Ransomware Groups

Track active ransomware operations, dark web infrastructure, and associated threat actors

637
Ransomware Groups

rabbithole

1 site

radiant

1 site

ranstreet

1 site

raworld

RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.

2 sites

rebornvc

2 sites

redransomware

1 site

RunSomeWares

3 sites

satanlockv2

1 site

shaoleaks

1 site

ShinySp1d3r

Likely associated with the cybercrime group BlingLibra (ShinyHunters)

1 site

sicarii

2 sites

SilentRansomGroup

a former Conti team

1 site

skira

1 site

spacebears

1 site

thegentlemen

1 site

thegreenbloodgroup

1 site

threeam

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

2 sites

u-bomb

1 site

underground

2 sites1 actor
Tropical Scorpius, RomCom

ValenciaLeaks

1 site

vanirgroup

1 site

vendetta

Ransomware, which appears to be a rebranding of win.cuba.

1 site

wannacry

WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat. Cybercriminals used the ransomware to hold an organization's data hostage and extort money in the form of cryptocurrency. WannaCry spreads using EternalBlue, an exploit leaked from the National Security Agency (NSA). EternalBlue enables attackers to use a zero-day vulnerability to gain access to a system. It targets Windows computers that use a legacy version of the Server Message Block (SMB) protocol.

1 site2 actors
Lazarus Group, Hidden Cobra, Labyrinth ChollimaLazarus Group

x001xs

1 site
Showing 601 - 624 of 637
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001