Examples from the most active ransomware groups

Ransom
notes

Ransom notes are the final stage of 2020’s plague — a ransomware attack.
They reveal how threat actors apply pressure, structure
negotiations, and weaponize stolen data.

Group-IB’s Threat Intelligence team monitors hundreds of ransomware groups worldwide daily, tracking their Dedicated Leak Sites, affiliate programs, malware variants, and negotiation tactics.

Find out which ransomware gangs are targeting you

Find real examples of ransom notes collected from the most active groups shaping the global threat landscape in 2026 to stay protected.

All available ransom notes ()

Threat actor:
8Base
Targeted Region:
🇫🇷 France
🇩🇪 Germany
🇮🇹 Italy
🇯🇵 Japan
🇸🇪 Sweden
🇺🇸 United States
Targeted industry:
Manufacturing
Real estate
First seen:
03 Apr 2022
Description:

8Base is a ransomware group that encrypts data and demands a ransom for its decryption, with activities believed to have started in April 2022. On their Dedicated Leak Site (DLS), they position themselves as ethical pentesters, claiming to target companies that neglect data privacy. Group-IB specialists found that 8Base uses an obfuscated 2020 version of Phobos ransomware, with the majority of their victims being small and medium-sized businesses in the U.S., Europe, and other regions, focusing primarily on the professional, scientific, technical, and manufacturing sectors.

Threat actor:
Abyss
Targeted Region:
🇨🇭 Switzerland
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Manufacturing
Real estate
Science and engineering
First seen:
06 Mar 2023
Description:

Abyss is a ransomware group discovered in March 2023. Abyss ransomware encrypts the victim’s data and uploads it to a remote server for further extortion. Abyss operates a Dedicated Leak Site (DLS).

Threat actor:
Akira
Targeted Region:
🇧🇷 Brazil
🇨🇦 Canada
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Education
Manufacturing
Real estate
Transportation
First seen:
06 Apr 2023
Description:

Akira is a ransomware operator group discovered in April 2023. Akira ransomware encrypts the victim’s data, and once encrypted, the data is uploaded to a remote server controlled by the attackers.

Threat actor:
BianLian
Targeted Region:
🇨🇦 Canada
🇮🇳 India
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Construction
Financial services
Health care
Manufacturing
Real estate
First seen:
01 Feb 2022
Description:

BianLian (also known as Masked Spider) is a ransomware gang. Infrastructure associated with the BianLian group first appeared online in December 2021, and their toolset has been under active development since then. BianLian ransomware encrypts the victim’s data using a custom encryptor developed in Go. Once the data is encrypted, it is uploaded to a remote server.

Threat actor:
Black Basta
Targeted Region:
🇨🇦 Canada
🇩🇪 Germany
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Manufacturing
First seen:
14 Feb 2022
Description:

Black Basta is a ransomware group that was discovered in April 2022 and operates privately, not as a Ransomware-as-a-Service (RaaS). It encrypts victims’ data using ChaCha20 and RSA-4096 algorithms, uploading files to a remote server before completing the encryption process. Black Basta targets both Windows and Linux systems, including VMware ESXi virtual machines, using a cross-platform approach built in C++. The group uses a Dedicated Leak Site (DLS) to publish stolen data from their attacks.

Threat actor:
Black Byte
Targeted Region:
🇳🇱 Netherlands
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Manufacturing
Non profit
Real estate
Transportation
First seen:
11 Aug 2021
Description:

BlackByte ransomware was discovered in July 2021. This crypto-ransomware encrypts users’ data using AES and RSA encryption algorithms and then demands a ransom in Bitcoin (BTC) to recover the files. This ransomware primarily targets English-speaking users, and it can spread globally. The cybercrime group behind BlackByte also operates a Dedicated Leak Site (DLS), where stolen data is published if the ransom is not paid.

Threat actor:
BlackSuit
Targeted Region:
🇧🇪 Belgium
🇧🇷 Brazil
🇨🇦 Canada
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Education
Manufacturing
Real estate
First seen:
01 May 2023
Description:

BlackSuit is a new ransomware variant that targets both Linux and Windows operating systems. It was first observed on May 1, 2023. This ransomware appends a .blacksuit extension to the encrypted files, indicating that the data has been compromised.

Threat actor:
Brain Cipher
Targeted Region:
🇮🇩 Indonesia
🇲🇽 Mexico
🇺🇸 United States
Targeted industry:
Government and military
First seen:
16 Jun 2024
Description:

Brain Cipher is a ransomware group discovered in June 2024. Brain Cipher ransomware encrypts the victim’s data, targeting Windows systems. The ransomware’s Windows version is a fork of the LockBit ransomware. The group communicates with victims using a negotiation page hosted on their dedicated website.

Threat actor:
Cactus
Targeted Region:
🇦🇺 Australia
🇨🇦 Canada
🇫🇷 France
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Information technology
Manufacturing
Real estate
First seen:
27 Feb 2023
Description:

CACTUS is a ransomware group that has been targeting large commercial entities since March 2023. The name “CACTUS” is derived from the filename in the ransom note, cAcTuS.readme.txt, and the group’s self-declared name within the note. CACTUS operates a Dedicated Leak Site (DLS), which was first detected on July 21, 2023, containing 18 victims at the time. To become an affiliate, the group requires a deposit of 77.77777 XMR, with 20% of the ransom going to the group and the remainder to the affiliates. CACTUS ransomware targets Linux, Windows, and ESXi systems, focusing primarily on companies from developed countries.

Threat actor:
Ciphbit
Targeted Region:
🇧🇪 Belgium
🇫🇷 France
🇮🇹 Italy
🇳🇱 Netherlands
🇺🇸 United States
Targeted industry:
Clothing and apparel
Design
First seen:
26 Apr 2023
Description:

Ciphbit is a ransomware group that first appeared on August 31, 2023. The ransomware appends an extension to encrypted files based on a specific pattern: the original filename is followed by a unique victim ID, the threat actors’ email, and a set of random characters. The group primarily targets businesses, although affiliates are also allowed to attack home users. To become an affiliate, a $1,000 deposit is required. The group takes 30% of the revenue from the ransom, but after the first three payments, this drops to 25%.

Threat actor:
Cl0p
Targeted Region:
🇨🇦 Canada
🇩🇪 Germany
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Financial services
Information technology
Manufacturing
First seen:
01 Feb 2019
Description:

Clop is a major cybercrime group that uses Clop ransomware to encrypt victims’ sensitive files and demand ransoms in Bitcoin. Discovered in February 2019, Clop initially spread via Flawed Ammyy malware and compromised Active Directory (AD) servers by stealing administrator credentials. Over time, the group evolved its tactics, using the Get2 downloader and SDBbot backdoor for reconnaissance and lateral movement in victims’ networks. As of 2023, Clop remains one of the largest ransomware groups, with over 350 victims, and utilizes a Dedicated Leak Site (DLS) to publish stolen data since August 2021.

Threat actor:
d0nut
Targeted Region:
🇧🇧 Barbados
🇨🇦 Canada
🇩🇪 Germany
🇪🇸 Spain
🇺🇸 United States
Targeted industry:
Clothing and apparel
Real estate
Software
First seen:
24 May 2022
Description:

D0nut is a ransomware operator group discovered in August 2022. D0nut operates a Dedicated Leak Site (DLS). The ransom note includes a link to an onion domain, which the attackers use to communicate with victims. Additionally, the ransom note contains contact details for TOX, which the group also uses as a communication method with victims.

Threat actor:
Daixin Team
Targeted Region:
🇨🇦 Canada
🇩🇪 Germany
🇦🇪 United Arab Emirates
🇺🇸 United States
Targeted industry:
Energy
Health care
Hospital
Manufacturing
First seen:
04 Jun 2022
Description:

The Daixin Team is a ransomware group discovered in June 2022. The Daixin Team ransomware encrypts the victim’s data, and once the data is encrypted, it is uploaded to a remote server.

Threat actor:
Dark Angels
Targeted Region:
🇳🇱 Netherlands
🇺🇸 United States
Targeted industry:
Consumer electronics
Hardware
Manufacturing
Public transportation
First seen:
05 Apr 2023
Description:

Dark Angels (aka Dunghill Leak) is a ransomware operator group discovered in April 2023. Dark Angels has a DLS. Dark Angels ransomware encrypts the victim’s data. Once data is encrypted, ransomware uploads it to a remote server.

Threat actor:
Devman
Targeted Region:
🇫🇷 France
🇹🇼 Taiwan
Targeted industry:
Health care
Legal
Manufacturing
First seen:
April 2025
Description:

Devman is a former Qilin affiliate who launched independent ransomware operations in 2025, with victims appearing on both DLS platforms simultaneously suggesting a parallel overlap before full separation. One confirmed victim also appeared on Lynx’s DLS, indicating shared or brokered initial access across groups. The actor is notable for aggressive public branding via X (@Inifintyink), where he taunts victims by name, confirms intrusion details, and publicly announces ransom demands — including one post naming a victim, specifying an $800,000 demand, a 10-day deadline, and the exact vulnerability exploited.

Threat actor:
Dire Wolf
Targeted Region:
🇦🇺 Australia
🇧🇷 Brazil
🇲🇾 Malaysia
Thailand
Turkey
🇺🇸 United States
Targeted industry:
Financial services
Health care
Manufacturing
Real estate
Transportation
First seen:
May 2025
Description:

Dire Wolf is a ransomware operator discovered in May 2025 that has rapidly become one of the most prolific threats in the current landscape. The group operates a double extortion model, encrypting victims’ files with the .direwolf extension while exfiltrating sensitive data before encryption. Their DLS and negotiation portal are both hosted on the Tor network. With 171 confirmed attacks across 28+ countries in under a year, Dire Wolf has demonstrated an unusually high attack tempo, including coordinated mass campaigns targeting multiple organizations simultaneously.

Threat actor:
DISPOSSESSOR
Targeted Region:
🇨🇦 Canada
🇴🇲 Oman
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Financial services
Information technology
Real estate
First seen:
03 May 2021
Description:

Dispossessor is a ransomware group that emerged in April 2024. The group operates its own Dedicated Leak Site (DLS). A notable feature of Dispossessor’s victims is their overlap with LockBit’s target list. The group prohibits attacks on Post-Soviet countries and critical infrastructure. Affiliates working with Dispossessor receive 80% of the ransom, while 20% goes to the group itself. To join as an affiliate, candidates are required to pay a deposit of 1 BTC.

Threat actor:
DragonForce
Targeted Region:
🇦🇺 Australia
🇮🇹 Italy
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Manufacturing
First seen:
13 Aug 2023
Description:

DragonForce is a ransomware group discovered in September 2023. It employs a variant of the LockBit ransomware to encrypt victims’ data. The group also operates a Dedicated Leak Site (DLS) where stolen data is published if ransom demands are not met.

Threat actor:
Eldorado
Targeted Region:
🇭🇷 Croatia
🇮🇹 Italy
🇰🇷 South Korea
🇺🇸 United States
Targeted industry:
Education
Government and military
Real estate
Transportation
First seen:
03 Dec 2023
Description:

Eldorado is a ransomware group discovered in March 2024. Eldorado ransomware encrypts the victim’s data and uploads it to a remote server once encrypted.

Threat actor:
Embargo
Targeted Region:
🇦🇺 Australia
🇫🇷 France
🇩🇪 Germany
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Commerce and shopping
Real estate
First seen:
17 Apr 2024
Description:

Embargo is a ransomware operator group that was discovered in April 2024. The group uses its Embargo ransomware to encrypt victims’ data and demands a ransom for decryption. Embargo operates a Dedicated Leak Site (DLS) where it publishes stolen data if the ransom is not paid.

Threat actor:
Everest
Targeted Region:
🇧🇷 Brazil
🇨🇦 Canada
🇫🇷 France
🇮🇹 Italy
🇵🇭 Philippines
🇺🇸 United States
Targeted industry:
Construction
Health care
Manufacturing
Real estate
First seen:
14 Jan 2020
Description:

The Everest (also known as the Everest ransom team) is a cybercrime group that uses the Everest Ransomware for its attacks. This ransomware was first detected in the wild at the end of December 2020. The Everest ransom team operates a blog for publishing stolen data. This ransomware primarily targeted companies in North America, especially in Canada. A possible name for the ransom note is: “EVEREST LOCKER.txt.”

Threat actor:
Hunters International
Targeted Region:
🇲🇽 Mexico
🇪🇸 Spain
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Health care
Manufacturing
First seen:
20 Oct 2023
Description:

Hunters International is a ransomware group that was first detected on October 20, 2023. The group is likely connected to the Hive ransomware through purchased code. Despite this connection, on October 24, 2023, Hunters International publicly stated that they are not affiliated with Hive. This clarification came after law enforcement seized Hive’s servers in January 2023, dismantling their operations.

Threat actor:
Inc
Targeted Region:
🇦🇺 Australia
🇨🇦 Canada
🇫🇷 France
🇩🇪 Germany
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Construction
Education
Financial services
Government
Health care
Manufacturing
Real estate
First seen:
June 2023
Description:

INC Ransom is a mature RaaS operation active since mid-2023 with one of the broadest targeting profiles in the current ransomware landscape — 192+ industry sectors across 66 countries. The group exploits Citrix NetScaler ADC and Gateway vulnerabilities as a primary initial access vector, supplemented by spear-phishing for credential harvesting. For data exfiltration, affiliates abuse the legitimate backup tool Restic, often renamed to “winupdate.exe” to evade detection, staging stolen data to cloud storage before encryption. High-profile victims include Scotland’s NHS, McLaren Health Care, Yamaha Motor, Xerox Business Solutions, and the Texas State Bar.

Threat actor:
INC Ransomware
Targeted Region:
🇦🇺 Australia
🇫🇷 France
🇳🇱 Netherlands
🇵🇭 Philippines
🇺🇸 United States
Targeted industry:
Education
Non profit
Real estate
First seen:
12 Jun 2023
Description:

INC Ransomware is a ransomware group that first appeared in late August 2023. The ransomware appends the “.INC” extension to encrypted files. The group also operates a Dedicated Leak Site (DLS) to publish data stolen from victims who do not comply with their ransom demands.

Threat actor:
LockBit
Targeted Region:
🇫🇷 France
🇩🇪 Germany
🇮🇹 Italy
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Manufacturing
First seen:
18 Jan 2020
Description:

LockBit is a prominent cybercrime group known for using LockBit ransomware, first detected in December 2019. By January 2020, its attacks primarily targeted organizations in the USA, Germany, France, and China. LockBit ransomware utilizes both RSA and AES encryption algorithms and is capable of deleting backups, bypassing User Account Control (UAC), and spreading via SMB using stolen credentials. Since October 2021, LockBit has expanded its attacks to Linux systems, specifically targeting VMware ESXi virtual machines, and operates a Dedicated Leak Site (DLS) to publish stolen data.

Threat actor:
Lynx
Targeted Region:
🇩🇪 Germany
🇮🇳 India
🇺🇸 United States
Targeted industry:
Financial services
Health care
Legal
Manufacturing
First seen:
July 2024
Description:

Lynx is a RaaS operation that emerged in July 2024 using a fork of INC Ransom source code — the two share 48% code similarity, suggesting a common developer lineage or deliberate rebrand. The group runs a structured affiliate program offering an 80/20 revenue split favoring affiliates, recruited openly on RAMP by the user “silencer.” Infrastructure is unusually redundant for a group of its age, with 29 Tor domains spanning admin panels, blog mirrors, guest panels, and internal chat systems. The ransomware targets Windows, ESXi, and NAS systems, with configurable encryption modes ranging from 5% to 100% of file content, allowing affiliates to balance speed and impact. Dedicated call centers are available to affiliates for victim harassment during negotiations. The group explicitly excludes CIS countries, Ukraine, China, Iran, and North Korea from targeting, and maintains a self-imposed restriction against attacking healthcare, government, churches, non-profits, and child welfare organizations — though March 2026 incidents indicate healthcare targeting has occurred in practice.

Threat actor:
mallox
Targeted Region:
🇧🇷 Brazil
🇫🇷 France
🇮🇳 India
🇵🇹 Portugal
🇺🇸 United States
Targeted industry:
Manufacturing
Software
First seen:
12 Jun 2021
Description:

Mallox is a long-standing ransomware group. It was first observed in June 2021 under the name “TargetCompany ransomware” but was later renamed “Fargo” in mid to late 2022 due to the extension it adds to encrypted files. From December 2022 onwards, it became known as Mallox. Mallox perates a Dedicated Leak Site (DLS).

Threat actor:
Medusa
Targeted Region:
🇦🇺 Australia
🇧🇷 Brazil
🇨🇦 Canada
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Commerce and shopping
Education
Health care
Manufacturing
First seen:
01 May 2022
Description:

MedusaLocker is a ransomware group that was first discovered in October 2019. MedusaLocker operates a Dedicated Leak Site (DLS), where they publish stolen data if ransoms are not paid. The ransomware variant is notable for its use of various file extensions, which differ across samples of the malware, depending on the version or configuration of the attack.

Threat actor:
Monti
Targeted Region:
🇦🇹 Austria
🇫🇷 France
🇩🇪 Germany
🇮🇹 Italy
🇺🇸 United States
Targeted industry:
Education
Health care
First seen:
05 Dec 2022
Description:

Monti is a ransomware operator group discovered in November 2022. Monti ransomware encrypts users’ sensitive files and then demands a ransom in Bitcoin (BTC) for their return. Monti ransomware operates a Dedicated Leak Site (DLS). In September 2023, the group had started using the name BIDON.

Threat actor:
MyData
Targeted Region:
🇦🇺 Australia
🇫🇷 France
🇩🇪 Germany
🇮🇱 Israel
🇮🇹 Italy
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Business development
Education
Food and beverage
Health care
First seen:
31 Jan 2024
Description:

MyData is a ransomware group discovered in January 2024. MyData ransomware encrypts victims’ data, using encryption techniques to block access and demand a ransom for recovery.

Threat actor:
Play
Targeted Region:
🇨🇦 Canada
🇩🇪 Germany
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Information technology
Manufacturing
Real estate
First seen:
01 Aug 2022
Description:

Play is a ransomware operator group discovered in July 2022. Play ransomware encrypts a victim’s sensitive files and then demands a ransom in Bitcoin (BTC) to return the files. Play launched its Dedicated Leak Site (DLS) in November 2022 to publish stolen data from victims who refuse to pay the ransom.

Threat actor:
Qilin
Targeted Region:
🇧🇪 Belgium
🇨🇦 Canada
🇫🇷 France
🇩🇪 Germany
🇮🇹 Italy
🇺🇸 United States
Targeted industry:
Construction
Legal
Manufacturing
First seen:
06 Nov 2022
Description:

Qilin is a ransomware operator group discovered in July 2022. In February 2023, they launched a Ransomware-as-a-Service (RaaS) platform on an underground forum. An earlier version of Qilin ransomware was known as Agenda ransomware, which was originally developed in Go. The newer version, Qilin ransomware, is developed in Rust. Despite the name change, Agenda ransomware is still used as an alternate name for Qilin. Qilin ransomware operates a Dedicated Leak Site (DLS) for publishing data stolen from victims who refuse to pay the ransom.

Threat actor:
RA Group
Targeted Region:
🇩🇪 Germany
🇹🇼 Taiwan
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Financial services
Manufacturing
Transportation
First seen:
21 Apr 2023
Description:

RA Group, discovered in April 2023, is a ransomware group that uses a variant of Babuk ransomware to encrypt data and uploads it to a remote server. They customize ransom notes for each target and append the “.GAGUP” extension to encrypted files. The group operates a Dedicated Leak Site (DLS) and utilizes qTox for communication with victims.

Threat actor:
RansomEXX
Targeted Region:
🇧🇷 Brazil
🇩🇪 Germany
🇮🇹 Italy
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Government
Government and military
Manufacturing
First seen:
22 Jun 2020
Description:

RansomExx is a ransomware family that began targeting multiple companies in mid-2020. It shares similarities with Defray777. The RansomExx group is also known by the aliases GoldDupont and Sprite Spider.

Threat actor:
RansomHub
Targeted Region:
🇦🇺 Australia
🇧🇷 Brazil
🇮🇹 Italy
🇪🇸 Spain
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Information technology
Manufacturing
Real estate
First seen:
02 Feb 2024
Description:

RansomHub is a ransomware operator group first discovered in January 2024. The RansomHub ransomware encrypts victims’ data using a locker written in Golang and C++. Its asymmetric algorithm is based on x25519, while the encryption algorithm varies, using AES-256, ChaCha20, or XChaCha20, depending on hardware support. The ransomware adds random characters to the file extensions of encrypted files and operates a Dedicated Leak Site (DLS) for publishing stolen data if ransoms are not paid.

Threat actor:
Rhysida
Targeted Region:
🇩🇪 Germany
🇮🇹 Italy
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Education
Government
Health care
Software
First seen:
1 Dec 2022
Description:

Rhysida is a ransomware group first discovered in May 2023. Rhysida ransomware encrypts victims’ data and adds the .rhysida extension to the affected files. After encryption, the ransomware uploads the compromised data to a remote server.

Threat actor:
Risen
Targeted Region:
🇺🇸 United States
Targeted industry:
Environmental engineering
First seen:
09 Apr 2024
Description:

Risen is a ransomware group discovered in May 2024. The ransomware encrypts victims’ data, leveraging encryption techniques to lock access. The group also operates a Dedicated Leak Site (DLS).

Threat actor:
SafePay
Targeted Region:
🇺🇸 United States
Targeted industry:
Construction
Education
Financial services
Health care
Legal
Manufacturing
Transportation
First seen:
September 2024
Description:

SafePay is a private ransomware operation — not a RaaS — where core developers directly orchestrate attacks rather than recruiting affiliates. This distinguishes it from the majority of active ransomware groups and contributes to its operational consistency and tight infrastructure control. Emerging in September 2024, SafePay scaled from 20+ victims in its first months to 260+ confirmed victims globally by early 2025, making it one of the fastest-growing ransomware operations in the current landscape. The group’s most significant confirmed attack was against Ingram Micro in July 2025, where 3.5TB of data was exfiltrated, causing widespread system outages affecting over 42,000 individuals.

Threat actor:
Sarcoma Ransomware
Targeted Region:
🇦🇺 Australia
🇦🇹 Austria
🇧🇷 Brazil
🇨🇦 Canada
🇩🇪 Germany
🇮🇹 Italy
🇹🇼 Taiwan
🇺🇸 United States
Targeted industry:
Energy
Financial services
Government
Health care
Manufacturing
Real estate
First seen:
October 2024
Description:

Sarcoma is a ransomware operation discovered in October 2024 that claimed 36 victims in its first month and reached 221 documented incidents within 18 months — one of the fastest growth trajectories in the current ransomware landscape. The group operates a double extortion model, encrypting files with a randomized extension while exfiltrating data before encryption, across both Windows and Linux environments. Their DLS and negotiation portal are hosted on the Tor network. Notable confirmed targets include Unimicron in Taiwan and a Swiss federal government supply chain breach. Sarcoma’s ransom note includes an unusual crowdsourcing section actively soliciting insider tips from disgruntled employees, which is a tactic rare among active operators.

Threat actor:
ScareCrow
Targeted Region:
🇩🇪 Germany
🇮🇳 India
🇮🇹 Italy
🇵🇭 Philippines
🇷🇺 Russia
🇺🇸 United States
Targeted industry:
First seen:
November 2022.
Description:

ScareCrow ransomware operator group was discovered in November 2022. ScareCrow ransomware encrypts users’ sensitive files and demands a ransom in exchange for their return. Unlike many modern ransomware groups, ScareCrow does not operate a Dedicated Leak Site (DLS) for publishing stolen data.

Threat actor:
SenSayQ
Targeted Region:
🇫🇷 France
🇮🇹 Italy
Targeted industry:
Insurance
Packaging services
First seen:
05 Jun 2024
Description:

SenSayQ is a ransomware group that emerged in June 2024. The group operates a Dedicated Leak Site (DLS), where they position themselves as ethical ‘pentesters,’ claiming to care about the security of their targets. On their “About” page, they portray their actions as beneficial for security improvements. They strictly prohibit the involvement of law enforcement agencies such as the FBI, CIA, and NSA in negotiations, warning victims not to engage with these authorities.

Threat actor:
Sinobi
Targeted Region:
🇦🇺 Australia
🇦🇹 Austria
🇧🇷 Brazil
🇨🇦 Canada
Denmark
🇫🇷 France
🇮🇹 Italy
🇬🇧 United Kingdom
🇺🇸 United States
Targeted industry:
Construction
Education
Financial services
Health care
Legal
Manufacturing
First seen:
July 2025
Description:

Sinobi emerged in July 2025 and scaled to 278 documented attacks within eight months, briefly ranking among the top three most active ransomware groups globally — an unusually rapid rise that attracted significant attention in threat intelligence communities. Infrastructure analysis suggests possible links to Lynx through shared web server frameworks and design patterns, with Prodaft reporting Sinobi may operate as a Hopeful Mantis affiliate. The group runs a resilient multi-mirror DLS infrastructure across 15 documented domains and offers victims a 7-day negotiation window with test decryption and stolen file lists as standard negotiation tools. Rclone is confirmed in use for data exfiltration. The group explicitly states financial motivation with no political agenda.

Threat actor:
Trinity
Targeted Region:
🇨🇦 Canada
🇯🇪 Jersey
🇵🇭 Philippines
Targeted industry:
Education
Information technology
Non profit
First seen:
23 Apr 2024
Description:

Trinity is a ransomware group discovered in April 2024. Trinity ransomware encrypts victims’ data and everages the encrypted files as part of their extortion process. Trinity operates a Dedicated Leak Site (DLS), where they publish stolen data if ransom payments are not met.

Threat actor:
Underground Team
Targeted Region:
🇫🇷 France
🇲🇾 Malaysia
🇰🇷 South Korea
🇪🇸 Spain
🇸🇪 Sweden
🇺🇸 United States
Targeted industry:
Commerce and shopping
Manufacturing
Real estate
First seen:
05 Jul 2023
Description:

Underground is a ransomware group first discovered in July 2023. The ransomware encrypts the victim’s data and uploads it to a remote server for ransom leverage. Underground does not operate a Dedicated Leak Site (DLS).

Threat actor:
WhiteRabbit
Targeted Region:
🇩🇴 Dominican Republic
🇮🇹 Italy
🇪🇸 Spain
🇺🇸 United States
Targeted industry:
Financial services
Information technology
Insurance
First seen:
10 Dec 2021
Description:

White Rabbit ransomware was first detected on December 14, 2021. The ransomware adds the .scrypt extension to encrypted files and drops a ransom note named <filename>.scrypt.txt.

Anatomy of a modern ransom note

A ransom note is the final stage of a ransomware attack and a carefully engineered psychological instrument. Every element serves a purpose.
Anatomy of a modern ransom note

The evolution of ransom notes

Ransom notes date back centuries — originally letters cut out from newspapers and magazines to hide the sender’s identity. As crime moved into the digital realm, so did the ransom note, evolving in form and psychological sophistication.

1980s–1990s
1980s–1990s
Early ransomware notes were blunt and low-tech. The AIDS Trojan asked victims to mail $189 to a PO Box in Panama. The attack relied on novelty, not fear.
2013
2013
CryptoLocker introduced the countdown timer: pay in Bitcoin within 72 hours or lose your data permanently. The ticking clock became ransomware's most enduring psychological weapon.
2016
2016
Locky brought professionalism to extortion. Multilingual notes walked victims step by step through Tor browsers and payment portals, making ransom payment feel like a business transaction.
2019
2019
Maze changed the ransomware market. By threatening to publish stolen data alongside encrypting it, they invented double extortion. Reputation risk joined financial loss as a core pressure lever. REvil and DoppelPaymer followed immediately.
2020-2021
2020-2021
REvil added live chat negotiation to the ransom note experience, mimicking e-commerce support systems. BlackCat pushed to triple extortion: leak data, notify the victim's partners and media, and threaten DDoS attacks simultaneously.
2022–2025
2022–2025
RaaS standardized the ransom note into a branded template. Early-payment discounts, cryptocurrency guides, and public shaming became routine features across affiliate programs.

Ransomware
readiness guide

Check out the self-assessment framework to test your ransomware resilience

2026 and beyond:
Key trends in ransom notes

Professional tone
Modern ransom notes read like service agreements. SafePay frames the intrusion as “paid training for your system administrators.” Medusa specifies it will only speak with “an authorized person — CEO, top management.” The tone is corporate, and the implicit message is that payment is a routine business decision rather than a response to a crime.
“User-friendly” payment instructions
Modern notes treat the victim as a non-technical end user who needs guidance through the payment process. Sinobi provides 7 negotiation portal mirrors with a clearnet fallback if Tor is blocked. INC Ransom and 8Base include explicit Tor Browser download links and step-by-step contact instructions. The logic is commercial: a victim who cannot figure out how to pay is a victim who does not pay.
Turning employees into informants
Some groups now embed recruitment appeals in the ransom note, targeting employees at the victim organization. Sarcoma's note states: “If you help us find this company's dirty laundry you will be rewarded.” The tactic may serve two purposes: yield intelligence about where sensitive data is stored and signal to leadership that the attacker may already have an inside source, amplifying paranoia and urgency.
Delegitimizing every alternative to payment
Notes try to discredit every option other than direct negotiation. INC Ransom devotes more text to attacking law enforcement, recovery companies, and cyber insurers than to explaining the payment process. Medusa warns that authorities “will only waste your time.” SafePay frames non-payment as a reputational and legal liability. The goal is to make the victim feel like paying is the only rational choice (which is not!).
Staged disclosure as a negotiating framework
Modern notes use tiered timelines rather than a single deadline. Dire Wolf offers 3 days of confidentiality before a 30-working-day publication clock begins. SafePay gives 14 days before a blog post goes live, then a further 3-day timer before publication. The Gentlemen post a 48-hour pre-publication warning with a 239-hour reveal counter. Staged disclosure gives victims the illusion of control while keeping pressure constant.
“In 2026, ransomware won't just encrypt files or leak data — it'll run like a hyper-efficient enterprise. AI agents will integrate into RaaS platforms, executing rapid encryption, destroying backups, and disabling defenses in minutes. Businesses need to reassess response strategies to mitigate ransomware that operates faster than conventional defensive measures.”
Dmitry Volkov
Dmitry Volkov
CEO at Group-IB

Ransomware attacks in 2025

Top 10 Industries Attacked by Ransomware Groups in 2025
Top 10 Industries Attacked by Ransomware Groups in 2025
Top 10 Ransomware Groups by Number of Attacks in 2025
Top 10 Ransomware Groups by Number of Attacks in 2025

Top ransomware groups to
watch out for in 2026

Hunters International
Pivoted from ransomware to extortion-only operations in January 2025 under a new project named World Leaks, providing affiliates with a self-developed exfiltration tool via panel. Despite officially announcing shutdown on July 4, 2025, the group continues to operate — leveraging stolen data alone as leverage without encryption.
Dragonforce
Active since 2023, DragonForce specializes in MSP supply chain attacks via RMM tool compromise, enabling simultaneous ransomware deployment across multiple downstream victims.
Gentlemen
Ex-Qilin affiliate turned independent RaaS operator. Emerged July 2025, run by Russian-speaking actor "hastalamuerte." Exploits FortiOS authentication bypass and maintains a database of ~14,700 pre-compromised FortiGate devices for affiliate use.
Lynx
Mid-tier RaaS group that emerged in mid-2024 and scaled rapidly through 2025. Strong presence in North America and Europe with focus on professional services.
Qilin
RaaS operation active since 2022. Led global attack counts in 2025 across all regions. Known for spear phishing initial access and targeting healthcare and manufacturing.
Deadlock
Low-profile group with no DLS or affiliate program. Uses Polygon blockchain smart contracts to rotate C2 proxy addresses — a novel evasion technique. Ransom notes have evolved across three versions, now offering victims a post-incident security report and non-reattack guarantee.
Akira
Prolific RaaS group with strong North American and European presence. Targets professional services, manufacturing, and healthcare with double extortion tactics.
Cl0p
Veteran operator known for mass exploitation of zero-day vulnerabilities in file transfer software. Operates island-style with internal tooling and no public affiliate recruitment.
Play
Consistent mid-tier operator with a strong focus on North America. Avoids public RaaS advertising, operating as a closed group with selective targeting.
SafePay
Emerging group that rose sharply in 2025, establishing a particularly strong foothold in Europe and Latin America. Operates a lean, low-profile affiliate structure.
Sinobi
Emerging operator with a concentrated focus on North America. Ranked in the top 10 globally in 2025 despite limited prior visibility, suggesting rapid affiliate expansion.
Inc Ransomware
Versatile RaaS operator with activity across all major regions. Targets a broad range of industries with consistent double extortion pressure.
Sarcoma
Claimed 36 victims in its first month and 221 incidents within 18 months — one of the fastest growth trajectories in the current landscape. Targets both Windows and Linux environments and is notable for embedding employee solicitation directly in the ransom note, offering rewards for insider intelligence on the victim organization.

Frequently asked
questions

What is a ransom note in cybersecurity?

A ransom note is a message left by attackers after a successful ransomware attack. It informs the victim that their files have been encrypted and, in most modern attacks, that data has been exfiltrated. The note provides instructions for paying the ransom in exchange for a decryption key and a promise not to publish stolen data. Modern ransom notes include unique victim IDs, Tor-based negotiation portals, deadline timers, and increasingly, specific references to regulatory obligations or named individuals whose data has been taken.

What should I do if I receive a ransom note?

Contact Group-IB’s incident response experts immediately. There is a chance that your files can be decrypted and that your data can be recovered. Do not reboot any affected systems before forensic experts can take memory dumps — this data is critical and may be lost permanently if systems are restarted. Do not engage with threat actors through any communication channel they provide.

Your immediate priorities should be containment and evidence preservation. Work with incident response specialists to identify the attackers’ TTPs, determine the root cause, and uncover any hidden traces of the attackers still present in your infrastructure. Report the attack to law enforcement to initiate a formal investigation.

Should I pay the ransom?

No. Group-IB strongly advises against paying the ransom. In 83% of ransomware cases, data exfiltration is now involved, adding another layer of danger and complication. Even when organizations feel pressured to pay, there are no guarantees of recovering encrypted data or having stolen information removed from dedicated leak sites.
Paying the ransom only emboldens the cybercriminals and signals that the organization is an easy target. Beyond immediate response, organizations should take proactive steps to overhaul their security strategies and stay ahead of ransomware operators.

Can ransomware be decrypted without paying?

In some cases, yes. Decryption without payment is possible when law enforcement operations have seized a ransomware group’s infrastructure and recovered decryption keys — as occurred with operations targeting LockBit and Hive. For FunkSec specifically, a free decryptor was released in July 2025 following the group’s dormancy. Group-IB’s incident response team assesses decryption possibilities as a first step in every engagement.

How do I identify which ransomware group attacked me?

Ransomware groups can often be identified through the file extension appended to encrypted files, the name and format of the ransom note file, the content and structure of the note, and the Tor address used for negotiation. Group-IB’s Threat Intelligence team maintains profiles on hundreds of active ransomware groups and can identify attackers rapidly based on these artifacts.

What is a Dedicated Leak Site (DLS)?

A Dedicated Leak Site is a website, typically hosted on the Tor network, operated by a ransomware group to publicly publish stolen data from victims who refuse to pay. Group-IB tracks over 100 active leak sites as part of its continuous threat intelligence monitoring.

What is double extortion ransomware?

Double extortion is a technique introduced by the Maze group in 2019, in which attackers both encrypt a victim’s data and exfiltrate a copy before encryption. This creates two independent threats: the operational disruption of locked files, and the reputational and legal risk of stolen data being published. Today, data exfiltration is involved in most ransomware cases. Triple extortion adds threats of DDoS attacks or direct notification to customers, partners, and regulators.

What is Ransomware-as-a-Service (RaaS)?

Ransomware-as-a-Service is a criminal business model in which ransomware developers lease their malware and supporting infrastructure to affiliates, who carry out attacks and share a percentage of ransom payments with the developers. RaaS has dramatically lowered the technical barrier to conducting ransomware attacks. In 2025, the total number of new affiliate programs dropped from 39 in 2024 to 32, an 18% decrease. While new groups continue to emerge, the net decline highlights a more cautious, fragmented market, where operators are prioritizing operational security over recruitment scale.

How can ransomware attacks be prevented?

Ransomware attacks are not instantaneous — they unfold over days, sometimes even weeks. In good news, this gives organizations several opportunities to detect and stop the attack before serious damage occurs.

  • Implement Endpoint Detection and Response solutions like Managed XDR to identify ransomware indicators at the earliest stage
  • Monitor dark web activity through Threat Intelligence to detect when access to your network is being bought or sold by initial access brokers
  • Maintain regular offline data backups stored separately from primary infrastructure
  • Conduct infrastructure audits such as Compromise Assessment and Red Teaming to identify and remediate vulnerabilities before attackers can exploit them
  • Train your leadership with Management Masterclasses, and stress-test your teams with Tabletop Exercises to validate your readiness before a ransomware attack happens.
How does Group-IB help ransomware victims?

Group-IB’s incident response team has handled hundreds of ransomware cases across industries and geographies. From the moment you make contact, our experts work to contain the breach, preserve forensic evidence, identify the threat actor and their methods, and support recovery. In some cases, decryption without payment is possible. Our threat intelligence capabilities allow us to monitor whether your data appears on leak sites or underground forums, giving you visibility into the full scope of exposure. Group-IB is ranked #1 for Incident Response retainer by the Cybersecurity Excellence Awards.