Ransomware Groups

Track active ransomware operations, dark web infrastructure, and associated threat actors

660
Ransomware Groups

Hive

Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe. In 2022 there was a switch from GoLang to Rust.

3 sites2023

Cryakl

Fargo

Fakersa

Noname

NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized businesses globally using its custom ScRansom tool, exploiting vulnerabilities like EternalBlue and ZeroLogon, and becoming a RansomHub affiliate to access that platform's RaaS infrastructure.

5 sites2024

Skira Team

1 site2025

Mydecryptor

MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.

1 site2021

Bidon

Xelera

Dataf Locker

1 site2024

Thundercrypt

Bitransomware

1 site2024

La Piovra

3 sites2024

Minteye

MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction, engineering, architecture, and logistics sectors, with victims documented in the US and Chile; limited public technical analysis is available.

2 sites2025

Chort

Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance.

1 site2024

Kuiper

Jaff

1 site1 actor2024
TA505, Graceful Spider, Gold Evergreen

Zero Tolerance Gang (Ztg)

1 site2024

Darkrace

DarkRace is a ransomware variant that surfaced in mid-2023 sharing strong code similarities with LockBit, employing double-extortion via a dark web leak site, but remained a minor player with fewer than 15 posted victims in its first half-year.

1 site2023

Lockbit3

LockBit, also recognized as LockBit Black or Lockbit 3.0, is one of the largest Ransomware Groups in the world and has orchestrated extensive cyberattacks across various industries, impacting thousands of organizations globally with its relentless and adaptive strategies.

41 sites2022

Deathgrip

Direwolf

Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.

3 sites2026

Ymir

Payoutsking

PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics.

3 sites2025
Showing 241 - 264 of 660
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001