Security Intelligence

Security Intelligence

Ransomware Groups

A directory of known ransomware threat groups. Browse active and historical groups, their tactics, and associated attacks.

Understanding Ransomware Threat Groups

The ransomware ecosystem is run by organized threat groups that operate like businesses — with affiliate programs, negotiation teams, and dedicated leak sites. Each group has its own tactics, preferred targets, and level of sophistication. Understanding who these actors are is essential for threat intelligence teams building detection rules, incident responders attributing an attack, and risk analysts evaluating exposure to specific adversaries.

This directory catalogs every known ransomware group tracked by the community, ranked by confirmed victim count. Use it to research a group’s history, compare their activity levels, and identify which threat actors are most active right now. If your organization or industry appears among a group’s recent victims, that is an immediate signal to harden defenses against their known techniques and tooling.

Ransomware Groups Directory

277 groups
lockbit3
2,016
LockBit, also recognized as LockBit Black or Lockbit 3.0, is one of the largest Ransomware Groups in the world and...
qilin
1,931
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes;...
akira
1,524
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to...
play
1,268
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America....
clop
1,254
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting...
lockbit2
1,002
LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via...
ransomhub
842
The group emerged in mid-February 2024 and has already listed several organizations as alleged victims of their attacks, resulting from...
incransom
832
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors...
alphv
731
aka blackcat
The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to promote...
dragonforce
580
DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue...
bianlian
552
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as...
blackbasta
523
"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February...
medusa
517
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including...
thegentlemen
504
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by...
safepay
502
SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all...
8base
455
The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. This group...
lynx
414
Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold...
everest
365
Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit...
conti
351
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems....
dispossessor
344
This is not a ransomware group but a data broker
pysa
309
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware...
hunters
307
In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold,...
nightspire
293
NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing,...
killsec
281
KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially...
lockbit5
278
LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform...
sinobi
274
Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware...
rhysida
273
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks...
cactus
248
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain...
royal
211
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to...
hive
208
Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by...
ransomhouse
198
RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120...
fog
189
Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat...
vicesociety
188
Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations...
blacksuit
184
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
devman
184
aka Devman 2.0
Former RansomHub and INC Ransom affiliate.
babuk2
180
aka Satanlock
Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on...
coinbasecartel
177
CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve...
stormous
177
Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across...
handala
175
Not a Ransomware Group
funksec
172
FunkSec is an AI-assisted ransomware-as-a-service group that launched its data leak site in December 2024 and rapidly claimed over 85...
malas
170
Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its targets, victims, or...
worldleaks
167
World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file...
cloak
165
Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in Europe — especially Germany — across...
blackbyte
147
Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.
apt73
146
aka bashe
A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that...
avaddon
146
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware...
meow
145
Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning...
snatch
142
Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections...
sarcoma
141
Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally...
nova
140
Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying...
spacebears
136
Space Bears is a double-extortion ransomware group that emerged in April 2024, distinguished by a professional "corporate" aesthetic on its...
ragnarlocker
128
Ragnar Locker was an elite ransomware group active from December 2019 to October 2023 that targeted large enterprises and critical...
shinyhunters
128
ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake)...
noescape
126
NoEscape was a RaaS operation active from May to December 2023 believed to be a rebrand of the defunct Avaddon...
raworld
126
aka ragroup
RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.
silentransomgroup
117
aka leakeddata
toufan
117
Pro-Palestinian Group
eldorado
112
interlock
110
Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and...
monti
110
Monti is a ransomware group first observed in June 2022 that initially copied nearly all of Conti's leaked source code,...
cuba
103
aka Colddraw
The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a...
payoutsking
100
aka Payouts King
PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of...
arcusmedia
98
Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and...
revil
96
Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his...
pear
95
aka Pure Extraction And Ransom
Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private...
abyss
90
Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source...
genesis
90
Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail,...
kairos
88
Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily...
ransomexx
85
RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
threeam
85
aka 3Am
A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by...
anubis
83
Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates...
lorenz
78
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the...
warlock
78
The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known...
cicada3301
75
Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting...
direwolf
75
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting...
karakurt
74
Karakurt is a pure data-extortion group (no encryption) assessed with high confidence to be the extortion arm of the Conti...
avoslocker
70
AvosLocker is the ransomware payload of the Avos RaaS group, active from July 2021 to approximately May 2023, targeting education,...
beast
70
aka GIGAKICK
Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and...
quantum
68
Quantum ransomware, active from mid-2021 through 2022, was a rebrand of the MountLocker/AstroLocker/XingLocker lineage that operated as RaaS, known for...
ransomed
68
RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims including Sony, innovating by...
medusalocker
67
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP,...
blacklock
64
BlackLock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most...
lv
63
LV ransomware group main message: "Here are companies which didn't meet consumer data protection obligations. They rejected to fix their...
braincipher
59
flocker
59
Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via...
maze
59
Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers...
chaos
57
Chaos is a ransomware-as-a-service operation that emerged in early 2025, likely formed by former BlackSuit/Royal members, offering cross-platform ransomware for...
darkvault
55
DarkVault is a data-exfiltration and double-extortion group first identified in late 2023, targeting medium-to-large organizations in finance, professional services, legal,...
payload
55
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems...
losttrust
53
LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching...
krybit
52
Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support...
mallox
49
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to...
tengu
49
Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land...
trigona
49
According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the...
knight
48
[Cyclops](group/cyclops) rebrand
nitrogen
48
Nitrogen began as a malware loader in 2023 used to deliver BlackCat/ALPHV ransomware, then evolved into a fully independent ransomware...
crypto24
46
Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services,...
termite
46
Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most...
midas
44
This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is...
blackshrantac
43
BlackShrantac is a ransomware group that emerged in late 2025, targeting organizations in manufacturing, financial services, technology, and the public...
donutleaks
42
Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks...
gunra
42
Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and...
j
41
ailock
39
darkleakmarket
39
DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransomware...
dragonransomware
39
Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a compact 50KB file size,...
embargo
39
Embargo is a Rust-based ransomware-as-a-service group that emerged in April 2024, primarily targeting US healthcare, manufacturing, and business services organizations...
securotrop
37
Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while maintaining an independent...
ciphbit
36
CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with...
helldown
36
Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial...
insomnia
36
Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient...
nokoyawa
36
Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting...
arvinclub
35
Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via...
spook
35
Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on the Thanos builder),...
lamashtu
34
Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Romania, and Thailand...
dan0n
33
obscura
33
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON...
wannacry
33
WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in...
blackmatter
32
Ransomware-as-a-Service
global
32
GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring...
marketo
32
Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or back...
suncrypt
32
SunCrypt is a RaaS operation first observed in October 2019, notable for pioneering triple extortion (encryption, data publication threats, and...
alphalocker
31
AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin panel, ransomware executable,...
blacknevas
31
aka Trial Recovery
BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting...
metaencryptor
31
MetaEncryptor is a ransomware group first observed in mid-2023, targeting medium-to-large enterprises in legal, technology, logistics, manufacturing, and finance sectors...
frag
30
Frag is a ransomware group that emerged in late 2024, exploiting a critical Veeam Backup & Replication vulnerability (CVE-2024-40711) to...
moneymessage
30
aka ThreatLabz
Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms...
payloadbin
29
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed...
onyx
28
Onyx is a ransomware group first observed in April 2022, based on the Chaos ransomware builder, that is notably destructive...
kelvinsecurity
26
KelvinSecurity is a financially motivated hacking group active since at least 2015, primarily engaged in stealing and selling databases from...
m3rx
26
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US,...
netwalker
26
NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The...
underground
26
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023...
werewolves
26
WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an...
doppelpaymer
25
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to...
fulcrumsec
25
FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting...
kraken
25
Kraken is a Russian-speaking ransomware group that emerged in February 2025, believed to have links to the HelloKitty operation, employing...
vect
25
VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a...
lapsus$
24
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia,...
radar
24
Radar (also known as Dispossessor), active since August 2023 and led by an actor called "Brain," was a RaaS group...
daixin
21
Daixin Team is a ransomware and data extortion group active since at least June 2022, exclusively targeting the US Healthcare...
xinglocker
21
XingLocker is a ransomware group that emerged in May 2021 as part of a franchise-style RaaS model built on a...
hellcat
20
HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric,...
leaktheanalyst
20
LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims, notable for...
bravox
19
BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting...
cephalus
19
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via...
cmdorganization
19
morpheus
19
Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group,...
ralord
19
RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and...
siegedsec
19
Not a ransomware group but a hacktivist group that appeared coincidentally days before Russia’s invasion of Ukraine
brotherhood
18
Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing,...
d4rk4rmy
18
D4rk4rmy is a ransomware and data extortion group active since at least 2025, targeting financial services, hospitality, technology, and logistics...
mountlocker
18
MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for...
trinity
18
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption...
alp-001
17
kawa4096
17
aka KaWaLocker
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily...
sabbath
17
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand...
apos
16
Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or...
datacarry
16
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak...
dunghill
16
aka darkangel
Dunghill Leak is the data extortion site operated by the Dark Angels ransomware group, active since early 2023, targeting large...
madliberator
16
MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption...
mosesstaff
16
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be...
redransomware
16
Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across...
tridentlocker
16
TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of regulated or third-party data —...
cheers
15
Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks...
nefilim
15
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of...
auditteam
14
benzona
14
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare,...
freecivilian
14
FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukrainian government websites...
sparta
14
Sparta is a short-lived ransomware group first observed in September 2022 that conducted double-extortion attacks primarily targeting organizations in Spain...
unsafe
14
A group which seems to recycle leak from other ransomware groups
weyhro
14
Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak...
argonauts
13
Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, healthcare, energy, and telecom...
aurora
13
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold...
groove
13
Groove emerged in mid-2021 as a loose criminal collective linked to former Babuk gang members, known for publicly leaking Fortinet...
mindware
13
Ransomware, potential rebranding of win.sfile.
imncrew
12
shadowbyt3$
12
teamxxx
12
TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, agriculture, hospitality,...
cryp70n1c0d3
11
Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology, and operational model remain poorly documented...
icefire
11
IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability...
crazyhunter
10
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese...
darkpower
10
Dark Power emerged in January 2023 as a ransomware group written in the Nim programming language, claiming 10 victims across...
darkrace
10
DarkRace is a ransomware variant that surfaced in mid-2023 sharing strong code similarities with LockBit, employing double-extortion via a dark...
darkside
10
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become...
deadlock
10
blackout
9
Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France,...
kazu
9
Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations...
leakbazaar
9
rook
9
According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them....
titan
9
Founded 4 April 2026
babuk
8
Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled...
cryptbb
8
CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to encrypted files...
mogilevich
8
Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, but was quickly exposed...
qiulong
8
Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double extortion and unique tactics...
radiant
8
Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing...
skira
8
Skira is a small ransomware group that emerged around late 2024, claiming responsibility for the breach of Carruth Compliance Consulting...
vanhelsing
8
0mega
7
0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files...
bert
7
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and...
blackwater
7
Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and targeting healthcare...
chort
7
Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US...
cyclops
7
Cyclops emerged in May 2023 as a cross-platform RaaS operation targeting Windows, macOS, and Linux systems; it rebranded as "Knight"...
karma
7
Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating...
malekteam
7
Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on...
pay2key
7
Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July...
arkana
6
Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband...
cipherforce
6
CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeting...
dataleak
6
Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited public threat intelligence...
netrunner
6
NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across...
rancoz
6
Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered...
redalert
6
RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware...
runsomewares
6
silent
6
Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own...
yanluowang
6
According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the...
0day syndicate
5
atomsilo
5
AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access...
black x
5
bqtlock
5
BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist...
donex
5
DoNex is a ransomware strain that emerged in March 2024 as the latest rebrand of a lineage beginning with Muse...
gdlockersec
5
kryptos
5
Kryptos is a small ransomware group first observed in October 2025, conducting simultaneous attacks across North America and Oceania on...
lockbit
5
LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its...
lockdata
5
LockData Auction is a dark web marketplace that emerged around May 2021 operating an invite-only stolen data auction portal, representing...
minteye
5
MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction, engineering, architecture, and logistics sectors,...
orca
5
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting...
pandora
5
Pandora ransomware was obtained by vx-underground at 2022-03-14.
projectrelic
5
Project Relic emerged in mid-2022 as a Golang-based ransomware targeting Windows and Linux hosts, operating with a TOR-based data leak...
raznatovic
5
RANSOMED.VC aka Raznatovic
valencialeaks
5
blacktor
4
Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in...
desolator
4
Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe...
exitium
4
Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targeting victims...
linkc
4
Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI,...
ms13089
4
aka ms13-089
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin,...
prinzeugen
4
ransomcortex
4
RansomCortex emerged in July 2024 with a narrow focus on healthcare facilities, claiming four victims within days of its first...
satanlockv2
4
SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after...
shaoleaks
4
SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but lacking detailed...
blackshadow
3
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and...
bluebox
3
Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden,...
bonacigroup
3
Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going...
grief
3
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to...
hellogookie
3
HelloGookie is a rebrand of the HelloKitty ransomware group announced in April 2024, releasing previously stolen data from CD Projekt...
mnt6
3
MNT6 is a lower-profile ransomware group claiming victims across legal, manufacturing, construction, healthcare, and logistics sectors in the US, Canada,...
noname
3
NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized businesses globally...
ragnarok
3
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese...
rebornvc
3
aka RansomedVC2
RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion, and double...
timc
3
trisec
3
Trisec is a Tunisian-origin ransomware group that emerged in February 2024, claiming affiliation with the Tunisian government and operating as...
vanirgroup
3
VanirGroup is an Eastern European ransomware group composed of former affiliates from Karakurt, LockBit, and Knight ransomware that emerged in...
vendetta
3
Ransomware, which appears to be a rebranding of win.cuba.
yurei
3
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source...
cryptnet
2
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256...
icarus
2
kittykatkrew
2
KittyKatKrew is a newly emerged ransomware group first identified in early 2026, using both direct and double-extortion methods against US...
lunalock
2
LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and...
nightsky
2
Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, gaining notoriety...
osiris
2
Osiris is a ransomware-as-a-service operation first observed in November 2025 that uses a Bring Your Own Vulnerable Driver (BYOVD) technique...
prolock
2
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses...
sensayq
2
triple x
2
crosslock
1
CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519...
hades
1
According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety...
insane
1
Insane is a short-lived ransomware group that briefly surfaced in early 2024, claiming a single victim in Thailand before going...
la_piovra
1
ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
nasirsecurity
1
Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle...
playboy
1
PlayBoy Locker is a ransomware-as-a-service operation that emerged in September 2024, targeting Windows, NAS, and ESXi systems across multiple sectors...
ranstreet
1
Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lists but without major vendor...
reynolds
1
Reynolds is a ransomware family first identified in early 2026, notable for embedding BYOVD (Bring Your Own Vulnerable Driver) defense...
robinhood
1
RobbinHood is a ransomware group first observed in April–May 2019, responsible for high-profile attacks on US cities including Baltimore, Maryland...
secp0
1
Encrypted Extension: .vanhelsing, .vanlocker. Targets Windows Platform only
sicarii
1
Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targeting Arab and Muslim-majority organizations while avoiding Israeli...
slug
1
Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing company)...
synack
1
SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process...
walocker
1
WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and government entities,...
zerotolerance
1
ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named...

Source: Ransomware.live