ULose was added to Ransomware.live on 2026-06-09. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
Added to the source registry: 2024-05-01 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: "Unknown" is a catch-all tracking label used on ransomware monitoring platforms for attacks where the responsible threat actor has not been positively attributed to a known named group, serving as a placeholder for unattributed incidents.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: A group which seems to recycle leak from other ransomware groups
Added to the source registry: 2022-12-21 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of data and publishing it on a dedicated leak site, with documented victims including the City of Pleasanton, CA (283 GB exfiltrated) and pharmaceutical firm Duo Pharma Biotech.
Added to the source registry: 2024-09-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.
Added to the source registry: 2025-03-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: VanirGroup is an Eastern European ransomware group composed of former affiliates from Karakurt, LockBit, and Knight ransomware that emerged in mid-2024, before German law enforcement (Karlsruhe Public Prosecutor's Office) seized its leak site.
Added to the source registry: 2024-07-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.
Added to the source registry: 2026-01-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Ransomware, which appears to be a rebranding of win.cuba.
Added to the source registry: 2023-02-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Vexy Ransomware was added to Ransomware.live on 2026-09-03. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-09-03 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentation and no detailed analysis or named victims published by major threat intelligence vendors.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Aliases: Vice Society, DEV-0832
Vice Society is a blackmail actor who was best known for attacks on education and public sector, using existing ransomware variants instead of having a completely private locker.
Added to the source registry: 2021-05-31 · Source snapshot: 2026-09-15
Loading stored claims…
Wallstreet was added to Ransomware.live on 2026-06-26. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-06-26 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and government entities, with a notable attack breaching Myanmar's Union Civil Service Board and exposing data on approximately 200,000 government officials.
Added to the source registry: 2025-06-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat.
Added to the source registry: 2017-05-12 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta.
Added to the source registry: 2025-06-10 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe.
Added to the source registry: 2023-12-20 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.
Added to the source registry: 2025-03-06 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid
Added to the source registry: 2025-05-16 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing standard double-extortion tactics with no detailed technical analysis published by major vendors.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: XingLocker is a ransomware group that emerged in May 2021 as part of a franchise-style RaaS model built on a customized MountLocker payload, using IcedID for initial access and Windows Active Directory APIs for worm-style lateral movement across networks.
Added to the source registry: 2021-04-29 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: XP95 is a cyber-extortion group that emerged in March 2026, using a pure data-theft-and-extortion model with a Windows XP/95-themed leak site, with notable targets including Statistics South Africa (154 GB exfiltrated) and the Gauteng Provincial Government.
Added to the source registry: 2026-03-17 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
xpl0itrs was added to Ransomware.live on 2026-08-15. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-15 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the README.txt file containing a ransom note. It appends the .yanluowang extension to filenames.
Added to the source registry: 2022-07-02 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Added to the source registry: 2025-09-05 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
ZaWoo was added to Ransomware.live on 2026-08-30. The consulted group metadata does not contain a substantive technical description.
Added to the source registry: 2026-08-30 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of former Conti "Team One" members, deliberately avoiding the RaaS model and keeping its code and infrastructure private.
Added to the source registry: Date unknown · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: ZeroLockerSec is a small ransomware group with very limited public documentation that became inactive by Q2 2025 with no recorded leak posts, suggesting a brief operational period before going dormant.
Added to the source registry: 2025-04-28 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Ransomware.live source assessment: ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named victim reports published by major threat intelligence vendors.
Added to the source registry: 2024-05-09 · Source snapshot: 2026-09-15
Limited publicly documented technical evidence for this actor.
Loading stored claims…
Choose a daily overview for the last 24 hours or a weekly overview for the previous week. The email explicitly states that these are darknet and feed claims, not confirmed incidents.
We link this email preference to your account, so you can later choose daily, weekly or off yourself.
Not because these are the only relevant actors, but because they show how different motivation, access and impact can be.
Double extortion, supply chain pressure and rapid impact on production and healthcare environments.
Longer dwell time, quiet cloud abuse scenarios and high-value targets.
Social engineering, helpdesk abuse and cloud access through identity bypass.
The live version should show a clear pattern not only per actor, but also per actor family.
The highest visibility is often around ransomware groups, but the real value of actor profiling lies in access patterns, brokers, tooling and the pace at which business pressure is created.
This is less about visible disruption and more about quiet access, long-term presence and targeted information advantage. Executive relevance sits mainly in provability, governance and confidentiality.
Not every actor is the final attacker. Brokers, stealer ecosystems and access resellers create the fuel other campaigns build on. That layer is critical for early warning.