Ransomware Groups
Track active ransomware operations, dark web infrastructure, and associated threat actors
Space Bears
Gunra
Suncrypt
Jo Of Satan
Arvinclub
Playboy
Zircon
Weaxor
Telegram
Bluesky
Malphas
Ghost
Evolution
Toufan
Pro-Palestinian Group
Cryptnet
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256 bit key and IV.* The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
Diavol
A ransomware with potential ties to Wizard Spider.
Noescape
Ragnarlocker
Doppelpaymer
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".