Actor Profile

🏹 Threat Actor Profile

Unified dossier across APT, nation-state, ransomware & malware actors: aliases, MITRE ATT&CK, live leak-site victims, associated indicators & pivots.

Tracked Ransomware Groups (Ransomware.live)

GroupDescription
0apt The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele dossier
0day Syndicate dossier
0mega 0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worl dossier
8base The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. Th dossier
ALP-001 ⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified. WE HAVE DECIDED TO REMOVE dossier
Abrahams_Ax Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily target dossier
AiLock AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid C dossier
Aptlock dossier
AuditTeam AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and dossier
Barracuda dossier
Black X dossier
Blackfield dossier
Booba Project Booba dossier
BrainCipher Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of dossier
CMDOrganization CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all dossier
CRPxO CRPxO is actively recruiting affiliates, offering: 🔹 70% revenue share 🔹 XMR/BTC payouts 🔹 Claimed payouts within 24 hou dossier
ContFR RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon dossier
D1R D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion dossier
Dark Project Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortio dossier
DarkMatter dossier
Deadlock dossier
Doommageddon Direct Extortion Double Extortion dossier
ElDorado In September The El Dorado ransomware group have been rebrand as BlackLock dossier
ExfilSquad Only exfiltration dossier
GDLockerSec Our team members are from different countries and we are not interested in anything else, we are only interested in doll dossier
Gammax dossier
Global Secret Group dossier
GodDamn ransomwhere dossier
IMNCrew IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial service dossier
Icarus dossier
J J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 includi dossier
LeakBazaar dossier
Loki dossier
NotPetya dossier
Orova First seen 2026-07-07 dossier
Panzer dossier
Payday dossier
PrinzEugen dossier
Redact dossier
RunSomeWares RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain ser dossier
Section9 🚨 This is a fake group with fake victims. dossier
SenSayQ SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortio dossier
SevyWare Direct Extortion Double Extortion dossier
ShadowByt3$ ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communic dossier
Shiba dossier
ShinySp1d3r Likely associated with the cybercrime group BlingLibra (ShinyHunters) dossier
SilentRansomGroup a former Conti team dossier
The Green Blood Group dossier
The Syndicate Data Broker dossier
TiMc TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader S dossier
Tommyleaks dossier
Triple X dossier
ULose dossier
ValenciaLeaks ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of dossier
VanHelsing VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and s dossier
Wallstreet dossier
aGl0bGVyCg "aGl0bGVyCg" (Base64 for "hitler") is a reference to the Hitler-Ransomware (2016), a German-origin proof-of-concept that dossier
abyss Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk sour dossier
adminlocker AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files a dossier
againstthewest AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived dossier
akira The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the for dossier
ako A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker dossier
alphalocker AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin pane dossier
alphv The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to dossier
anubis Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, dossier
apos Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publ dossier
apt73 A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the gro dossier
arcusmedia Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA- dossier
argonauts Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, dossier
arkana Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband pro dossier
arvinclub Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data dossier
atomsilo AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vuln dossier
aurora Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams fro dossier
avaddon Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where dossier
avos Avos is the threat actor group behind AvosLocker ransomware, a RaaS operation active since June 2021 that recruited affi dossier
avoslocker AvosLocker is the ransomware payload of the Avos RaaS group, active from July 2021 to approximately May 2023, targeting dossier
aware Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documenta dossier
aztroteam AztroTeam is a ransomware group with very limited public documentation and no confirmed victims, listed as offline on ra dossier
babuk Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most us dossier
babuk2 Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on for dossier
babyduck BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduc dossier
beast Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, se dossier
benzona Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organization dossier
bert BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across heal dossier
bianlian BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a dossier
blackbasta "Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 dossier
blackbyte Ransomware. Uses dropper written in JavaScript to deploy a .NET payload. dossier
blacklock BlackLock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most acti dossier
blackmatter Ransomware-as-a-Service dossier
blacknevas BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware fam dossier
blackout Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities dossier
blackshadow BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies includin dossier
blackshrantac BlackShrantac is a ransomware group that emerged in late 2025, targeting organizations in manufacturing, financial servi dossier
blacksuit According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware. dossier
blacktor Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victim dossier
blackwater Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and target dossier
bluebox Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims prim dossier
bluelocker Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum dossier
bluesky BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/ dossier
bonacigroup Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going off dossier
bqtlock BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payme dossier
bravox BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the dossier
brotherhood Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia ac dossier
cactus The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities t dossier
cephalus Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomwar dossier
chaos Chaos is a ransomware-as-a-service operation that emerged in early 2025, likely formed by former BlackSuit/Royal members dossier
cheers Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in att dossier
chilelocker ChileLocker (also known as ARCrypter) first appeared in August 2022 after attacking a Chilean government agency and quic dossier
chort Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primari dossier
cicada3301 Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 usin dossier
ciphbit CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the U dossier
cipherforce CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeti dossier
cloak Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in dossier
clop The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that t dossier
coinbasecartel CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on dossier
conti Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It dossier
cooming CoomingProject is a ransomware group that emerged around 2021 and operated a double-extortion scheme with multiple Tor-b dossier
crazyhunter CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, ex dossier
crosslock CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve dossier
cry0 Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payloa dossier
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php