Ransomware Groups

Track active ransomware operations, dark web infrastructure, and associated threat actors

661
Ransomware Groups

Endurance

1 site2023

Thanos

Pyrx

2 sites2025

C3Rb3R

2 sites1 actor2024
C3RB3R operator

Vandev

Cloak.Su (Locker Leak)

1 site2026

Elonmusknow

1 site2025

Vicesociety

Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty"

8 sites2021

Lunalock

LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid.

2 sites2026

Late.Lol

1 site2026

Kazu

Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations primarily in Southeast Asia, the Middle East, and Latin America, with notable claimed breaches including Dubai's Ports, Customs and Free Zone Corporation with 1.94 TB exfiltrated.

1 site2026

Sabbath

Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.

2 sites2021

Karakurt

Karakurt is a pure data-extortion group (no encryption) assessed with high confidence to be the extortion arm of the Conti ransomware group, active from 2021, that steals data and threatens to auction or publish it unless ransoms ranging from $25,000 to $13 million are paid.

9 sites2023

Lcryptorx

2 sites2025

Crynox

Handala

Not a Ransomware Group

6 sites1 actor2026
Handala Hack Team

Ctblocker

2 sites2024

Helldown

Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.

4 sites2024

Darkvault

DarkVault is a data-exfiltration and double-extortion group first identified in late 2023, targeting medium-to-large organizations in finance, professional services, legal, and technology sectors across Europe, the UK, and North America, with a suspected connection to LockBit.

3 sites2025

Tssxx25

1 site2025

Ironchain

1 site2026

Hyflock

1 site2026

Spirigatito

Arachna Leak

1 site2026
Showing 313 - 336 of 661
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001