Ransomware

LIVE

RANSOMWARE INTELLIGENCE

Activity ratings derived from real-time victim leak site data. Groups are auto-discovered and scored based on victim volume, recency, and momentum.

91 groups tracked

Surging

4

3+ victims in 7 days

Active Groups

66

Currently operating

Critical Threat

8

Highest priority

Total Victims

863

From leak site data

Untracked

0

All groups synced

Sort:

Ransomware Groups (91)

Qilin

Qilin.B (Rust variant)

100
269
33
176
Surging
Critical
Active

Akira

GOLD SAHARA, PUNK SPIDER

100
114
23
77
Surging
High
Active

Nightspire

99
98
17
60
Surging
High
Active

DragonForce

DragonForce Ransomware Cartel

98
93
6
64
Surging
High
Active

Play

Play Ransomware, Playboy Ransomware

89
101
2
60
Active
High
Active

LockBit5

LockBit, LockBit 3.0

59
46
0
29
Active
Critical
Disrupted

Genesis

59
29
0
22
Active
High
Active

Vect

56
21
0
16
Active
Critical
Highly Active

Lapsus$

LAPSUS$, Lapsus Group

48
10
0
10
Active
High
Inactive

Everest

Everest Ransomware

38
16
1
7
Active
High
Active

Sinobi

35
30
0
9
Active
High
Active

Atomsilo

AtomSilo, Grief

32
1
0
1
Declining
High
Inactive

Rhysida

31
10
0
5
Active
High
Active

Medusa

31
10
0
5
Active
High
Highly Active

RansomHouse

RansomHouse Group

24
11
0
4
Declining
High
Active

Morpheus

Agent Smith, The Architect

22
2
0
1
Declining
Critical
Active (High Activity)

Abyss

Abyss Locker, AbyssLocker

22
2
0
1
Declining
High
Active

LockBit 3.0

LockBit Black, LockBit

0
0
0
0
Dormant
Critical
Active

LockBit

LockBit 2.0, LockBit 3.0

0
0
0
0
Dormant
Critical
Disrupted (Operation Cronos)

LockBit 2.0

LockBit, LockBit Black

0
0
0
0
Dormant
Critical
Active

Conti

Conti Team, Conti Group

0
0
0
0
Dormant
Critical
Disrupted/Evolved

0mega

0mega Ransomware, Omega Ransomware

0
0
0
0
Dormant
High
Active

Monti

Monti Ransomware

0
0
0
0
Dormant
High
Active

Osiris

0
0
0
0
Dormant
High
Active

Trident Locker

TridentLocker, Trident

0
0
0
0
Dormant
High
Active

Inc Ransom

Inc. Ransom, GOLD IONIC

0
0
0
0
Dormant
High
Active

Money Message

MoneyMessage, MnyMsg

0
0
0
0
Dormant
High
Active

Black Basta

Storm-0506

0
0
0
0
Dormant
High
Active

RansomHub

RansomHub Ransomware

0
0
0
0
Dormant
High
Active

Hunters

Hunters International

0
0
0
0
Dormant
High
Active

Mallox

TargetCompany, Fpcc

0
0
0
0
Dormant
High
Active

Cooming

CoomingProject

0
0
0
0
Dormant
High
Active

BlackSuit

BlackSuit Ransomware

0
0
0
0
Dormant
High
Active

VanirGroup

Vanir Locker

0
0
0
0
Dormant
High
Active

MalekTeam

0
0
0
0
Dormant
High
Active

imncrew

IMNCrew

0
0
0
0
Dormant
High
Active

BlueLocker

Blue Locker

0
0
0
0
Dormant
High
Active

raworld

Raworld

0
0
0
0
Dormant
High
Active

GunRansom

GunRansomware, GUNRANSOM

0
0
0
0
Dormant
High
Active

BonaciGroup

Bonaci

0
0
0
0
Dormant
High
Active

RedAlert

Nokoyawa

0
0
0
0
Dormant
High
Active

Babuk2

Babuk Locker, Babuk

0
0
0
0
Dormant
High
Active

Hotarus

0
0
0
0
Dormant
High
Active

LostTrust

LostTrust Ransomware

0
0
0
0
Dormant
High
Active

Babuk

Babuk Locker, Babuk Ransomware

0
0
0
0
Dormant
High
Inactive (core group), Variants/Offshoots Active

HolyGhost

Holy Ghost, HolyGhost Ransomware

0
0
0
0
Dormant
High
Active

Daixin Team

Daixin

0
0
0
0
Dormant
High
Active

Snatch

Snatch Ransomware

0
0
0
0
Dormant
High
Active

MosesStaff

Moses Staff

0
0
0
0
Dormant
High
Active

MedusaLocker

Medusa, Medusa Ransomware

0
0
0
0
Dormant
High
Active

NovaLocker

Nova, Nova Ransomware

0
0
0
0
Dormant
High
Active (Sporadic activity reported in late 2023)

Lorenz

Lorenz ransomware

0
0
0
0
Dormant
High
Active

Nevada

Nevada Ransomware

0
0
0
0
Dormant
High
Active

Pysa

Mespinoza, WannaCryFF

0
0
0
0
Dormant
High
Active

Ransom Cartel

RansomCartel

0
0
0
0
Dormant
High
Active

Lunalock

Luna Ransomware

0
0
0
0
Dormant
High
Active

Lilith

Lilith Ransomware

0
0
0
0
Dormant
High
Active

Pandora

Pandora Ransomware

0
0
0
0
Dormant
High
Active

DarkAngels

Dark Angels

0
0
0
0
Dormant
High
Active

Midas Ransomware

Midas Ransomware, Midas

0
0
0
0
Dormant
High
Active

Karakurt

Karakurt Team, Karakurt Ransomware Group

0
0
0
0
Dormant
High
Active

DagonLocker

Dagon

0
0
0
0
Dormant
High
Active

Entropy

FiveHands

0
0
0
0
Dormant
High
Active

IceFire

0
0
0
0
Dormant
High
Active

RagnarLocker

Ragnar Locker, Ragnar_Locker

0
0
0
0
Dormant
High
Active (with periods of reduced activity and re-emergence)

Rook

Rook Ransomware

0
0
0
0
Dormant
High
Inactive

Ranzy

Ranzy Locker

0
0
0
0
Dormant
High
Inactive

Diavol

Diavol Ransomware

0
0
0
0
Dormant
High
Active

HelloKitty

FiveHands, DeathKitty

0
0
0
0
Dormant
High
Inactive

onepercent

OnePercent Group, OnePercent Ransomware

0
0
0
0
Dormant
High
Inactive

Prometheus

Prometheus Ransomware

0
0
0
0
Dormant
High
Inactive

BlackMatter

DarkSide, REvil

0
0
0
0
Dormant
High
Disbanded

Ragnarok

Ragnar Locker

0
0
0
0
Dormant
High
Inactive

MountLocker

Mount Locker

0
0
0
0
Dormant
High
Inactive/Evolved

Prolock

Prolocker

0
0
0
0
Dormant
High
Inactive/Declining

Avaddon

Avaddon Ransomware

0
0
0
0
Dormant
High
Inactive (Self-proclaimed shutdown)

Nefilim

Nephilim, Nemty

0
0
0
0
Dormant
High
Inactive

Pay2Key

Linked to: Pioneer Kitten

0
0
0
0
Dormant
High
Inactive

Hades

Hades Ransomware, Linked to: Evil Corp

0
0
0
0
Dormant
High
Inactive

Netwalker

Mailto, Karakurt

0
0
0
0
Dormant
High
Disrupted

Maze

ChaCha, Active Directory

0
0
0
0
Dormant
High
Inactive

RobinHood

RobinHood Ransomware

0
0
0
0
Dormant
High
Inactive

BlackByte

0
0
0
0
Dormant
High
Active

GOLD SOUTHFIELD

Pinchy Spider

0
0
0
0
Dormant
High
Active

Storm-0501

0
0
0
0
Dormant
High
Active

Storm-1811

0
0
0
0
Dormant
High
Active

Water Galura

GOLD FEATHER

0
0
0
0
Dormant
High
Active

Nokoyawa

Bashful Scorpius

0
0
0
0
Dormant
High
Active

Trigona

0
0
0
0
Dormant
High
Active

REvil

Sodinokibi, GOLD SOUTHFIELD

0
0
0
0
Dormant
High
Active

Medusa Group

0
0
0
0
Dormant
High
Active