Ransomware Groups 31 articles
More in Adversaries & Campaigns:
APT Campaigns 26
Cybercrime Groups 77
Hacktivist Groups 29
Initial Access Brokers 16
Nation-State Actors 54
Ransomware Groups 31
01
Akira
Summary Akira is a sophisticated application-layer attack framework designed to exploit vulnerabilities in web applications and APIs. It automates the process of identifying and exploiting security weaknesses such as injection…
02
Babuk
Summary Babuk is a ransomware strain known for targeting organizations by encrypting their data and demanding ransom payments for decryption keys. It gained notoriety for its use in high-profile attacks…
03
BlackByte
Summary BlackByte is a ransomware group known for deploying sophisticated ransomware attacks targeting organizations worldwide. It operates by encrypting victims' data and demanding ransom payments, often accompanied by data exfiltration…
04
Cl0p
Summary Cl0p is a ransomware group known for targeting organizations through application vulnerabilities and exploiting security weaknesses to deploy ransomware and exfiltrate sensitive data. It employs double extortion tactics, encrypting…
05
Conti
Summary Conti is a sophisticated ransomware group known for deploying ransomware-as-a-service (RaaS) operations targeting organizations worldwide. It primarily compromises enterprise networks through phishing, exploiting vulnerabilities, and brute-force attacks to encrypt…
06
Cuba
Summary Cuba has been identified as a source of various cyber threats, including application-layer attacks targeting government, financial, and telecommunications sectors. These attacks often involve exploitation of web applications, injection…
07
DarkMatter
Summary DarkMatter is a cyber threat actor known for conducting sophisticated application attacks, often targeting government, military, and critical infrastructure organizations. The group is associated with advanced persistent threat (APT)…
08
Egregor
Summary Egregor is a ransomware-as-a-service (RaaS) operation known for targeting organizations worldwide by encrypting data and demanding ransom payments for decryption keys. Emerging in late 2020, Egregor quickly gained notoriety…
09
Everest
Summary Everest is a type of application attack that targets vulnerabilities in software applications to gain unauthorized access, disrupt services, or steal sensitive data. It typically exploits flaws such as…
10
HelloKitty
Summary HelloKitty is a ransomware strain known for targeting enterprise environments by encrypting critical data and demanding ransom payments for decryption keys. It gained notoriety for its sophisticated attack techniques,…
11
Hive
Summary Hive is a ransomware group known for deploying ransomware-as-a-service (RaaS) to conduct widespread cyberattacks targeting organizations across various sectors. The group encrypts victims' data and demands ransom payments, often…
12
Karakurt
Summary Karakurt is a cybercriminal group known for engaging in data extortion and ransomware-related activities. The group primarily targets organizations by stealing sensitive data and threatening to release it publicly…
13
Knight (Cyclops)
Summary Knight (Cyclops) is a sophisticated application attack framework targeting web and mobile applications to exploit vulnerabilities such as injection flaws, authentication bypass, and session hijacking. It is known for…
14
LockBit
Summary LockBit is a ransomware family known for targeting organizations by encrypting their data and demanding ransom payments for decryption keys. It operates as a ransomware-as-a-service (RaaS) model, allowing affiliates…
15
Lorenz
Summary Lorenz is a type of malware primarily classified as a remote access trojan (RAT) that targets Windows-based systems. It is used by threat actors to gain unauthorized access, control…
16
Makop
Summary Makop is a ransomware strain that targets Windows-based systems by encrypting files and demanding a ransom payment for their decryption. It is typically distributed through phishing emails, exploit kits,…
17
Maze
Summary Maze is a ransomware strain and cybercriminal group known for combining data encryption with data exfiltration and extortion tactics. It targets organizations by infiltrating networks, encrypting critical files, and…
18
Medusa
Summary Medusa is a fast, parallel, and modular password brute-forcing tool used primarily to perform online brute-force attacks against various network services and applications. It is designed to test the…
19
MegaCortex
Summary MegaCortex is a ransomware strain that primarily targets enterprise networks, leveraging advanced techniques to encrypt data and demand ransom payments. It is known for its use of legitimate administrative…
20
MountLocker
Summary MountLocker is a ransomware family first identified in mid-2020 that targets enterprise networks by encrypting files and demanding ransom payments for decryption keys. It is known for its use…