Threat actors
Ransomware victim watch

Live overview of groups and claimed victims

By default this layer shows potential victims from the last 3 days. Use search to query the stored history.

Loading

One moment, our live darknet feed is loading

Once the feed arrives, the most active ransomware groups appear here.

Victim Group Country / sector Claim date
Feed loading ... ... ...
CTI

All ransomware actors (401)

Browse the locally documented actors, aliases and available intelligence. Profiles distinguish documented findings from research gaps.

401 actors found

These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

0apt

Ransomware.live source assessment: The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly selected organizations.

Added to the source registry: 2026-01-28 · Source snapshot: 2026-09-15

Limited publicly documented technical evidence for this actor.

Latest five known victim claims

Loading stored claims…

    Read the actor profile

    0day Syndicate

    0day Syndicate was added to Ransomware.live on 2026-05-28. The consulted group metadata does not contain a substantive technical description.

    Added to the source registry: 2026-05-28 · Source snapshot: 2026-09-15

    Limited publicly documented technical evidence for this actor.

    Latest five known victim claims

    Loading stored claims…

      Read the actor profile

      0mega

      Ransomware.live source assessment: 0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.

      Added to the source registry: 2022-07-14 · Source snapshot: 2026-09-15

      Limited publicly documented technical evidence for this actor.

      Latest five known victim claims

      Loading stored claims…

        Read the actor profile

        3AM

        Aliases: ThreeAM, 3AM ransomware

        3AM is a ransomware family that stood out as an alternative to failing other payloads, with post-exploitation via Cobalt Strike, privilege use and classic impact preparation.

        Added to the source registry: 2023-09-14 · Source snapshot: 2026-09-15

        Latest five known victim claims

        Loading stored claims…

          Read the actor profile

          8Base

          Aliases: 8Base ransomware

          8Base is a double-extortion group with strong activity since 2023, often discussed in relation to Phobos-like ransomware and RansomHouse-like communication.

          Added to the source registry: 2023-05-23 · Source snapshot: 2026-09-15

          Latest five known victim claims

          Loading stored claims…

            Read the actor profile

            Abrahams_Ax

            Ransomware.live source assessment: Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily targeting Saudi Arabian government institutions for geopolitical reasons related to Saudi-Israeli normalization, using destructive wiper malware and data leak tactics rather than financial ransomware.

            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

            Limited publicly documented technical evidence for this actor.

            Latest five known victim claims

            Loading stored claims…

              Read the actor profile

              Abyss Locker

              Aliases: Abyss, Abyss Locker ransomware

              Abyss Locker shows how Windows and Linux/ESXi ransomware can jointly affect business continuity.

              Added to the source registry: 2023-03-21 · Source snapshot: 2026-09-15

              Latest five known victim claims

              Loading stored claims…

                Read the actor profile

                adminlocker

                Ransomware.live source assessment: AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files and demanding Bitcoin ransom via a Tor-based portal, operated by a lone actor or small closed group with no evidence of an affiliate model.

                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                Limited publicly documented technical evidence for this actor.

                Latest five known victim claims

                Loading stored claims…

                  Read the actor profile

                  againstthewest

                  Ransomware.live source assessment: AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.

                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                  Limited publicly documented technical evidence for this actor.

                  Latest five known victim claims

                  Loading stored claims…

                    Read the actor profile

                    aGl0bGVyCg

                    Ransomware.live source assessment: "aGl0bGVyCg" (Base64 for "hitler") is a reference to the Hitler-Ransomware (2016), a German-origin proof-of-concept that displayed a Hitler image, did not actually encrypt files, and demanded a 25-euro Vodafone card payment; assessed as an amateur test project rather than a serious criminal operation.

                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                    Limited publicly documented technical evidence for this actor.

                    Latest five known victim claims

                    Loading stored claims…

                      Read the actor profile

                      AiLock

                      Ransomware.live source assessment: AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid.

                      Added to the source registry: 2026-03-03 · Source snapshot: 2026-09-15

                      Limited publicly documented technical evidence for this actor.

                      Latest five known victim claims

                      Loading stored claims…

                        Read the actor profile

                        Akira

                        Aliases: Akira ransomware, Akira RaaS

                        Akira is an active ransomware and extortion operation in which remote access, valid accounts, virtualisation, backups and data theft are central.

                        Added to the source registry: 2023-04-26 · Source snapshot: 2026-09-15

                        Latest five known victim claims

                        Loading stored claims…

                          Read the actor profile

                          AKO

                          Aliases: Ako ransomware, Ako Ransomware

                          AKO is historically relevant as a double-extortion group from the early leak-site period.

                          Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                          Latest five known victim claims

                          Loading stored claims…

                            Read the actor profile

                            ALP-001

                            Ransomware.live source assessment: ⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified.

                            Added to the source registry: 2026-03-21 · Source snapshot: 2026-09-15

                            Limited publicly documented technical evidence for this actor.

                            Latest five known victim claims

                            Loading stored claims…

                              Read the actor profile

                              alphalocker

                              Ransomware.live source assessment: AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin panel, ransomware executable, and decryption key generator, lowering the barrier for entry-level cybercriminals using double-extortion tactics.

                              Added to the source registry: 2024-01-24 · Source snapshot: 2026-09-15

                              Limited publicly documented technical evidence for this actor.

                              Latest five known victim claims

                              Loading stored claims…

                                Read the actor profile

                                ALPHV / BlackCat

                                Aliases: ALPHV, BlackCat, Noberus

                                ALPHV is the feed name for BlackCat/Noberus: a Rust-based RaaS operation known for double extortion, affiliates and FBI/CISA/DOJ context.

                                Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                Latest five known victim claims

                                Loading stored claims…

                                  Read the actor profile

                                  anubis

                                  Ransomware.live source assessment: Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates a flexible revenue split model and an optional destructive "wipe mode" alongside standard encryption.

                                  Added to the source registry: 2025-02-25 · Source snapshot: 2026-09-15

                                  Limited publicly documented technical evidence for this actor.

                                  Latest five known victim claims

                                  Loading stored claims…

                                    Read the actor profile

                                    apos

                                    Ransomware.live source assessment: Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or sell stolen information rather than encrypting files, targeting technology, healthcare, manufacturing, telecom, and government sectors across multiple countries.

                                    Added to the source registry: 2024-04-29 · Source snapshot: 2026-09-15

                                    Limited publicly documented technical evidence for this actor.

                                    Latest five known victim claims

                                    Loading stored claims…

                                      Read the actor profile

                                      apt73

                                      Ransomware.live source assessment: A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the group reportedly self-proclaimed as an APT, which stands for 'Advanced Persistent Threat' in the cybersecurity field. According to research, much of the available information about the aforementioned group came from another ransomware group known as LockBit.

                                      Added to the source registry: 2024-04-22 · Source snapshot: 2026-09-15

                                      Limited publicly documented technical evidence for this actor.

                                      Latest five known victim claims

                                      Loading stored claims…

                                        Read the actor profile

                                        Aptlock

                                        Aptlock was added to Ransomware.live on 2025-01-01. The consulted group metadata does not contain a substantive technical description.

                                        Added to the source registry: 2025-01-01 · Source snapshot: 2026-09-15

                                        Limited publicly documented technical evidence for this actor.

                                        Latest five known victim claims

                                        Loading stored claims…

                                          Read the actor profile

                                          arcusmedia

                                          Ransomware.live source assessment: Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.

                                          Added to the source registry: 2024-05-15 · Source snapshot: 2026-09-15

                                          Limited publicly documented technical evidence for this actor.

                                          Latest five known victim claims

                                          Loading stored claims…

                                            Read the actor profile

                                            argonauts

                                            Ransomware.live source assessment: Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, healthcare, energy, and telecom sectors, with approximately 13 claimed victims tracked via a TOR-based leak site.

                                            Added to the source registry: 2024-11-27 · Source snapshot: 2026-09-15

                                            Limited publicly documented technical evidence for this actor.

                                            Latest five known victim claims

                                            Loading stored claims…

                                              Read the actor profile

                                              arkana

                                              Ransomware.live source assessment: Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband provider WideOpenWest (WOW!), operating a three-phase ransom/sale/leak extortion model primarily focused on telecom and internet service providers.

                                              Added to the source registry: 2025-03-25 · Source snapshot: 2026-09-15

                                              Limited publicly documented technical evidence for this actor.

                                              Latest five known victim claims

                                              Loading stored claims…

                                                Read the actor profile

                                                arvinclub

                                                Ransomware.live source assessment: Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via a TOR site and Telegram rather than deploying file-encrypting ransomware, targeting government, education, and banking sectors globally including Iranian government entities.

                                                Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                Limited publicly documented technical evidence for this actor.

                                                Latest five known victim claims

                                                Loading stored claims…

                                                  Read the actor profile

                                                  atomsilo

                                                  Ransomware.live source assessment: AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access and demanding ransoms up to $1 million, attributed to the Chinese state-linked threat actor BRONZE STARLIGHT.

                                                  Added to the source registry: 2021-12-21 · Source snapshot: 2026-09-15

                                                  Limited publicly documented technical evidence for this actor.

                                                  Latest five known victim claims

                                                  Loading stored claims…

                                                    Read the actor profile

                                                    AuditTeam

                                                    Ransomware.live source assessment: AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and Southeast Asia across technology and manufacturing sectors, operating a data leak site consistent with double-extortion methodology.

                                                    Added to the source registry: 2026-04-08 · Source snapshot: 2026-09-15

                                                    Limited publicly documented technical evidence for this actor.

                                                    Latest five known victim claims

                                                    Loading stored claims…

                                                      Read the actor profile

                                                      aurora

                                                      Ransomware.live source assessment: Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.

                                                      Added to the source registry: 2026-04-29 · Source snapshot: 2026-09-15

                                                      Limited publicly documented technical evidence for this actor.

                                                      Latest five known victim claims

                                                      Loading stored claims…

                                                        Read the actor profile

                                                        Avaddon

                                                        Aliases: Avaddon ransomware

                                                        Avaddon was a RaaS operation using double extortion and DDoS pressure; researchers published technical analysis and decryption context.

                                                        Added to the source registry: 2021-02-01 · Source snapshot: 2026-09-15

                                                        Latest five known victim claims

                                                        Loading stored claims…

                                                          Read the actor profile

                                                          Avos

                                                          Aliases: Avos, AvosLocker alias

                                                          Avos is a short feed alias that usually points to AvosLocker and should remain clickable for feed history and search.

                                                          Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                          Latest five known victim claims

                                                          Loading stored claims…

                                                            Read the actor profile

                                                            AvosLocker

                                                            Aliases: AvosLocker ransomware, Avos

                                                            AvosLocker is a RaaS operation that FBI/CISA says affects Windows, Linux and VMware ESXi, abuses legitimate remote administration tools and uses exfiltration-based extortion.

                                                            Added to the source registry: 2021-06-13 · Source snapshot: 2026-09-15

                                                            Latest five known victim claims

                                                            Loading stored claims…

                                                              Read the actor profile

                                                              aware

                                                              Ransomware.live source assessment: Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documentation and no publicly catalogued victims, tools, or TTPs in major threat intelligence databases.

                                                              Added to the source registry: 2026-01-06 · Source snapshot: 2026-09-15

                                                              Limited publicly documented technical evidence for this actor.

                                                              Latest five known victim claims

                                                              Loading stored claims…

                                                                Read the actor profile

                                                                aztroteam

                                                                Ransomware.live source assessment: AztroTeam is a ransomware group with very limited public documentation and no confirmed victims, listed as offline on ransomware tracking platforms.

                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                Limited publicly documented technical evidence for this actor.

                                                                Latest five known victim claims

                                                                Loading stored claims…

                                                                  Read the actor profile

                                                                  Babuk

                                                                  Aliases: Babuk Locker, Babuk ransomware

                                                                  Babuk is historically important because of leaked source code, ESXi/Linux impact and reuse of code in later ransomware variants.

                                                                  Added to the source registry: 2020-10-25 · Source snapshot: 2026-09-15

                                                                  Latest five known victim claims

                                                                  Loading stored claims…

                                                                    Read the actor profile

                                                                    babuk2

                                                                    Ransomware.live source assessment: Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on forums, decided to impersonate Babuk Ransomware group. He launched a blog where he claimed multiple public breaches from BreachForums as ransomware attacks

                                                                    Added to the source registry: 2025-01-27 · Source snapshot: 2026-09-15

                                                                    Limited publicly documented technical evidence for this actor.

                                                                    Latest five known victim claims

                                                                    Loading stored claims…

                                                                      Read the actor profile

                                                                      babyduck

                                                                      Ransomware.live source assessment: BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduck extension to encrypted files, distinct from the better-known Babuk group.

                                                                      Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                      Limited publicly documented technical evidence for this actor.

                                                                      Latest five known victim claims

                                                                      Loading stored claims…

                                                                        Read the actor profile

                                                                        Barracuda

                                                                        Barracuda was added to Ransomware.live on 2026-08-06. The consulted group metadata does not contain a substantive technical description.

                                                                        Added to the source registry: 2026-08-06 · Source snapshot: 2026-09-15

                                                                        Limited publicly documented technical evidence for this actor.

                                                                        Latest five known victim claims

                                                                        Loading stored claims…

                                                                          Read the actor profile

                                                                          beast

                                                                          Ransomware.live source assessment: Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.

                                                                          Added to the source registry: 2025-07-29 · Source snapshot: 2026-09-15

                                                                          Limited publicly documented technical evidence for this actor.

                                                                          Latest five known victim claims

                                                                          Loading stored claims…

                                                                            Read the actor profile

                                                                            benzona

                                                                            Ransomware.live source assessment: Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.

                                                                            Added to the source registry: 2025-11-26 · Source snapshot: 2026-09-15

                                                                            Limited publicly documented technical evidence for this actor.

                                                                            Latest five known victim claims

                                                                            Loading stored claims…

                                                                              Read the actor profile

                                                                              bert

                                                                              Ransomware.live source assessment: BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.

                                                                              Added to the source registry: 2025-04-06 · Source snapshot: 2026-09-15

                                                                              Limited publicly documented technical evidence for this actor.

                                                                              Latest five known victim claims

                                                                              Loading stored claims…

                                                                                Read the actor profile

                                                                                BianLian

                                                                                Aliases: BianLian ransomware, BianLian extortion

                                                                                BianLian is a data-extortion group that, according to CISA/FBI/ACSC, shifted from ransomware to primarily exfiltration-based extortion.

                                                                                Added to the source registry: 2022-07-14 · Source snapshot: 2026-09-15

                                                                                Latest five known victim claims

                                                                                Loading stored claims…

                                                                                  Read the actor profile

                                                                                  Black Basta

                                                                                  Aliases: BlackBasta, Black Basta ransomware

                                                                                  Black Basta is a professional ransomware operation with strong focus on enterprise impact, data theft, lateral movement and disruption of recovery.

                                                                                  Added to the source registry: 2022-04-26 · Source snapshot: 2026-09-15

                                                                                  Latest five known victim claims

                                                                                  Loading stored claims…

                                                                                    Read the actor profile

                                                                                    Black X

                                                                                    Black X was added to Ransomware.live on 2026-06-02. The consulted group metadata does not contain a substantive technical description.

                                                                                    Added to the source registry: 2026-06-02 · Source snapshot: 2026-09-15

                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                    Latest five known victim claims

                                                                                    Loading stored claims…

                                                                                      Read the actor profile

                                                                                      BlackByte

                                                                                      Aliases: BlackByte ransomware

                                                                                      BlackByte is a ransomware group linked by FBI/USSS to attacks on US critical infrastructure sectors and known IOCs around encryption and ransom notes.

                                                                                      Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15

                                                                                      Latest five known victim claims

                                                                                      Loading stored claims…

                                                                                        Read the actor profile

                                                                                        BlackCat / ALPHV

                                                                                        Aliases: ALPHV, BlackCat, Noberus

                                                                                        BlackCat/ALPHV is a mature RaaS profile that combined affiliate operations, social engineering, data theft, encryption and aggressive extortion.

                                                                                        Latest five known victim claims

                                                                                        Loading stored claims…

                                                                                          Read the actor profile

                                                                                          Blackfield

                                                                                          Blackfield was added to Ransomware.live on 2026-06-29. The consulted group metadata does not contain a substantive technical description.

                                                                                          Added to the source registry: 2026-06-29 · Source snapshot: 2026-09-15

                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                          Latest five known victim claims

                                                                                          Loading stored claims…

                                                                                            Read the actor profile

                                                                                            BlackLock

                                                                                            Aliases: BlackLock ransomware

                                                                                            BlackLock shows how young ransomware brands can appear quickly in feeds and mainly build pressure through double-extortion claims.

                                                                                            Added to the source registry: 2025-05-16 · Source snapshot: 2026-09-15

                                                                                            Latest five known victim claims

                                                                                            Loading stored claims…

                                                                                              Read the actor profile

                                                                                              BlackLocks

                                                                                              BlackLocks was added to Ransomware.live on 2026-09-04. The consulted group metadata does not contain a substantive technical description.

                                                                                              Added to the source registry: 2026-09-04 · Source snapshot: 2026-09-15

                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                              Latest five known victim claims

                                                                                              Loading stored claims…

                                                                                                Read the actor profile

                                                                                                BlackMatter

                                                                                                Aliases: BlackMatter ransomware

                                                                                                BlackMatter was a ransomware group that CISA/FBI/NSA linked to critical infrastructure attacks and TTPs around SMB, LDAP, PowerShell and encryption of shared resources.

                                                                                                Added to the source registry: 2021-09-08 · Source snapshot: 2026-09-15

                                                                                                Latest five known victim claims

                                                                                                Loading stored claims…

                                                                                                  Read the actor profile

                                                                                                  blacknevas

                                                                                                  Ransomware.live source assessment: BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.

                                                                                                  Added to the source registry: 2025-08-06 · Source snapshot: 2026-09-15

                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                  Latest five known victim claims

                                                                                                  Loading stored claims…

                                                                                                    Read the actor profile

                                                                                                    blackout

                                                                                                    Ransomware.live source assessment: Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.

                                                                                                    Added to the source registry: 2024-02-26 · Source snapshot: 2026-09-15

                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                    Latest five known victim claims

                                                                                                    Loading stored claims…

                                                                                                      Read the actor profile

                                                                                                      BlackShadow

                                                                                                      Aliases: BlackShadow ransomware

                                                                                                      BlackShadow is mainly known from Israel-focused ransomware and data-leak claims and should therefore be read with geopolitical context.

                                                                                                      Added to the source registry: 2021-12-18 · Source snapshot: 2026-09-15

                                                                                                      Latest five known victim claims

                                                                                                      Loading stored claims…

                                                                                                        Read the actor profile

                                                                                                        blackshrantac

                                                                                                        Ransomware.live source assessment: BlackShrantac is a ransomware group that emerged in late 2025, targeting organizations in manufacturing, financial services, technology, and the public sector globally, employing double-extortion combined with living-off-the-land techniques to weaponize legitimate tools and disable defenses before encrypting files.

                                                                                                        Added to the source registry: 2025-09-17 · Source snapshot: 2026-09-15

                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                        Latest five known victim claims

                                                                                                        Loading stored claims…

                                                                                                          Read the actor profile

                                                                                                          BlackSuit

                                                                                                          Aliases: Royal, Royal ransomware, BlackSuit ransomware

                                                                                                          BlackSuit is the successor or rebrand line around Royal and remains relevant through enterprise attacks, callback phishing, RDP, data exfiltration and high impact on healthcare and critical sectors.

                                                                                                          Added to the source registry: 2023-06-12 · Source snapshot: 2026-09-15

                                                                                                          Latest five known victim claims

                                                                                                          Loading stored claims…

                                                                                                            Read the actor profile

                                                                                                            blacktor

                                                                                                            Ransomware.live source assessment: Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.

                                                                                                            Added to the source registry: 2021-12-30 · Source snapshot: 2026-09-15

                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                            Latest five known victim claims

                                                                                                            Loading stored claims…

                                                                                                              Read the actor profile

                                                                                                              blackwater

                                                                                                              Ransomware.live source assessment: Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and targeting healthcare organizations, with known victims including Minidoka Memorial Hospital in Idaho.

                                                                                                              Added to the source registry: 2026-04-12 · Source snapshot: 2026-09-15

                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                              Latest five known victim claims

                                                                                                              Loading stored claims…

                                                                                                                Read the actor profile

                                                                                                                bluebox

                                                                                                                Ransomware.live source assessment: Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.

                                                                                                                Added to the source registry: 2024-12-11 · Source snapshot: 2026-09-15

                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                Latest five known victim claims

                                                                                                                Loading stored claims…

                                                                                                                  Read the actor profile

                                                                                                                  bluelocker

                                                                                                                  Ransomware.live source assessment: Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum

                                                                                                                  Added to the source registry: 2025-08-19 · Source snapshot: 2026-09-15

                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                  Latest five known victim claims

                                                                                                                  Loading stored claims…

                                                                                                                    Read the actor profile

                                                                                                                    bluesky

                                                                                                                    Ransomware.live source assessment: BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/Curve25519 encryption for fast file locking on Windows hosts, with code sharing significant overlap with Conti v2/v3 and Babuk, attributed with high confidence to Russian-origin threat actors.

                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                    Latest five known victim claims

                                                                                                                    Loading stored claims…

                                                                                                                      Read the actor profile

                                                                                                                      BlueWhale

                                                                                                                      BlueWhale was added to Ransomware.live on 2026-08-14. The consulted group metadata does not contain a substantive technical description.

                                                                                                                      Added to the source registry: 2026-08-14 · Source snapshot: 2026-09-15

                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                      Latest five known victim claims

                                                                                                                      Loading stored claims…

                                                                                                                        Read the actor profile

                                                                                                                        Bolt Team

                                                                                                                        Bolt Team was added to Ransomware.live on 2026-08-01. The consulted group metadata does not contain a substantive technical description.

                                                                                                                        Added to the source registry: 2026-08-01 · Source snapshot: 2026-09-15

                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                        Latest five known victim claims

                                                                                                                        Loading stored claims…

                                                                                                                          Read the actor profile

                                                                                                                          bonacigroup

                                                                                                                          Ransomware.live source assessment: Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going offline, with very little public documentation about their tactics, targets, or tooling.

                                                                                                                          Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15

                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                          Latest five known victim claims

                                                                                                                          Loading stored claims…

                                                                                                                            Read the actor profile

                                                                                                                            Booba Project

                                                                                                                            Ransomware.live source assessment: Booba

                                                                                                                            Added to the source registry: 2026-07-06 · Source snapshot: 2026-09-15

                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                            Latest five known victim claims

                                                                                                                            Loading stored claims…

                                                                                                                              Read the actor profile

                                                                                                                              bqtlock

                                                                                                                              Ransomware.live source assessment: BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.

                                                                                                                              Added to the source registry: 2025-07-31 · Source snapshot: 2026-09-15

                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                              Latest five known victim claims

                                                                                                                              Loading stored claims…

                                                                                                                                Read the actor profile

                                                                                                                                Brain Cipher

                                                                                                                                Aliases: Brain Cipher ransomware

                                                                                                                                Brain Cipher became publicly visible through the attack on Indonesian national data-centre services and claims around LockBit-like code.

                                                                                                                                Added to the source registry: 2024-07-01 · Source snapshot: 2026-09-15

                                                                                                                                Latest five known victim claims

                                                                                                                                Loading stored claims…

                                                                                                                                  Read the actor profile

                                                                                                                                  bravox

                                                                                                                                  Ransomware.live source assessment: BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.

                                                                                                                                  Added to the source registry: 2026-02-11 · Source snapshot: 2026-09-15

                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                  Latest five known victim claims

                                                                                                                                  Loading stored claims…

                                                                                                                                    Read the actor profile

                                                                                                                                    brotherhood

                                                                                                                                    Ransomware.live source assessment: Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.

                                                                                                                                    Added to the source registry: 2025-11-15 · Source snapshot: 2026-09-15

                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                    Latest five known victim claims

                                                                                                                                    Loading stored claims…

                                                                                                                                      Read the actor profile

                                                                                                                                      Cactus

                                                                                                                                      Aliases: Cactus ransomware

                                                                                                                                      Cactus is a known double-extortion group notable for VPN/edge access, encryptor self-protection and attacks where data exfiltration and recovery disruption are central.

                                                                                                                                      Added to the source registry: 2023-07-20 · Source snapshot: 2026-09-15

                                                                                                                                      Latest five known victim claims

                                                                                                                                      Loading stored claims…

                                                                                                                                        Read the actor profile

                                                                                                                                        cephalus

                                                                                                                                        Ransomware.live source assessment: Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.

                                                                                                                                        Added to the source registry: 2025-08-26 · Source snapshot: 2026-09-15

                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                        Latest five known victim claims

                                                                                                                                        Loading stored claims…

                                                                                                                                          Read the actor profile

                                                                                                                                          Chaos

                                                                                                                                          Aliases: Chaos ransomware, Chaos RaaS

                                                                                                                                          Chaos is described in recent reporting as a possible successor or splinter of BlackSuit/Royal that continues double extortion.

                                                                                                                                          Added to the source registry: 2025-03-31 · Source snapshot: 2026-09-15

                                                                                                                                          Latest five known victim claims

                                                                                                                                          Loading stored claims…

                                                                                                                                            Read the actor profile

                                                                                                                                            cheers

                                                                                                                                            Ransomware.live source assessment: Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks against VMware ESXi servers, running a double-extortion leak site with four documented victims.

                                                                                                                                            Added to the source registry: 2022-05-29 · Source snapshot: 2026-09-15

                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                            Latest five known victim claims

                                                                                                                                            Loading stored claims…

                                                                                                                                              Read the actor profile

                                                                                                                                              chilelocker

                                                                                                                                              Ransomware.live source assessment: ChileLocker (also known as ARCrypter) first appeared in August 2022 after attacking a Chilean government agency and quickly expanded globally, appending a ".crypt" extension to encrypted files and recruiting affiliates under a RaaS model on criminal forums.

                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                              Latest five known victim claims

                                                                                                                                              Loading stored claims…

                                                                                                                                                Read the actor profile

                                                                                                                                                chort

                                                                                                                                                Ransomware.live source assessment: Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance.

                                                                                                                                                Added to the source registry: 2024-11-17 · Source snapshot: 2026-09-15

                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                Latest five known victim claims

                                                                                                                                                Loading stored claims…

                                                                                                                                                  Read the actor profile

                                                                                                                                                  Cicada3301

                                                                                                                                                  Aliases: Cicada3301 ransomware, Cicada 3301

                                                                                                                                                  Cicada3301 is a modern Rust-based ransomware group with Linux/ESXi-like impact and public discussion about overlap with ALPHV-like techniques.

                                                                                                                                                  Added to the source registry: 2024-06-20 · Source snapshot: 2026-09-15

                                                                                                                                                  Latest five known victim claims

                                                                                                                                                  Loading stored claims…

                                                                                                                                                    Read the actor profile

                                                                                                                                                    ciphbit

                                                                                                                                                    Ransomware.live source assessment: CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion.

                                                                                                                                                    Added to the source registry: 2023-09-14 · Source snapshot: 2026-09-15

                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                    Latest five known victim claims

                                                                                                                                                    Loading stored claims…

                                                                                                                                                      Read the actor profile

                                                                                                                                                      cipherforce

                                                                                                                                                      Ransomware.live source assessment: CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeting technology, business services, and logistics companies across the US, China, Vietnam, India, and UAE, with at least 6 claimed victims.

                                                                                                                                                      Added to the source registry: 2026-02-23 · Source snapshot: 2026-09-15

                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                      Latest five known victim claims

                                                                                                                                                      Loading stored claims…

                                                                                                                                                        Read the actor profile

                                                                                                                                                        CL0P

                                                                                                                                                        Aliases: Clop, Cl0p, TA505 linked CL0P

                                                                                                                                                        CL0P is especially relevant as a data-extortion group that abuses vulnerabilities in data-rich enterprise and file-transfer platforms at scale.

                                                                                                                                                        Added to the source registry: 2020-03-13 · Source snapshot: 2026-09-15

                                                                                                                                                        Latest five known victim claims

                                                                                                                                                        Loading stored claims…

                                                                                                                                                          Read the actor profile

                                                                                                                                                          Cloak

                                                                                                                                                          Aliases: Cloak ransomware

                                                                                                                                                          Cloak is mainly known through leak-site claims and is therefore useful as a data-focused claim-triage profile.

                                                                                                                                                          Added to the source registry: 2023-08-24 · Source snapshot: 2026-09-15

                                                                                                                                                          Latest five known victim claims

                                                                                                                                                          Loading stored claims…

                                                                                                                                                            Read the actor profile

                                                                                                                                                            cmdorganization

                                                                                                                                                            Ransomware.live source assessment: CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company. CMD operates on a global scale recognizing the critical importance of timeliness and confidentiality.

                                                                                                                                                            Added to the source registry: 2026-05-02 · Source snapshot: 2026-09-15

                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                            Latest five known victim claims

                                                                                                                                                            Loading stored claims…

                                                                                                                                                              Read the actor profile

                                                                                                                                                              coinbasecartel

                                                                                                                                                              Ransomware.live source assessment: CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve system encryption or operational disruption.

                                                                                                                                                              Added to the source registry: 2025-09-15 · Source snapshot: 2026-09-15

                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                              Latest five known victim claims

                                                                                                                                                              Loading stored claims…

                                                                                                                                                                Read the actor profile

                                                                                                                                                                ContFR

                                                                                                                                                                Ransomware.live source assessment: RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fonctionne pas sur Linux. Tableau de vitcimes et récupération de données possible depuis votre espace abonné.

                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                Loading stored claims…

                                                                                                                                                                  Read the actor profile

                                                                                                                                                                  Conti

                                                                                                                                                                  Aliases: Conti ransomware

                                                                                                                                                                  Conti was a large RaaS operation that CISA/FBI/NSA/USSS linked to TrickBot, IcedID, Cobalt Strike, malicious Word attachments and hundreds of attacks.

                                                                                                                                                                  Added to the source registry: 2020-07-31 · Source snapshot: 2026-09-15

                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                    Read the actor profile

                                                                                                                                                                    cooming

                                                                                                                                                                    Ransomware.live source assessment: CoomingProject is a ransomware group that emerged around 2021 and operated a double-extortion scheme with multiple Tor-based leak sites; six members were identified by French authorities in February 2022, after which the group's infrastructure went offline.

                                                                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                      Read the actor profile

                                                                                                                                                                      crazyhunter

                                                                                                                                                                      Ransomware.live source assessment: CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.

                                                                                                                                                                      Added to the source registry: 2025-03-09 · Source snapshot: 2026-09-15

                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                        Read the actor profile

                                                                                                                                                                        crosslock

                                                                                                                                                                        Ransomware.live source assessment: CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.

                                                                                                                                                                        Added to the source registry: 2023-04-17 · Source snapshot: 2026-09-15

                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                          Read the actor profile

                                                                                                                                                                          CRPxO

                                                                                                                                                                          Ransomware.live source assessment: CRPxO is actively recruiting affiliates, offering: 🔹 70% revenue share 🔹 XMR/BTC payouts 🔹 Claimed payouts within 24 hours 🔹 $333 one-time affiliate access

                                                                                                                                                                          Added to the source registry: 2026-07-09 · Source snapshot: 2026-09-15

                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                            Read the actor profile

                                                                                                                                                                            cry0

                                                                                                                                                                            Ransomware.live source assessment: Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payload with blockchain-based (Internet Computer Protocol) negotiation infrastructure to resist law enforcement takedowns and offering affiliates a 90/10 revenue split.

                                                                                                                                                                            Added to the source registry: 2026-01-19 · Source snapshot: 2026-09-15

                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                              Read the actor profile

                                                                                                                                                                              CryLock

                                                                                                                                                                              Aliases: CryLock ransomware

                                                                                                                                                                              CryLock appears historically as a ransomware family and is mainly useful for retro-hunting and older incidents.

                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                cryp70n1c0d3

                                                                                                                                                                                Ransomware.live source assessment: Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology, and operational model remain poorly documented in open sources.

                                                                                                                                                                                Added to the source registry: 2021-12-18 · Source snapshot: 2026-09-15

                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                  cryptbb

                                                                                                                                                                                  Ransomware.live source assessment: CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to encrypted files and whose data leak site copied 8Base's source code, listing approximately 8 victims as of September 2023.

                                                                                                                                                                                  Added to the source registry: 2023-09-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                    CryptNet

                                                                                                                                                                                    Aliases: CryptNet ransomware

                                                                                                                                                                                    CryptNet is a smaller double-extortion name that is mainly relevant for historical feed and claim triage.

                                                                                                                                                                                    Added to the source registry: 2023-04-19 · Source snapshot: 2026-09-15

                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                      crypto24

                                                                                                                                                                                      Ransomware.live source assessment: Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate.

                                                                                                                                                                                      Added to the source registry: 2025-04-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                        Cuba

                                                                                                                                                                                        Aliases: Cuba ransomware, Cuba ransomware actors

                                                                                                                                                                                        Cuba ransomware actors use vulnerabilities, phishing, compromised credentials, RDP and Hancitor-related access to perform data extortion and encryption.

                                                                                                                                                                                        Added to the source registry: 2021-02-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                          cyclops

                                                                                                                                                                                          Ransomware.live source assessment: Cyclops emerged in May 2023 as a cross-platform RaaS operation targeting Windows, macOS, and Linux systems; it rebranded as "Knight" in August 2023 and its codebase was ultimately sold, with affiliates largely migrating to RansomHub.

                                                                                                                                                                                          Added to the source registry: 2023-07-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                            D1R

                                                                                                                                                                                            Ransomware.live source assessment: D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion

                                                                                                                                                                                            Added to the source registry: 2026-07-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                              d4rk4rmy

                                                                                                                                                                                              Ransomware.live source assessment: D4rk4rmy is a ransomware and data extortion group active since at least 2025, targeting financial services, hospitality, technology, and logistics sectors, operating a RaaS model with notable claimed victims including the Monte Carlo casino resort.

                                                                                                                                                                                              Added to the source registry: 2025-07-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                dagonlocker

                                                                                                                                                                                                Ransomware.live source assessment: Dagon Locker is a ransomware strain that first appeared in early 2023, evolved from the MountLocker/Quantum ransomware lineage, and uses IcedID as an initial access vector before deploying double-extortion attacks with ChaCha20+RSA-2048 encryption.

                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                  Daixin Team

                                                                                                                                                                                                  Aliases: Daixin, Daixin Team ransomware

                                                                                                                                                                                                  Daixin Team focuses, according to CISA/FBI/HHS, mainly on healthcare and public health, using VPN access, credential abuse, RDP/SSH, data exfiltration and ransomware.

                                                                                                                                                                                                  Added to the source registry: 2022-08-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                    dAn0n

                                                                                                                                                                                                    Ransomware.live source assessment: dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.

                                                                                                                                                                                                    Added to the source registry: 2024-04-25 · Source snapshot: 2026-09-15

                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                      Dark Angels

                                                                                                                                                                                                      Aliases: Dark Angels ransomware, Dunghill Leak

                                                                                                                                                                                                      Dark Angels is known for highly targeted big-game extortion and sometimes quiet negotiations without broad publicity.

                                                                                                                                                                                                      Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                        Dark Power

                                                                                                                                                                                                        Aliases: DarkPower ransomware

                                                                                                                                                                                                        Dark Power is a smaller double-extortion name in ransomware feeds and mainly requires careful claim validation.

                                                                                                                                                                                                        Added to the source registry: 2023-03-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                          Dark Project

                                                                                                                                                                                                          Ransomware.live source assessment: Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortion model (stealing sensitive data before encrypting local systems and threatening to leak it on their dark web portal).

                                                                                                                                                                                                          Added to the source registry: 2026-08-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                            DarkBit

                                                                                                                                                                                                            Aliases: DarkBit ransomware

                                                                                                                                                                                                            DarkBit is mainly known for politically motivated or hacktivist-style ransomware claims against Israeli targets.

                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                              darkleakmarket

                                                                                                                                                                                                              Ransomware.live source assessment: DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransomware groups and hacking forums, with 39 known victim organizations; it operates more as a data resale market than a traditional ransomware operator.

                                                                                                                                                                                                              Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                DarkMatter

                                                                                                                                                                                                                DarkMatter was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                  DarkRace

                                                                                                                                                                                                                  Aliases: DarkRace ransomware

                                                                                                                                                                                                                  DarkRace is a smaller ransomware feed name with limited public technical detail but useful claim-triage value.

                                                                                                                                                                                                                  Added to the source registry: 2023-05-31 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                    DarkSide

                                                                                                                                                                                                                    Aliases: DarkSide ransomware

                                                                                                                                                                                                                    DarkSide is the ransomware group confirmed by the FBI in the Colonial Pipeline attack and remains a core case for IT/OT segmentation and business disruption.

                                                                                                                                                                                                                    Added to the source registry: 2020-08-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                      darkvault

                                                                                                                                                                                                                      Ransomware.live source assessment: DarkVault is a data-exfiltration and double-extortion group first identified in late 2023, targeting medium-to-large organizations in finance, professional services, legal, and technology sectors across Europe, the UK, and North America, with a suspected connection to LockBit.

                                                                                                                                                                                                                      Added to the source registry: 2024-04-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                        datacarry

                                                                                                                                                                                                                        Ransomware.live source assessment: DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.

                                                                                                                                                                                                                        Added to the source registry: 2025-05-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                          datakeeper

                                                                                                                                                                                                                          Ransomware.live source assessment: DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "CrystalPartnership RaaS," offering a Windows-focused ransomware toolkit with hybrid RSA-4096 encryption, open dark web registration, and an innovative split-payment mechanism to build affiliate trust.

                                                                                                                                                                                                                          Added to the source registry: 2026-01-14 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                            dataleak

                                                                                                                                                                                                                            Ransomware.live source assessment: Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited public threat intelligence exists on this group's tools, TTPs, or origins.

                                                                                                                                                                                                                            Added to the source registry: 2022-12-02 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                              Deadlock

                                                                                                                                                                                                                              Deadlock was added to Ransomware.live on 2026-06-15. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                              Added to the source registry: 2026-06-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                desolator

                                                                                                                                                                                                                                Ransomware.live source assessment: Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.

                                                                                                                                                                                                                                Added to the source registry: 2025-08-30 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                  devman

                                                                                                                                                                                                                                  Ransomware.live source assessment: Former RansomHub and INC Ransom affiliate.

                                                                                                                                                                                                                                  Added to the source registry: 2025-04-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                    Diavol

                                                                                                                                                                                                                                    Aliases: Diavol ransomware

                                                                                                                                                                                                                                    Diavol has been linked in public CTI to TrickBot-ecosystem-style methods and fast ransomware deployment.

                                                                                                                                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                      direwolf

                                                                                                                                                                                                                                      Ransomware.live source assessment: Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.

                                                                                                                                                                                                                                      Added to the source registry: 2025-05-22 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                        dispossessor

                                                                                                                                                                                                                                        Ransomware.live source assessment: This is not a ransomware group but a data broker

                                                                                                                                                                                                                                        Added to the source registry: 2024-04-19 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                          Donex

                                                                                                                                                                                                                                          Aliases: Donex ransomware

                                                                                                                                                                                                                                          Donex is known mainly as a modern extortion name through leak-site claims and limited technical reporting.

                                                                                                                                                                                                                                          Added to the source registry: 2024-03-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                            donutleaks

                                                                                                                                                                                                                                            Ransomware.live source assessment: Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.

                                                                                                                                                                                                                                            Added to the source registry: 2022-08-24 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                              Doommageddon

                                                                                                                                                                                                                                              Ransomware.live source assessment: Direct Extortion Double Extortion

                                                                                                                                                                                                                                              Added to the source registry: 2026-07-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                DoppelPaymer

                                                                                                                                                                                                                                                Aliases: DoppelPaymer ransomware, DopplePaymer

                                                                                                                                                                                                                                                DoppelPaymer was a double-extortion ransomware operation known for leak-site pressure and attacks on large organisations and public services.

                                                                                                                                                                                                                                                Added to the source registry: 2019-05-25 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                  DragonForce

                                                                                                                                                                                                                                                  Aliases: DragonForce ransomware

                                                                                                                                                                                                                                                  DragonForce is an active ransomware and extortion operation that stands out by affiliate action, cartel-like positioning and technically creative abuse of normal business communications.

                                                                                                                                                                                                                                                  Added to the source registry: 2023-12-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                    dragonransomware

                                                                                                                                                                                                                                                    Ransomware.live source assessment: Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a compact 50KB file size, ultra-fast encryption speed, and a builder tool that allows users to personalize ransomware configurations.

                                                                                                                                                                                                                                                    Added to the source registry: 2024-12-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                      dread

                                                                                                                                                                                                                                                      Ransomware.live source assessment: Dread is a ransomware group that appears in tracking databases but has no publicly documented attacks or confirmed TTPs from major security vendors.

                                                                                                                                                                                                                                                      Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                        Dunghill

                                                                                                                                                                                                                                                        Aliases: Dunghill Leak, Dunghill

                                                                                                                                                                                                                                                        Dunghill especially if leak-site/extortion name appears and therefore has value for data breach claim

                                                                                                                                                                                                                                                        Added to the source registry: 2023-04-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                          DYSPHOR1A

                                                                                                                                                                                                                                                          Ransomware.live source assessment: Suspicious group. We did not manage to confirm any victims.

                                                                                                                                                                                                                                                          Added to the source registry: 2026-08-20 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                            eCh0raix

                                                                                                                                                                                                                                                            Aliases: eCh0raix, QNAPCrypt

                                                                                                                                                                                                                                                            eCh0raix specifically NAS- devices such as QNAP and Synology hit storage layers and thereby underlined ransomware target

                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                              Eclipse

                                                                                                                                                                                                                                                              Eclipse was added to Ransomware.live on 2026-08-11. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                              Added to the source registry: 2026-08-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                Eldorado

                                                                                                                                                                                                                                                                Aliases: Eldorado ransomware

                                                                                                                                                                                                                                                                Eldorado is a modern RaaS operation with Windows- and Linux variants and Go-based payload context in public CTI

                                                                                                                                                                                                                                                                Added to the source registry: 2024-06-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                  Embargo

                                                                                                                                                                                                                                                                  Aliases: Embargo ransomware

                                                                                                                                                                                                                                                                  Embargo is a modern Rust-based ransomware family that is paired in public CTI to double extortion and tooling like MDeployer/MDeleter

                                                                                                                                                                                                                                                                  Added to the source registry: 2024-04-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                    emperador

                                                                                                                                                                                                                                                                    emperador was added to Ransomware.live on 2026-08-12. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                    Added to the source registry: 2026-08-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                      EndZone

                                                                                                                                                                                                                                                                      EndZone is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.

                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                        Entropy

                                                                                                                                                                                                                                                                        Aliases: Entropy ransomware

                                                                                                                                                                                                                                                                        Entropy was linked by Sophos to attacks where Dridex/IcedID-like access preceded ransomware

                                                                                                                                                                                                                                                                        Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                          ep918

                                                                                                                                                                                                                                                                          Ransomware.live source assessment: EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly documented attacks or operational details.

                                                                                                                                                                                                                                                                          Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                            ESXiArgs

                                                                                                                                                                                                                                                                            Aliases: ESXiArgs ransomware

                                                                                                                                                                                                                                                                            vulnerable VMware ESXi systems could be hit massively and CISA recovery guide published

                                                                                                                                                                                                                                                                            Added to the source registry: 2023-02-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                              Ethics

                                                                                                                                                                                                                                                                              Ethics was added to Ransomware.live on 2026-08-12. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                              Added to the source registry: 2026-08-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                Everest

                                                                                                                                                                                                                                                                                Aliases: Everest ransomware, Everest extortion

                                                                                                                                                                                                                                                                                Everest developed from ransomware/extortion to broader data extortion and initial access-broker-like activity.

                                                                                                                                                                                                                                                                                Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                  ExfilSquad

                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Only exfiltration

                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                    exitium

                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targeting victims via bulk data exfiltration followed by public naming-and-shaming, with known victims including a Brazilian agro-industrial firm and a US county appraisal district.

                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-03-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                      exorcist

                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption.

                                                                                                                                                                                                                                                                                      Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                        Falcon

                                                                                                                                                                                                                                                                                        Falcon was added to Ransomware.live on 2026-08-28. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                        Added to the source registry: 2026-08-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                          fletchen

                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Fletchen is primarily documented as a sophisticated infostealer-as-a-service written in Rust, targeting browser credentials, cryptocurrency wallets, and financial data, used by groups including Hunters International; its developer also advertises ransomware services on underground forums.

                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-01-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                            flocker

                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via phishing, compromised RDP, and exploit kits using a double extortion model, and observed collaborating with FunkSec.

                                                                                                                                                                                                                                                                                            Added to the source registry: 2024-05-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                              Fog

                                                                                                                                                                                                                                                                                              Aliases: Fog ransomware

                                                                                                                                                                                                                                                                                              Fog is a ransomware variant that Arctic Wolf saw in 2024 in U.S. education and recreation sectors, with later reporting around SonicWall SSL VPN- activity.

                                                                                                                                                                                                                                                                                              Added to the source registry: 2024-07-16 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                frag

                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Frag is a ransomware group that emerged in late 2024, exploiting a critical Veeam Backup & Replication vulnerability (CVE-2024-40711) to compromise targets in industrial sectors, with blockchain analysis linking it to a shared wallet cluster with the Akira group.

                                                                                                                                                                                                                                                                                                Added to the source registry: 2025-03-24 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                  freecivilian

                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukrainian government websites — including sites offering surrender guidance to Russian troops — blending cybercrime with apparent state-aligned political objectives.

                                                                                                                                                                                                                                                                                                  Added to the source registry: 2022-12-31 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                    fsteam

                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware or extortion group

                                                                                                                                                                                                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                      fulcrumsec

                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.

                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-05-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                        FunkSec

                                                                                                                                                                                                                                                                                                        Aliases: FunkSec ransomware

                                                                                                                                                                                                                                                                                                        FunkSec is a young ransomware and extortion name that stands out by fast claim growth, low ransoms, hacktivist tone and claims around AI-supported tooling.

                                                                                                                                                                                                                                                                                                        Added to the source registry: 2024-12-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                          Galago

                                                                                                                                                                                                                                                                                                          Galago is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.

                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                            Gammax

                                                                                                                                                                                                                                                                                                            Gammax was added to Ransomware.live on 2026-07-30. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                            Added to the source registry: 2026-07-30 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                              GDLockerSec

                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Our team members are from different countries and we are not interested in anything else, we are only interested in dollars. We do not allow CIS, Cuba, North Korea and China to be targeted.

                                                                                                                                                                                                                                                                                                              Added to the source registry: 2025-01-24 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                genesis

                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, focusing heavily on data exfiltration and public leaking.

                                                                                                                                                                                                                                                                                                                Added to the source registry: 2025-10-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                  global

                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.

                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2025-06-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                    Global Secret Group

                                                                                                                                                                                                                                                                                                                    Aliases: GSG

                                                                                                                                                                                                                                                                                                                    Global Secret Group was added to Ransomware.live on 2026-07-26. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                      GodDamn ransomwhere

                                                                                                                                                                                                                                                                                                                      GodDamn ransomwhere was added to Ransomware.live on 2026-07-26. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                        Grief

                                                                                                                                                                                                                                                                                                                        Aliases: Grief ransomware, PayOrGrief

                                                                                                                                                                                                                                                                                                                        Grief historically is considered to be DoppelPaymer-like extortion operation with leak site publication

                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2021-05-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                          Groove

                                                                                                                                                                                                                                                                                                                          Aliases: Groove ransomware

                                                                                                                                                                                                                                                                                                                          Groove especially if ransomware/ecosystem name around former Babuk- or RAMP--like context occurred and less as a highly technically documented family

                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                            gunra

                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and manufacturing sectors across Japan, Egypt, Panama, Italy, and Argentina, deploying separate Windows and Linux variants with a strict five-day payment deadline.

                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-04-23 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                              hades

                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension.

                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2020-12-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                Handala

                                                                                                                                                                                                                                                                                                                                Aliases: Handala Hack Team, Handala ransomware

                                                                                                                                                                                                                                                                                                                                Handala especially if politically motivated hacktivist extortion name is used and therefore must be read differently than purely financial RaaS

                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2024-05-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                  haron

                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.

                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                    Helix

                                                                                                                                                                                                                                                                                                                                    Helix was added to Ransomware.live on 2026-08-07. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-08-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                      HellCat

                                                                                                                                                                                                                                                                                                                                      Aliases: HellCat ransomware

                                                                                                                                                                                                                                                                                                                                      HellCat as modern extortion name appears in feeds and is especially relevant via claims and data breach printing

                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2024-10-25 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                        helldown

                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.

                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2024-08-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                          hellogookie

                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: HelloGookie is a rebrand of the HelloKitty ransomware group announced in April 2024, releasing previously stolen data from CD Projekt Red and Cisco; HelloKitty/HelloGookie has been active since 2020 with its highest-profile attack being the 2021 breach of CD Projekt Red.

                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2024-04-19 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                            HelloKitty

                                                                                                                                                                                                                                                                                                                                            Aliases: HelloKitty ransomware, FiveHands

                                                                                                                                                                                                                                                                                                                                            HelloKitty historically known by attacks on large organizations and later source code leaks, with server and ESXi risk

                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                              Hive

                                                                                                                                                                                                                                                                                                                                              Aliases: Hive ransomware

                                                                                                                                                                                                                                                                                                                                              Hive was a large RaaS operation with broad sector impact, known for phishing, RDP/VPN, credential theft, log removal, data steal and double extortion.

                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-08-14 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                HolyGhost

                                                                                                                                                                                                                                                                                                                                                Aliases: HolyGhost ransomware, DEV-0530

                                                                                                                                                                                                                                                                                                                                                Microsoft HolyGhost paired to DEV-0530 and North Korean cyberactivity, with attacks on small businesses and ransomware extortion

                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                  hotarus

                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Hotarus Corp is a ransomware group that came to attention in early 2021 after attacking Ecuador's Ministry of Finance and Banco Pichincha — the country's largest private bank — deploying PHP-based ransomware and claiming to have stolen tens of millions of customer records.

                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                    Hunters International

                                                                                                                                                                                                                                                                                                                                                    Aliases: Hunters, Hunters International ransomware, World Leaks

                                                                                                                                                                                                                                                                                                                                                    Hunters International was an active double-extortion group that later was linked to shift towards World Leaks; the lessons remain relevant for data diary and affiliate transition.

                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2023-10-20 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                      iah6477

                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Archive without group name

                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-08-20 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                        Icarus

                                                                                                                                                                                                                                                                                                                                                        Icarus was added to Ransomware.live on 2026-05-05. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2026-05-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                          IceFire

                                                                                                                                                                                                                                                                                                                                                          Aliases: IceFire ransomware

                                                                                                                                                                                                                                                                                                                                                          IceFire is known for Windows- and Linux variants and consequently explicitly touches server environments and Linux workloads

                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2022-08-20 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                            IMNCrew

                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.

                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-05-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                              INC Ransom

                                                                                                                                                                                                                                                                                                                                                              Aliases: INC, INC Ransomware

                                                                                                                                                                                                                                                                                                                                                              INC Ransom is an active extortion group that is mainly relevant due to data diode, leak site claims and attacks on organizations where continuity and sensitive data weigh heavily.

                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2023-08-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                insane

                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Insane is a short-lived ransomware group that briefly surfaced in early 2024, claiming a single victim in Thailand before going quiet, with minimal documented activity or technical details available.

                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2024-01-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                  insomnia

                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient files and threatening public exposure rather than encrypting files — and avoiding former Soviet states, consistent with Russian-speaking cybercrime norms.

                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-02-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                    Interlock

                                                                                                                                                                                                                                                                                                                                                                    Aliases: Interlock ransomware

                                                                                                                                                                                                                                                                                                                                                                    Interlock has become a rapidly mature ransomware group that combines social engineering, ClickFix/FileFix-like techniques, RATs, cloud tools and multi-platform encryption.

                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-10-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                      J

                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 including FAI Aviation Group (Germany), operating primarily as a leak-site-centric extortion identity with limited public technical analysis.

                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-05-02 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                        kairos

                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments.

                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2024-11-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                          Karakurt

                                                                                                                                                                                                                                                                                                                                                                          Aliases: Karakurt Team, Karakurt Lair

                                                                                                                                                                                                                                                                                                                                                                          Karakurt is a data extortion group that mainly pressures on stolen data and according to CISA/FBI/Treasury/FinCEN sometimes hits victims alongside other ransomware incidents.

                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2022-12-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                            karma

                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating double-extortion attacks against enterprises in healthcare, manufacturing, and technology; the group was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains. Platforms: Windows and Linux

                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                              kawa4096

                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.

                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2025-06-27 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                kazu

                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations primarily in Southeast Asia, the Middle East, and Latin America, with notable claimed breaches including Dubai's Ports, Customs and Free Zone Corporation with 1.94 TB exfiltrated.

                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2025-11-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                  kelvinsecurity

                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: KelvinSecurity is a financially motivated hacking group active since at least 2015, primarily engaged in stealing and selling databases from telecommunications, healthcare, and political organizations worldwide, with notable breaches including Vodafone Italia and Frost & Sullivan; the group's leader was arrested by Spanish police.

                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2022-04-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                    killsec

                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split, primarily targeting healthcare, financial services, and government sectors with over 250 documented victims as of late 2025.

                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-03-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                      kittykatkrew

                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: KittyKatKrew is a newly emerged ransomware group first identified in early 2026, using both direct and double-extortion methods against US targets including the Arkansas State Crime Laboratory, operating under the alias KKK with Telegram and X/Twitter communication channels.

                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-02-19 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                        Knight

                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Knight ransomware, Cyclops successor

                                                                                                                                                                                                                                                                                                                                                                                        Knight as successor/continue development of Cyclops-like ransomware was described and used phishing/stealer like access

                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2023-09-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                          kraken

                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Kraken is a Russian-speaking ransomware group that emerged in February 2025, believed to have links to the HelloKitty operation, employing a RaaS model notable for a benchmarking step that measures victim machine speed to optimize encryption, and in September 2025 launched an underground criminal forum called "The Last Haven Board."

                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2025-02-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                            krybit

                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.

                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2026-04-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                              kryptos

                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Kryptos is a small ransomware group first observed in October 2025, conducting simultaneous attacks across North America and Oceania on its debut day with a focus on professional, technical, and legal service sectors, with only 3 known documented victims.

                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2025-10-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                kyber

                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Kyber is a recently identified ransomware group using sophisticated hybrid encryption (AES-256-CTR with X25519 and Kyber1024), operating Tor-based communication channels and employing double-extortion with free partial decryption offered to build negotiation trust, discovered through underground forum monitoring in 2025.

                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2025-10-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                  L Group

                                                                                                                                                                                                                                                                                                                                                                                                  L Group was added to Ransomware.live on 2026-08-07. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-08-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                    la_piovra

                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)

                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2023-06-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                      lamashtu

                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Romania, and Thailand across energy, pharmaceutical, and film sectors; it has not yet been confirmed as operating actual file-encrypting ransomware rather than pure data-theft extortion.

                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-04-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                        LAPSUS$

                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: LAPSUS$, DEV-0537

                                                                                                                                                                                                                                                                                                                                                                                                        the group showed how identity attacks, social engineering, MFA-fatigue and insider recruitment without classic ransomware can cause enormous damage

                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2026-03-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                          LeakBazaar

                                                                                                                                                                                                                                                                                                                                                                                                          LeakBazaar was added to Ransomware.live on 2026-05-10. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-05-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                            Leaknet

                                                                                                                                                                                                                                                                                                                                                                                                            Leaknet is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.

                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                              leaktheanalyst

                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims, notable for a 2017 operation targeting a Mandiant security researcher; the group focuses on stealing and publishing sensitive corporate data rather than deploying file-encrypting ransomware.

                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2022-01-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                Lilith

                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: Lilith ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                Lilith is a smaller double-extortion group with limited technical resources but clear leak-site value

                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                  linkc

                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI, cloud, aerospace, and manufacturing companies — including H2O.ai — demanding ransoms as high as $15 million using double-extortion tactics.

                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2025-02-19 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                    LockBit

                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: LockBit 3.0, LockBit Black

                                                                                                                                                                                                                                                                                                                                                                                                                    LockBit is an industrialized ransomware-as-a-service ecosystem with large affiliate variation, broad victim base and strong publication pressure.

                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2020-10-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                      LockBit 2.0

                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: LockBit2, LockBit 2.0 ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                      LockBit 2.0 professionalisation of LockBit as RaaS made visible with StealBit data exfiltration and broad affiliate effect

                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                        LockBit 3.0

                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: LockBit Black, LockBit 3.0

                                                                                                                                                                                                                                                                                                                                                                                                                        LockBit 3.0 a mature RaaS version was with bug bounty, fast adjustment and great global impact

                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2022-06-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                          LockBit 5.0

                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: LockBit5, LockBit 5.0

                                                                                                                                                                                                                                                                                                                                                                                                                          LockBit 5.0 especially if new or claimed version/feed name is relevant after disruption of main operation

                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2025-12-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                            lockbit3_fs

                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.

                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                              LockData

                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: LockData ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                              LockData as smaller feed name has especially value for claim triage and historical searchability

                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                Loki

                                                                                                                                                                                                                                                                                                                                                                                                                                Loki was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                  lolnek

                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Lolnek (also known as Lolkek/GlobeImposter) is a commodity ransomware strain primarily targeting small and medium-sized businesses with relatively low ransom demands, associated with the TZW ransomware family, and unsophisticated compared to major RaaS operations with no formal affiliate program.

                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                    Lorenz

                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: Lorenz ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                    Lorenz is a historical double-extortion group, often linked to targeted attacks and leak site publication.

                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2020-01-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                      losttrust

                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US.

                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2023-09-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                        lunalock

                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid.

                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2025-09-02 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                          LV

                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: LV ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                          LV historically discussed as a REvil-like or LockBit-like extortion line and is especially relevant by leak-site claims

                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2021-11-22 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                            Lynx

                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: Lynx ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                            Lynx is a modern double-extortion group that is mainly relevant due to fast claim growth, data diary and similarities with older ransomware code or operator patterns.

                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2024-07-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                              m3rx

                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.

                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2026-04-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                madcat

                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: MadCat is a suspected fraudulent ransomware operation that surfaced briefly in late 2023, apparently linked to scammers targeting other criminals on the dark web with fake stolen passport offers; its leak site appeared dead shortly after announcement, casting doubt on whether it ever operated as a genuine ransomware group.

                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                  madliberator

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption patterns, targeting government entities including the Italian Ministry of Culture and using a data leak site to post exfiltrated files.

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2024-07-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                    majinahanashi

                                                                                                                                                                                                                                                                                                                                                                                                                                                    majinahanashi was added to Ransomware.live on 2026-08-12. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-08-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                      malas

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its targets, victims, or operational model is limited in public reporting.

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2023-04-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                        malekteam

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel), believed to be tied to Iranian military intelligence, primarily targeting Israeli organizations using data exfiltration and extortion, with notable attacks on Ziv Medical Center and Ono Academic College.

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2023-12-24 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Mallox

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: Mallox ransomware, TargetCompany

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Mallox is a ransomware family that is often linked to exposed MS-SQL servers, brutal force and opportunistic enterprise extortion in public CTI.

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2022-11-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                            mamona

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed before reverting; as a standalone strain it operates entirely offline with no C2 communication, uses custom encryption, and targets Windows systems.

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-03-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                              marketo

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or back to victims without encrypting files, applying aggressive pressure by emailing victims' competitors with sample data packs.

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-12-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Maze

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: Maze ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Maze was an early double-extortion group that published data to put pressure on and thus co-formulated the modern ransomware model.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2019-10-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  mbc

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: MBC is a very obscure ransomware group with minimal public documentation and no significant threat intelligence reports available from mainstream security vendors.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Medusa

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: Medusa ransomware, Medusa RaaS

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Medusa is a RaaS operation with double extortion,IAB- use,Rclone -exfiltration, gaze.exe deployment and a countdown leak site.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2023-01-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      MedusaLocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: MedusaLocker ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      this family has been coming back in incidents for years and should not be confused with the separate Medusa RaaS operation

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2022-11-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        meow

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning to a data-extortion-only model — selling stolen data rather than encrypting files — with a heavy focus on US healthcare and medical research organizations.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2023-11-24 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Meowciety403

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Meowciety403 was added to Ransomware.live on 2026-08-27. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-08-27 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            MetaEncryptor

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: MetaEncryptor ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            MetaEncryptor especially if modern feed name and double-extortion claim occurs with limited hard technical advice

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2023-08-16 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              midas

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-11-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                mindware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Ransomware, potential rebranding of win.sfile.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2022-05-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  minteye

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction, engineering, architecture, and logistics sectors, with victims documented in the US and Chile; limited public technical analysis is available.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2025-12-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    mnt6

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: MNT6 is a lower-profile ransomware group claiming victims across legal, manufacturing, construction, healthcare, and logistics sectors in the US, Canada, New Zealand, and Spain, with notable claimed targets including Silfab Solar; some victim listings have been flagged as potentially unverified.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-04-30 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      mogilevich

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, but was quickly exposed as a fraud — the group's operator admitted they were "professional fraudsters" who sold fake breach data and access to a non-existent RaaS panel.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2024-02-20 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Money Message

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Money Message ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Money Message is a ransomware variant that Sophos examined step by step; the Windows version was seen as windows.exe and writes among others C:\money_message.log.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2023-03-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Montage

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Montage was added to Ransomware.live on 2026-08-13. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-08-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Monti

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: Monti ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Monti is a ransomware group that is often discussed by similarities with Conti and later deviations in encryption tooling.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2022-12-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              morpheus

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2025-01-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                mortar

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                mortar was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Moses Staff

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: MosesStaff, Moses Staff

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Moses Staff more destructive/hacktivistic pressure used than classic financially motivated ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2021-12-18 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    MountLocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: MountLocker ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    MountLocker historically a RaaS operation that later came back in multiple rebrands/ecosystems

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2021-02-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ms13089

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-12-18 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        mydecryptor

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          n3tworm

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: N3tw0rm ransomware group is linked to Iran by many security researchers especially for the fact that the group targeting only Israeli companies. Like other ransomware groups, N3tw0rm has a data leak site in the darknet.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            nasirsecurity

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle East (UAE, Oman, Saudi Arabia, Iraq) and Israeli IT supply chain firms, using spear-phishing, BEC, and exploitation of public-facing applications.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-10-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              nblock

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              nblock was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Nefilim

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: Nefilim ransomware, Nephilim

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Nefilim was a ransomware operation linked to major corporate attacks;DOJ /FBI- context around LockerGoga/MegaCortex/Nefilim underlines enterprise impact.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2020-05-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Nemty

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: Nemty ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Nemty historically relevant as RaaS/ransomware family from the pre-modern double-extortion period

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    netrunner

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-04-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      NetWalker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: NetWalker ransomware, Mailto

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      NetWalker was a RaaS operation that linked FBI/CISA to attacks on education, care and public sector, with phishing, COVID-19-theme raptures and double extortion.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2020-01-31 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Nevada

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Nevada ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Nevada if Rust-based ransomware-as-a-service was announced and is especially relevant as cross-platform server risk

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Night Sky

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: NightSky ransomware, Night Sky

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Night Sky was known by double extortion and public analyses on human-operated ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2022-01-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            nightspire

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-03-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Nitrogen

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: Nitrogen ransomware, Nitrogen campaign

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Nitrogen is particularly relevant as initial access campaign that can result in ransomware such as BlackCat, Black Basta or other payloads via malvertising, SEO-poisoning and software imitation.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2024-09-30 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                NoEscape

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: NoEscape ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                NoEscape is a 2023 RaaS operation with Windows and Linux payloads, multi-extortion and TOR- based affiliate and leaksite infrastructure.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2023-06-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Nokoyawa

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: Nokoyawa ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Nokoyawa appeared in 2022 and was compared by researchers to Hive; later Nokoyawa was associated with zero-day exploitation chains such as CVE-2023-28252.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2022-12-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    NoName

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: NoName ransomware, NoName057(16) context

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    NoName claims sometimes are hacktivist or DDoS-like and therefore need to be read differently than financial RaaS

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-01-16 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      NotPetya

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      NotPetya was added to Ransomware.live on 2017-01-01. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2017-01-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        nova

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2025-04-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          obscura

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2025-09-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            OnePercent Group

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: OnePercent, OnePercent ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            FBI /CISA This group was linked to long-term access,Cobalt Strike and ransomware extortion against American organizations

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Onyx

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: Onyx ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Onyx historically known as ransomware that could destroy files instead of reliable encryption

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2022-04-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                orca

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2024-09-16 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  orion

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Orion is a ransomware operation first observed in October 2025 that listed 13 alleged victims on a dark web leak site across financial services, manufacturing, and healthcare, though analysts determined its victim list was recycled from prior LockBit and BlackCat disclosures rather than fresh compromises.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-01-14 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Orova

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: First seen 2026-07-07

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-07-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      osiris

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint detection tools before deploying hybrid ECC + AES-128-CTR encryption; Symantec researchers linked its operators to former INC ransomware affiliates.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-12-18 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Pandora

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Pandora ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Pandora especially if dual-extortion name occurs in feeds and requires claim triage around leak site publication

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2022-03-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Panzer

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Panzer was added to Ransomware.live on 2026-08-05. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-08-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Pay2Key

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: Pay2Key ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Pay2Key was linked by Check Point to targeted attacks on Israeli organizations with rapid lateral movement

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2020-12-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Payday

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Payday was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                payload

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2026-02-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  PayloadBIN

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: PayloadBIN ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  PayloadBIN is a Babuk-like ransomware name that was discussed in public reporting as successor/variant after the Babuk leak.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    payoutsking

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2025-07-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      pear

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-08-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Play

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Play ransomware, PlayCrypt, Playcrypt

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Play is a ransomware group in which valid accounts, public applications, edge vulnerabilities, log removal and unique binaries per attack are important.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2022-11-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          playboy

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: PlayBoy Locker is a ransomware-as-a-service operation that emerged in September 2024, targeting Windows, NAS, and ESXi systems across multiple sectors on an 85/15 affiliate revenue split; its source code was reportedly sold underground by late 2024.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2024-10-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            PrinzEugen

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            PrinzEugen was added to Ransomware.live on 2026-05-04. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2026-05-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              projectrelic

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-based data leak site and using double-extortion tactics, with operators dwelling in networks for days or weeks before encrypting.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2022-11-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ProLock

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: ProLock ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ProLock historically linked to QakBot access and thus gives a strong lesson about botnet-to-ransomware chains

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2020-02-23 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Prometheus

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: Prometheus ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Prometheus was a historical double-extortion group that presented itself as Conti partner but is technically documented in limited detail

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    promptlock

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2025-08-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      PYSA / Mespinoza

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: PYSA, Mespinoza ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      PYSA/Mespinoza is known for attacks on educational institutions and double extortion, with FBI- warnings about schools, higher education and seminars.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2020-07-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Qilin

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Agenda, Qilin ransomware, Agenda ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Qilin, previously also called Agenda, is a RaaS operation with strong emphasis on double extortion, care impact, Linux/ESXi payloads and defense avoidance.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2022-10-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          qiulong

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double extortion and unique tactics such as publishing identity documents of victims' family members to pressure payment.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2024-04-22 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Qlocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: Qlocker ransomware, QNAP Qlocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Qlocker massive QNAP NAS-systems hit by plugging files into password protected 7z archives

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Quantum

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: Quantum ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Quantum is known from DFIR-cases in which IcedID access quickly resulted in ransomware, often within short dwell time.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                RA World

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: RA Group, RA World ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                RA World, previously often referred to as RA Group, is a double-extortion operation that is mainly relevant by enterprise targets, data digs and publication via leak infrastructure.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2023-05-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  rabbithole

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: RabbitHole is a low-profile ransomware group with limited publicly available threat intelligence, not appearing prominently in major threat intelligence reports, suggesting it operates at a small scale or under limited visibility.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    radar

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: Radar (also known as Dispossessor), active since August 2023 and led by an actor called "Brain," was a RaaS group targeting small-to-mid-sized businesses across healthcare, education, finance, and transportation in over 14 countries; it was dismantled by an FBI-led international operation in August 2024 that seized 24 servers and 9 criminal domains.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2025-09-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      radiant

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-10-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ragnar Locker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: RagnarLocker, Ragnar Locker ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ragnar Locker is a big-game ransomware group that was linked to critical infrastructure by FBI/CISA-alerts and later disrupted by international actions.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2020-04-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ragnarok

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: Ragnarok ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ragnarok historically was a ransomware group that later released decryption keys and therefore has mostly historical and recovery value

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2021-03-31 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ralord

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and IT sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split; it later rebranded as "Nova."

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-03-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              RAMP

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: RAMP ransomware forum, RAMP ecosystem

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              RAMP more a ransomware forum/ecosystem name is than one locker, but it is relevant to affiliate and threat context

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                rancoz

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2023-05-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ranion

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model where affiliates keep 100% of ransom payments, with packages ranging from $150 to $1,900, making it a popular entry point for less experienced attackers.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransom Cartel

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: RansomCartel

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransom Cartel is a ransomware group that is often discussed by similarities with REvil-like ecosystems and double extortion.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ransombay

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-05-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ransomcortex

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: RansomCortex emerged in July 2024 with a narrow focus on healthcare facilities, claiming four victims within days of its first appearance including hospitals in Brazil and Canada, operating as a relatively small and niche group.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2024-07-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ransomed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims including Sony, innovating by threatening GDPR regulatory fines as an additional extortion lever; it briefly operated as a RaaS before shutting down in an apparent exit scam following reported arrests of six members.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2023-08-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            RansomEXX

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: RansomEXX, Defray777

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            RansomEXX is a targeted ransomware family known by Windows- and Linux variants for large organizations.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2020-05-14 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              RansomHouse

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: RansomHouse

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              RansomHouse is mainly a data extortion group that deviates from classic ransomware by emphasising data ditadestal instead of encryption.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-06-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                RansomHub

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: RansomHub ransomware, RansomHub RaaS

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                RansomHub is an active RaaS ecosystem with affiliate-driven attacks, broad victim claims, data digs and strong publication pressure.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2024-02-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ranstreet

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: Ranstreet

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ranstreet is a low-confidence feed name. There is little reliable public technical information, which essentially helps with source validation, victim interpretation and defensive triage.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2023-12-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ranzy Locker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: Ranzy Locker, Ranzy

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ranzy Locker historically originated from the ThunderX/Ranzy line and has especially value as a double-extortion case

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Raznatovic

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: Raznatovic

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Raznatovic is a low-confidence ransomware feed name with little reliable technical explanation. Treat claims as signals that first need source and victim verification.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2023-12-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        RebornVC

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Reborn VC, RebornVC

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        RebornVC is a limited documented feed name. The profile is aimed at validating claims and defense against general data extortion.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2025-07-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Red Ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: RedRansomware, Red ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Red Ransomware is a name that should be interpreted with caution: there is limited public technical detail information, but it fits the broader pattern of extortion through access, data and publication printing.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2024-03-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Redact

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Redact was added to Ransomware.live on 2026-06-28. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2026-06-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              RedAlert / N13V

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: RedAlert ransomware, N13V

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              RedAlert/N13V is known by Linux/VMware ESXi-like ransomware context and consequently hits server layers

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2022-07-14 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                REvil / Sodinokibi

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: REvil, Sodinokibi, Sodin

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                REvil/Sodinokibi was a major RaaS operation known for double extortion, MSP/supply-chain impact and the Kaseya VSA- campaign.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2019-08-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Reynolds

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: Reynolds ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Reynolds is a limited documented ransomware feed name. The profile value is in structured claim validation and practical hunts on access, data and recovery.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-02-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Rhysida

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: Rhysida ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Rhysida is a RaaS operation that hits targets of opportunity and often uses VPN- access with valid credentials, RDP, PowerShell and log removal.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2023-06-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      RobinHood

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: RobbinHood ransomware, RobinHood ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      RobbinHood's Baltimore case showed how ransomware can disrupt municipal services for months

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2021-12-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Rook

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Aliases: Rook ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Rook was a ransomware group that became visible at the end of 2021 and was linked to code overlap with Babuk. The profile is especially useful for lessons around reused ransomware code and enterprise impact.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2021-12-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Royal / BlackSuit

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: Royal ransomware, BlackSuit, Royal ransomware group

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Royal, later publicly linked to BlackSuit, is a double-extortion operation that combines phishing, remote access, legitimate tools and targeted encryption.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2022-11-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Rransom

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: Rransom

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Rransom is a low-trust feed name without solid public technical file. The profile monitors mainly source validation and generic defense value.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Runsomewares

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: Runsomewares

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Runsomewares is a limited documented feed name. Use claims under this name for triage, victim history and defensive controls against data diode and encryption.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2025-02-27 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Sabbath

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Aliases: Sabbath ransomware, UNC2190, Arcane

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Sabbath is a ransomware/extortion operation that is linked to UNC2190 and Arcane-like activity in public analysis. The profile is relevant through hands-on intrusions, data diary and printing via publication.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2021-11-22 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  SafePay

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: SafePay ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  SafePay is a rapidly growing double-extortion group that affects organizations through access, data diary, disruption and pressure via a leak site.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2024-11-19 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Sarcoma

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: Sarcoma ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Sarcoma is a double-extortion group in which data diary, leak-site claims and pressure on organizations with sensitive data are central.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-10-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      satanlockv2

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after claiming attacks against roughly 67 organizations — though over 65% of listed victims were duplicates from other groups — leaking all stolen data publicly upon shutdown.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-07-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        secp0

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2025-03-14 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Section9

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: 🚨 This is a fake group with fake victims.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-07-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            securotrop

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while maintaining an independent public identity, focusing exclusively on commercial targets and deliberately avoiding healthcare and government entities, with approximately 32 documented victims.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-07-22 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              SenSayQ

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortion attacks; Group-IB links it operationally to the Brain Cipher group and its siblings EstateRansomware and "Noname," suggesting a shared operator.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                settra

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                settra was added to Ransomware.live on 2026-06-28. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2026-06-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  SevyWare

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Direct Extortion Double Extortion

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    shadow

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; specific attribution details regarding its targets, origin, or scale remain sparse in published threat intelligence reports.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ShadowByt3$

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-02-25 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        shaoleaks

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but lacking detailed analysis by major threat intelligence firms, suggesting a very limited or short-lived operation.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2022-11-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Shiba

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Shiba was added to Ransomware.live on 2026-07-27. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-07-27 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ShinyHunters

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: UNC6040, UNC6240, Scattered Lapsus$ Hunters

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ShinyHunters is not a classic encryption group but a data diode and extortion brand that leans heavily on SaaS, social engineering, tokens and cloud data.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-10-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ShinySp1d3r

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Likely associated with the cybercrime group BlingLibra (ShinyHunters)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2025-11-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                sicarii

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targeting Arab and Muslim-majority organizations while avoiding Israeli systems, exploiting exposed RDP services and Fortinet devices, with its admin later instructing operators to migrate to the BQTLock platform.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2025-12-30 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  siegedsec

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: Not a ransomware group but a hacktivist group that appeared coincidentally days before Russia’s invasion of Ukraine

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2023-12-08 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    silent

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own statement, they avoid public negotiations and encrypt minimal data.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2025-04-23 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Silent Ransom Group

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Aliases: SRG, Luna Moth, Chatty Spider, UNC3753

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Silent Ransom Group mainly uses callback phishing and social engineering to abuse support or management relationships and steal data without classical encryption.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-05-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        sinobi

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware lineage, claiming 176 victims by end of 2025 through double-extortion attacks primarily against mid-market US organizations via compromised SonicWall VPN credentials.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2025-07-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          skira

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Skira is a small ransomware group that emerged around late 2024, claiming responsibility for the breach of Carruth Compliance Consulting that exposed SSNs, W-2s, and financial records of employees across 36 US school districts, with five total claimed victims across the US, Turkey, and India.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2025-03-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            slug

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing company) recorded on ransomware tracking platforms; no detailed threat intelligence reports exist for this group.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2024-01-18 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Snatch

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: Snatch ransomware, Team Truniger

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Snatch is a RaaS operation known for RDP- abuse, long dwell time, data exfiltration and encryption from Windows Safe Mode.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-11-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                solidbit

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Ransomware, written in .NET.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Sovcali

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Sovcali was added to Ransomware.live on 2026-08-09. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-08-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Space Bears

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Aliases: Space Bears ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Space Bears is a double-extortion name with public victim claims but limited hard technical publications; treat claims as extortion information that needs to be technically validated.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-04-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      sparta

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Sparta is a short-lived ransomware group first observed in September 2022 that conducted double-extortion attacks primarily targeting organizations in Spain before ceasing activity, gaining initial access via phishing and exploitation of unpatched systems.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2022-09-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Spirals

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Spirals is new in the ransomware feed. This profile was created automatically and must be enriched manually before it is used as a full actor profile.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          spook

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on the Thanos builder), conducting double-extortion attacks against global targets with a concentration in manufacturing and unusually publishing all victim names regardless of ransom payment.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2021-10-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Storm

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Storm was added to Ransomware.live on 2026-08-07. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2026-08-07 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Stormous

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: STORMOUS, Stormous ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Stormous is a politically coloured extortion and ransomware name known primarily by claims, publication print and opportunistic data breach communication.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2022-03-22 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                sugar

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Ransomware, written in Delphi.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  SunCrypt

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Aliases: SunCrypt ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  SunCrypt was a ransomware group known by double extortion, data diary and printing media such as publication and sometimes DDoS threat.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2020-08-24 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    synack

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process injection technique to evade detection; in August 2021 the group rebranded as El_Cometa, transitioning to a full RaaS model and releasing master decryption keys for prior victims.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2021-03-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      teamxxx

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, agriculture, hospitality, financial services, and shipping sectors in the US, UK, Norway, Ireland, and Europe within its first months.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-06-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        tengu

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2025-10-23 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Termite

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Aliases: Termite ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Termite is a ransomware group that became visible at the end of 2024/2025 and is linked to Babuk-like code, supply-chain impact and large data exfil claims.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2024-11-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            The Gentlemen

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Aliases: Gentlemen ransomware, TheGentlemen

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            The Gentlemen is a rapid-on-the-spot RaaS operation from 2025/2026 that is particularly relevant due to speed, proxy infrastructure and industrial victim claims.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-09-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              The Green Blood Group

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              The Green Blood Group was added to Ransomware.live on 2026-02-04. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2026-02-04 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                The Syndicate

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Data Broker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  thegreenbloodgroup

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-01-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    TiMc

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-04-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      titan

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: Founded 4 April 2026

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-05-18 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Tommyleaks

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Tommyleaks was added to Ransomware.live on Date unknown. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          toufan

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Pro-Palestinian Group

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2023-12-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            tridentlocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of regulated or third-party data — including government services, telecom, and engineering firms — across the US, Canada, UK, and Asia using double-extortion tactics.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-11-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              trigona

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2023-04-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                trinity

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2024-06-11 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Triple X

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Triple X was added to Ransomware.live on 2026-06-13. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2026-06-13 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    trisec

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: Trisec is a Tunisian-origin ransomware group that emerged in February 2024, claiming affiliation with the Tunisian government and operating as both a financially motivated and state-sponsored mercenary group, exclusively recruiting Tunisian members and reporting nine victims in the first half of 2024.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-02-16 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      u-bomb

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: U-Bomb is a low-profile ransomware operation discovered in March 2023 that arrives via phishing emails and uses third-party offensive frameworks (BRC4, Sliver, Cobalt Strike) for lateral movement before deploying its encryptor, likely becoming inactive in the second half of 2023.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ULose

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ULose was added to Ransomware.live on 2026-06-09. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2026-06-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          underground

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2024-05-01 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            unknown

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: "Unknown" is a catch-all tracking label used on ransomware monitoring platforms for attacks where the responsible threat actor has not been positively attributed to a known named group, serving as a placeholder for unattributed incidents.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              unsafe

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: A group which seems to recycle leak from other ransomware groups

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2022-12-21 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ValenciaLeaks

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of data and publishing it on a dedicated leak site, with documented victims including the City of Pleasanton, CA (283 GB exfiltrated) and pharmaceutical firm Duo Pharma Biotech.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2024-09-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  VanHelsing

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2025-03-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    vanirgroup

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: VanirGroup is an Eastern European ransomware group composed of former affiliates from Karakurt, LockBit, and Knight ransomware that emerged in mid-2024, before German law enforcement (Karlsruhe Public Prosecutor's Office) seized its leak site.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2024-07-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      vect

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-01-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        vendetta

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: Ransomware, which appears to be a rebranding of win.cuba.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2023-02-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Vexy Ransomware

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Vexy Ransomware was added to Ransomware.live on 2026-09-03. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2026-09-03 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            vfokx

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentation and no detailed analysis or named victims published by major threat intelligence vendors.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Vice Society

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Aliases: Vice Society, DEV-0832

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Vice Society is a blackmail actor who was best known for attacks on education and public sector, using existing ransomware variants instead of having a completely private locker.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: 2021-05-31 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Wallstreet

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Wallstreet was added to Ransomware.live on 2026-06-26. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2026-06-26 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  walocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and government entities, with a notable attack breaching Myanmar's Union Civil Service Board and exposing data on approximately 200,000 government officials.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2025-06-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    wannacry

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2017-05-12 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      warlock

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Ransomware.live source assessment: The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2025-06-10 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        werewolves

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2023-12-20 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          weyhro

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2025-03-06 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            worldleaks

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ransomware.live source assessment: World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2025-05-16 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              x001xs

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing standard double-extortion tactics with no detailed technical analysis published by major vendors.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                xinglocker

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: XingLocker is a ransomware group that emerged in May 2021 as part of a franchise-style RaaS model built on a customized MountLocker payload, using IcedID for initial access and Windows Active Directory APIs for worm-style lateral movement across networks.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2021-04-29 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  xinof

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    xp95

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware.live source assessment: XP95 is a cyber-extortion group that emerged in March 2026, using a pure data-theft-and-extortion model with a Windows XP/95-themed leak site, with notable targets including Statistics South Africa (154 GB exfiltrated) and the Gauteng Provincial Government.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Added to the source registry: 2026-03-17 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      xpl0itrs

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      xpl0itrs was added to Ransomware.live on 2026-08-15. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Added to the source registry: 2026-08-15 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        yanluowang

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Ransomware.live source assessment: According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the README.txt file containing a ransom note. It appends the .yanluowang extension to filenames.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Added to the source registry: 2022-07-02 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          yurei

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ransomware.live source assessment: Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Added to the source registry: 2025-09-05 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ZaWoo

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ZaWoo was added to Ransomware.live on 2026-08-30. The consulted group metadata does not contain a substantive technical description.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Added to the source registry: 2026-08-30 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              zeon

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ransomware.live source assessment: Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of former Conti "Team One" members, deliberately avoiding the RaaS model and keeping its code and infrastructure private.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Added to the source registry: Date unknown · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                zerolockersec

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Ransomware.live source assessment: ZeroLockerSec is a small ransomware group with very limited public documentation that became inactive by Q2 2025 with no recorded leak posts, suggesting a brief operational period before going dormant.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Added to the source registry: 2025-04-28 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Read the actor profile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  zerotolerance

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Ransomware.live source assessment: ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named victim reports published by major threat intelligence vendors.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Added to the source registry: 2024-05-09 · Source snapshot: 2026-09-15

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Limited publicly documented technical evidence for this actor.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Latest five known victim claims

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Loading stored claims…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Read the actor profile
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Victim digest

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Receive new victim claims by email

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Choose a daily overview for the last 24 hours or a weekly overview for the previous week. The email explicitly states that these are darknet and feed claims, not confirmed incidents.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Account required

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Log in or create a free account

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    We link this email preference to your account, so you can later choose daily, weekly or off yourself.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Featured dossiers

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Actor profiles that belong here first

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Not because these are the only relevant actors, but because they show how different motivation, access and impact can be.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware · High

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Qilin / ransomware clusters

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Double extortion, supply chain pressure and rapid impact on production and healthcare environments.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Access: Edge exposure, brokers, misconfigurations and stolen credentials.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Watch for: Privilege escalation, data theft tooling and pressure on business continuity.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Espionage · Targeted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    APT29 / diplomatic espionage

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Longer dwell time, quiet cloud abuse scenarios and high-value targets.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Access: Phishing, OAuth abuse, trusted cloud channels and stealthy persistence.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Watch for: Identity hygiene, mailbox rules, delegated grants and admin activity.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Identity abuse · Accelerating

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Scattered Spider-like operators

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Social engineering, helpdesk abuse and cloud access through identity bypass.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Access: SIM swap, helpdesk routes, MFA fatigue and privilege abuse.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Watch for: Conditional Access, admin separation and recovery accounts.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Actor families

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Which main groups matter most for organisations

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    The live version should show a clear pattern not only per actor, but also per actor family.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ransomware operators

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    The highest visibility is often around ransomware groups, but the real value of actor profiling lies in access patterns, brokers, tooling and the pace at which business pressure is created.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Strong focus on impact, public pressure and recovery cost
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Often dependent on IABs, exposed edge or identity abuse
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Highly relevant to leadership, continuity and insurability

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Espionage and state-linked actors

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    This is less about visible disruption and more about quiet access, long-term presence and targeted information advantage. Executive relevance sits mainly in provability, governance and confidentiality.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • More stealth, longer dwell time and more cloud-focused tradecraft
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Strong emphasis on identities, mail and app access
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • More relevant to government, semi-public and diplomatic chains

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Ecosystem actors and brokers

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Not every actor is the final attacker. Brokers, stealer ecosystems and access resellers create the fuel other campaigns build on. That layer is critical for early warning.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Credentials and sessions are the core issue
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Strong overlap with infostealers, phishing and dark web resale
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Highly relevant for monitoring and access hygiene prioritisation