Ransomware Groups

Track active ransomware operations, dark web infrastructure, and associated threat actors

637
Ransomware Groups

Snatch

Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.

11 sites2 actors2022
TA505, Graceful Spider, Gold EvergreenTA554

Kelvin Security

1 site2026

Blackberserk

Meow

5 sites2024

Ra Group

4 sites2023

Mailto

Kryptina

Taronis

Daixin

9 sites2024

Royal

According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.

5 sites2023

Rabbit Hole

1 site2024

Insane Ransomware

3 sites2024

Hades

According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension.

2 sites1 actor2021
Indrik Spider

Ciphbit

3 sites2025

Hunters

In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.

8 sites2024

Elpaco

Lapsus$

5 sites2026

Avoslocker

2 sites2023

Wiper Leak

1 site2026

Blackbyte

Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.

13 sites1 actor2021
BlackByte

Ransomexx

RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.

4 sites2025

White Lock

1 site2025

Safepay

12 sites2024

Chaos

10 sites2025
Showing 385 - 408 of 637
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001