Description:
8Base is a ransomware group that encrypts data and demands a ransom for its decryption, with activities believed to have started in April 2022. On their Dedicated Leak Site (DLS), they position themselves as ethical pentesters, claiming to target companies that neglect data privacy. Group-IB specialists found that 8Base uses an obfuscated 2020 version of Phobos ransomware, with the majority of their victims being small and medium-sized businesses in the U.S., Europe, and other regions, focusing primarily on the professional, scientific, technical, and manufacturing sectors.
Get Immediate Ransomware Support
Description:
Abyss is a ransomware group discovered in March 2023. Abyss ransomware encrypts the victim’s data and uploads it to a remote server for further extortion. Abyss operates a Dedicated Leak Site (DLS).
Get Immediate Ransomware Support
Description:
Akira is a ransomware operator group discovered in April 2023. Akira ransomware encrypts the victim’s data, and once encrypted, the data is uploaded to a remote server controlled by the attackers.
Get Immediate Ransomware Support
Description:
BianLian (also known as Masked Spider) is a ransomware gang. Infrastructure associated with the BianLian group first appeared online in December 2021, and their toolset has been under active development since then. BianLian ransomware encrypts the victim’s data using a custom encryptor developed in Go. Once the data is encrypted, it is uploaded to a remote server.
Get Immediate Ransomware Support
Description:
Black Basta is a ransomware group that was discovered in April 2022 and operates privately, not as a Ransomware-as-a-Service (RaaS). It encrypts victims’ data using ChaCha20 and RSA-4096 algorithms, uploading files to a remote server before completing the encryption process. Black Basta targets both Windows and Linux systems, including VMware ESXi virtual machines, using a cross-platform approach built in C++. The group uses a Dedicated Leak Site (DLS) to publish stolen data from their attacks.
Get Immediate Ransomware Support
Description:
BlackByte ransomware was discovered in July 2021. This crypto-ransomware encrypts users’ data using AES and RSA encryption algorithms and then demands a ransom in Bitcoin (BTC) to recover the files. This ransomware primarily targets English-speaking users, and it can spread globally. The cybercrime group behind BlackByte also operates a Dedicated Leak Site (DLS), where stolen data is published if the ransom is not paid.
Get Immediate Ransomware Support
Description:
BlackSuit is a new ransomware variant that targets both Linux and Windows operating systems. It was first observed on May 1, 2023. This ransomware appends a .blacksuit extension to the encrypted files, indicating that the data has been compromised.
Get Immediate Ransomware Support
Description:
Brain Cipher is a ransomware group discovered in June 2024. Brain Cipher ransomware encrypts the victim’s data, targeting Windows systems. The ransomware’s Windows version is a fork of the LockBit ransomware. The group communicates with victims using a negotiation page hosted on their dedicated website.
Get Immediate Ransomware Support
Description:
CACTUS is a ransomware group that has been targeting large commercial entities since March 2023. The name “CACTUS” is derived from the filename in the ransom note, cAcTuS.readme.txt, and the group’s self-declared name within the note. CACTUS operates a Dedicated Leak Site (DLS), which was first detected on July 21, 2023, containing 18 victims at the time. To become an affiliate, the group requires a deposit of 77.77777 XMR, with 20% of the ransom going to the group and the remainder to the affiliates. CACTUS ransomware targets Linux, Windows, and ESXi systems, focusing primarily on companies from developed countries.
Get Immediate Ransomware Support
Description:
Ciphbit is a ransomware group that first appeared on August 31, 2023. The ransomware appends an extension to encrypted files based on a specific pattern: the original filename is followed by a unique victim ID, the threat actors’ email, and a set of random characters. The group primarily targets businesses, although affiliates are also allowed to attack home users. To become an affiliate, a $1,000 deposit is required. The group takes 30% of the revenue from the ransom, but after the first three payments, this drops to 25%.
Get Immediate Ransomware Support
Description:
Clop is a major cybercrime group that uses Clop ransomware to encrypt victims’ sensitive files and demand ransoms in Bitcoin. Discovered in February 2019, Clop initially spread via Flawed Ammyy malware and compromised Active Directory (AD) servers by stealing administrator credentials. Over time, the group evolved its tactics, using the Get2 downloader and SDBbot backdoor for reconnaissance and lateral movement in victims’ networks. As of 2023, Clop remains one of the largest ransomware groups, with over 350 victims, and utilizes a Dedicated Leak Site (DLS) to publish stolen data since August 2021.
Get Immediate Ransomware Support
Description:
D0nut is a ransomware operator group discovered in August 2022. D0nut operates a Dedicated Leak Site (DLS). The ransom note includes a link to an onion domain, which the attackers use to communicate with victims. Additionally, the ransom note contains contact details for TOX, which the group also uses as a communication method with victims.
Get Immediate Ransomware Support
Description:
The Daixin Team is a ransomware group discovered in June 2022. The Daixin Team ransomware encrypts the victim’s data, and once the data is encrypted, it is uploaded to a remote server.
Get Immediate Ransomware Support
Description:
Dark Angels (aka Dunghill Leak) is a ransomware operator group discovered in April 2023. Dark Angels has a DLS. Dark Angels ransomware encrypts the victim’s data. Once data is encrypted, ransomware uploads it to a remote server.
Get Immediate Ransomware Support
Description:
Devman is a former Qilin affiliate who launched independent ransomware operations in 2025, with victims appearing on both DLS platforms simultaneously suggesting a parallel overlap before full separation. One confirmed victim also appeared on Lynx’s DLS, indicating shared or brokered initial access across groups. The actor is notable for aggressive public branding via X (@Inifintyink), where he taunts victims by name, confirms intrusion details, and publicly announces ransom demands — including one post naming a victim, specifying an $800,000 demand, a 10-day deadline, and the exact vulnerability exploited.
Get Immediate Ransomware Support
Description:
Dire Wolf is a ransomware operator discovered in May 2025 that has rapidly become one of the most prolific threats in the current landscape. The group operates a double extortion model, encrypting victims’ files with the .direwolf extension while exfiltrating sensitive data before encryption. Their DLS and negotiation portal are both hosted on the Tor network. With 171 confirmed attacks across 28+ countries in under a year, Dire Wolf has demonstrated an unusually high attack tempo, including coordinated mass campaigns targeting multiple organizations simultaneously.
Get Immediate Ransomware Support
Description:
Dispossessor is a ransomware group that emerged in April 2024. The group operates its own Dedicated Leak Site (DLS). A notable feature of Dispossessor’s victims is their overlap with LockBit’s target list. The group prohibits attacks on Post-Soviet countries and critical infrastructure. Affiliates working with Dispossessor receive 80% of the ransom, while 20% goes to the group itself. To join as an affiliate, candidates are required to pay a deposit of 1 BTC.
Get Immediate Ransomware Support
Description:
DragonForce is a ransomware group discovered in September 2023. It employs a variant of the LockBit ransomware to encrypt victims’ data. The group also operates a Dedicated Leak Site (DLS) where stolen data is published if ransom demands are not met.
Get Immediate Ransomware Support
Description:
Eldorado is a ransomware group discovered in March 2024. Eldorado ransomware encrypts the victim’s data and uploads it to a remote server once encrypted.
Get Immediate Ransomware Support
Description:
Embargo is a ransomware operator group that was discovered in April 2024. The group uses its Embargo ransomware to encrypt victims’ data and demands a ransom for decryption. Embargo operates a Dedicated Leak Site (DLS) where it publishes stolen data if the ransom is not paid.
Get Immediate Ransomware Support
Description:
The Everest (also known as the Everest ransom team) is a cybercrime group that uses the Everest Ransomware for its attacks. This ransomware was first detected in the wild at the end of December 2020. The Everest ransom team operates a blog for publishing stolen data. This ransomware primarily targeted companies in North America, especially in Canada. A possible name for the ransom note is: “EVEREST LOCKER.txt.”
Get Immediate Ransomware Support
Description:
Hunters International is a ransomware group that was first detected on October 20, 2023. The group is likely connected to the Hive ransomware through purchased code. Despite this connection, on October 24, 2023, Hunters International publicly stated that they are not affiliated with Hive. This clarification came after law enforcement seized Hive’s servers in January 2023, dismantling their operations.
Get Immediate Ransomware Support
Description:
INC Ransom is a mature RaaS operation active since mid-2023 with one of the broadest targeting profiles in the current ransomware landscape — 192+ industry sectors across 66 countries. The group exploits Citrix NetScaler ADC and Gateway vulnerabilities as a primary initial access vector, supplemented by spear-phishing for credential harvesting. For data exfiltration, affiliates abuse the legitimate backup tool Restic, often renamed to “winupdate.exe” to evade detection, staging stolen data to cloud storage before encryption. High-profile victims include Scotland’s NHS, McLaren Health Care, Yamaha Motor, Xerox Business Solutions, and the Texas State Bar.
Get Immediate Ransomware Support
Description:
INC Ransomware is a ransomware group that first appeared in late August 2023. The ransomware appends the “.INC” extension to encrypted files. The group also operates a Dedicated Leak Site (DLS) to publish data stolen from victims who do not comply with their ransom demands.
Get Immediate Ransomware Support
Description:
LockBit is a prominent cybercrime group known for using LockBit ransomware, first detected in December 2019. By January 2020, its attacks primarily targeted organizations in the USA, Germany, France, and China. LockBit ransomware utilizes both RSA and AES encryption algorithms and is capable of deleting backups, bypassing User Account Control (UAC), and spreading via SMB using stolen credentials. Since October 2021, LockBit has expanded its attacks to Linux systems, specifically targeting VMware ESXi virtual machines, and operates a Dedicated Leak Site (DLS) to publish stolen data.
Get Immediate Ransomware Support
Description:
Lynx is a RaaS operation that emerged in July 2024 using a fork of INC Ransom source code — the two share 48% code similarity, suggesting a common developer lineage or deliberate rebrand. The group runs a structured affiliate program offering an 80/20 revenue split favoring affiliates, recruited openly on RAMP by the user “silencer.” Infrastructure is unusually redundant for a group of its age, with 29 Tor domains spanning admin panels, blog mirrors, guest panels, and internal chat systems. The ransomware targets Windows, ESXi, and NAS systems, with configurable encryption modes ranging from 5% to 100% of file content, allowing affiliates to balance speed and impact. Dedicated call centers are available to affiliates for victim harassment during negotiations. The group explicitly excludes CIS countries, Ukraine, China, Iran, and North Korea from targeting, and maintains a self-imposed restriction against attacking healthcare, government, churches, non-profits, and child welfare organizations — though March 2026 incidents indicate healthcare targeting has occurred in practice.
Get Immediate Ransomware Support
Description:
Mallox is a long-standing ransomware group. It was first observed in June 2021 under the name “TargetCompany ransomware” but was later renamed “Fargo” in mid to late 2022 due to the extension it adds to encrypted files. From December 2022 onwards, it became known as Mallox. Mallox perates a Dedicated Leak Site (DLS).
Get Immediate Ransomware Support
Description:
MedusaLocker is a ransomware group that was first discovered in October 2019. MedusaLocker operates a Dedicated Leak Site (DLS), where they publish stolen data if ransoms are not paid. The ransomware variant is notable for its use of various file extensions, which differ across samples of the malware, depending on the version or configuration of the attack.
Get Immediate Ransomware Support
Description:
Monti is a ransomware operator group discovered in November 2022. Monti ransomware encrypts users’ sensitive files and then demands a ransom in Bitcoin (BTC) for their return. Monti ransomware operates a Dedicated Leak Site (DLS). In September 2023, the group had started using the name BIDON.
Get Immediate Ransomware Support
Description:
MyData is a ransomware group discovered in January 2024. MyData ransomware encrypts victims’ data, using encryption techniques to block access and demand a ransom for recovery.
Get Immediate Ransomware Support
Description:
Play is a ransomware operator group discovered in July 2022. Play ransomware encrypts a victim’s sensitive files and then demands a ransom in Bitcoin (BTC) to return the files. Play launched its Dedicated Leak Site (DLS) in November 2022 to publish stolen data from victims who refuse to pay the ransom.
Get Immediate Ransomware Support
Description:
Qilin is a ransomware operator group discovered in July 2022. In February 2023, they launched a Ransomware-as-a-Service (RaaS) platform on an underground forum. An earlier version of Qilin ransomware was known as Agenda ransomware, which was originally developed in Go. The newer version, Qilin ransomware, is developed in Rust. Despite the name change, Agenda ransomware is still used as an alternate name for Qilin. Qilin ransomware operates a Dedicated Leak Site (DLS) for publishing data stolen from victims who refuse to pay the ransom.
Get Immediate Ransomware Support
Description:
RA Group, discovered in April 2023, is a ransomware group that uses a variant of Babuk ransomware to encrypt data and uploads it to a remote server. They customize ransom notes for each target and append the “.GAGUP” extension to encrypted files. The group operates a Dedicated Leak Site (DLS) and utilizes qTox for communication with victims.
Get Immediate Ransomware Support
Description:
RansomExx is a ransomware family that began targeting multiple companies in mid-2020. It shares similarities with Defray777. The RansomExx group is also known by the aliases GoldDupont and Sprite Spider.
Get Immediate Ransomware Support
Description:
RansomHub is a ransomware operator group first discovered in January 2024. The RansomHub ransomware encrypts victims’ data using a locker written in Golang and C++. Its asymmetric algorithm is based on x25519, while the encryption algorithm varies, using AES-256, ChaCha20, or XChaCha20, depending on hardware support. The ransomware adds random characters to the file extensions of encrypted files and operates a Dedicated Leak Site (DLS) for publishing stolen data if ransoms are not paid.
Get Immediate Ransomware Support
Description:
Rhysida is a ransomware group first discovered in May 2023. Rhysida ransomware encrypts victims’ data and adds the .rhysida extension to the affected files. After encryption, the ransomware uploads the compromised data to a remote server.
Get Immediate Ransomware Support
Description:
Risen is a ransomware group discovered in May 2024. The ransomware encrypts victims’ data, leveraging encryption techniques to lock access. The group also operates a Dedicated Leak Site (DLS).
Get Immediate Ransomware Support
First seen:
September 2024
Description:
SafePay is a private ransomware operation — not a RaaS — where core developers directly orchestrate attacks rather than recruiting affiliates. This distinguishes it from the majority of active ransomware groups and contributes to its operational consistency and tight infrastructure control. Emerging in September 2024, SafePay scaled from 20+ victims in its first months to 260+ confirmed victims globally by early 2025, making it one of the fastest-growing ransomware operations in the current landscape. The group’s most significant confirmed attack was against Ingram Micro in July 2025, where 3.5TB of data was exfiltrated, causing widespread system outages affecting over 42,000 individuals.
Get Immediate Ransomware Support
Description:
Sarcoma is a ransomware operation discovered in October 2024 that claimed 36 victims in its first month and reached 221 documented incidents within 18 months — one of the fastest growth trajectories in the current ransomware landscape. The group operates a double extortion model, encrypting files with a randomized extension while exfiltrating data before encryption, across both Windows and Linux environments. Their DLS and negotiation portal are hosted on the Tor network. Notable confirmed targets include Unimicron in Taiwan and a Swiss federal government supply chain breach. Sarcoma’s ransom note includes an unusual crowdsourcing section actively soliciting insider tips from disgruntled employees, which is a tactic rare among active operators.
Get Immediate Ransomware Support
First seen:
November 2022.
Description:
ScareCrow ransomware operator group was discovered in November 2022. ScareCrow ransomware encrypts users’ sensitive files and demands a ransom in exchange for their return. Unlike many modern ransomware groups, ScareCrow does not operate a Dedicated Leak Site (DLS) for publishing stolen data.
Get Immediate Ransomware Support
Description:
SenSayQ is a ransomware group that emerged in June 2024. The group operates a Dedicated Leak Site (DLS), where they position themselves as ethical ‘pentesters,’ claiming to care about the security of their targets. On their “About” page, they portray their actions as beneficial for security improvements. They strictly prohibit the involvement of law enforcement agencies such as the FBI, CIA, and NSA in negotiations, warning victims not to engage with these authorities.
Get Immediate Ransomware Support
Description:
Sinobi emerged in July 2025 and scaled to 278 documented attacks within eight months, briefly ranking among the top three most active ransomware groups globally — an unusually rapid rise that attracted significant attention in threat intelligence communities. Infrastructure analysis suggests possible links to Lynx through shared web server frameworks and design patterns, with Prodaft reporting Sinobi may operate as a Hopeful Mantis affiliate. The group runs a resilient multi-mirror DLS infrastructure across 15 documented domains and offers victims a 7-day negotiation window with test decryption and stolen file lists as standard negotiation tools. Rclone is confirmed in use for data exfiltration. The group explicitly states financial motivation with no political agenda.
Get Immediate Ransomware Support
Description:
Trinity is a ransomware group discovered in April 2024. Trinity ransomware encrypts victims’ data and everages the encrypted files as part of their extortion process. Trinity operates a Dedicated Leak Site (DLS), where they publish stolen data if ransom payments are not met.
Get Immediate Ransomware Support
Description:
Underground is a ransomware group first discovered in July 2023. The ransomware encrypts the victim’s data and uploads it to a remote server for ransom leverage. Underground does not operate a Dedicated Leak Site (DLS).
Get Immediate Ransomware Support
Description:
White Rabbit ransomware was first detected on December 14, 2021. The ransomware adds the .scrypt extension to encrypted files and drops a ransom note named <filename>.scrypt.txt.
Get Immediate Ransomware Support