Ransomware Groups
Track active ransomware operations, dark web infrastructure, and associated threat actors
Vect
Lockbit5
Relic
Mortalkombat
Fletchen
Donutleaks
Mallox
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company>
Quicklock
Lynx
Cyberex
Grinch
Inpivx
Superblack
Dark Power
Crazyhunter Team
Balletspistol
Phobos
Lynxr
Pysa
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
Fulcrumsec
Cheers
Avaddon
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.
Solidbit
Ransomware, written in .NET.
Prometheus
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.