Ransomware Groups

Track active ransomware operations, dark web infrastructure, and associated threat actors

637
Ransomware Groups

Atomsilo

3 sites1 actor2021
Bronze Starlight

Nevada

3 sites2021

Funksec

10 sites2024

Maze

Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. is malware targeting organizations worldwide across many industries. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'.

7 sites3 actors2021
FIN7TA2101, Maze Team+1

Ragnarok

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.

2 sites2021

Vanhelsing

10 sites2025

Devman

Former RansomHub and INC Ransom affiliate.

3 sites2025

Spring

Babuk Bjorka

6 sites2025

Fog

Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.

5 sites1 actor2025
Unknown

Hermes

1 actor
Lazarus Group, Hidden Cobra, Labyrinth Chollima

Netwalker

NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.

2 sites1 actor2021
Circus Spider

Lamialocker

Risen

3 sites2024

Darkylock

Kryptos

1 site2025

Lyrix

1 site2025

Blacktor

1 site2023

Encrypthub

Aztroteam

1 site2021

J Group

3 sites2025

Global

4 sites2025

Argonauts Group

2 sites2025

Shade

1 site2024
Showing 481 - 504 of 637
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001