Trending Adversaries
Who's moving, and how fast. Mallory tracks named threat actors across vendor reports, researcher analysis, and underground chatter, then surfaces the ones picking up momentum right now.
Ranked by Mallory's mention-velocity model across sources.
Mention map · Last day
Sized by mentionsTop 24 threat actors · Last day
Medusa is a ransomware-as-a-service operation active since 2021 that evolved from a closed ransomware variant into an affiliate-based extortion enterprise around 2023. It is distinct from MedusaLocker. The operation is associated with the Medusa Blog leak site and uses double extortion, combining data theft with network encryption and threats to publish stolen information. Reporting through April 2026 indicates that Medusa had compromised more than 500 organizations, including a large number of critical infrastructure entities in the United States. Medusa has heavily targeted healthcare and public health organizations, while also affecting defense industrial base, critical manufacturing, government services, information technology, financial services, education, legal, insurance, and broader manufacturing environments. Victimology also includes U.S. municipal entities and international municipal governments. Medusa commonly obtains initial access through recruited initial access brokers and has also exploited public-facing applications and newly disclosed vulnerabilities with unusual speed, in some cases within 24 hours of disclosure and occasionally before public disclosure. Once inside a victim environment, operators and affiliates use credential theft, legitimate remote monitoring and management tools, living-off-the-land techniques, PowerShell, Windows Management Instrumentation, and Remote Desktop Protocol to expand access, move laterally, evade detection, exfiltrate data, and deploy ransomware. Observed tradecraft also includes disabling or terminating security tools, security software discovery, use of vulnerable or stolen drivers for defense evasion, and attempts to bypass User Account Control through COM-based methods. Medusa’s extortion model includes leak-site publication, discounts for rapid payment, and paid deadline extensions for delaying data release. At least one observed case suggested either triple-extortion behavior or internal operational dysfunction when a victim was told to pay again for a purported real decryptor after an earlier payment. Medusa operators typically recruit affiliates and access brokers on criminal forums and marketplaces, with payments reportedly ranging from small sums to very large payouts for exclusive access. The operation has been one of the more active ransomware groups in the broader cybercriminal ecosystem since its expansion in 2023.
TA505 is a financially motivated cybercrime threat actor active since at least 2014 and widely associated with large-scale malware distribution, ransomware deployment, and data-extortion operations. The cluster is also tracked under aliases including Graceful Spider, Gold Tahoe, Hive0065, DEV-0950, Lace Tempest, Monty Spider, and Spandex Tempest, and is closely linked to Clop/Cl0p operations. In multiple reporting traditions, Clop is treated either as a ransomware and extortion brand operated by TA505-linked actors or as a closely associated subgroup or affiliate ecosystem descended from TA505 activity. TA505 is known for broad, opportunistic victimization at enterprise scale and for repeatedly targeting widely deployed business software and managed file transfer or product lifecycle management platforms. Reported campaigns tied to the actor or its Clop-linked operations have involved exploitation of Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo products, Oracle E-Business Suite, and PTC Windchill and FlexPLM. The actor has demonstrated a pattern of mass exploitation of internet-exposed enterprise applications, followed by deployment of tailored web shells or follow-on tooling to steal sensitive data and pressure victims through extortion. Historically, TA505 has also been associated with spear-phishing-led intrusions and malware delivery, including use of the Get2 loader, and with subsequent deployment of Clop ransomware. More recent activity emphasizes data theft and extortion over pure encryption-centric operations. In Clop-linked campaigns, the actor has used custom implants purpose-built for victim platforms, including web shells capable of credential theft, secret decryption, database querying, file discovery, file transfer preparation, and in-memory execution of additional payloads. This tradecraft supports post-exploitation expansion, stealthy use of legitimate application identities, and theft of high-value enterprise data such as engineering records, intellectual property, backups, and internal business documents. The actor is widely described as Russian-speaking and Russia-linked. Its operations have affected major global enterprises across manufacturing, energy, technology, healthcare, government-related entities, and other sectors, with especially notable focus on organizations running exposed enterprise software. TA505 and its Clop-linked operations are best characterized as a mature cybercrime ecosystem specializing in initial compromise at scale, credential access, data exfiltration, persistence through server-side implants, and extortion monetization.
Dire Wolf is a ransomware threat group active by at least 2026 and publicly associated with multiple claimed intrusions across several countries. The group has been observed naming victims from the United States, Sweden, the United Kingdom, Australia, India, Brazil, Germany, and Spain, and it appeared in weekly ransomware claim tracking with 17 publicly claimed victims during one reporting period. Reported victimology indicates a broad, opportunistic targeting pattern rather than a narrowly specialized vertical focus. Observed victims span health care, financial services, information technology and software, education, and professional services. Health-care organizations appear prominently among reported victims, including hospitals, physicians-clinic contexts, and other health-related companies. Additional affected organizations include financial software providers, game and multimedia companies, legal-services firms, universities, and property-management or other professional-services entities. Operationally, Dire Wolf is associated with ransomware incidents that were also described as data breaches, indicating use of theft-based extortion in addition to ransomware deployment. Public victim claims and breach-style reporting support assessment of extortion activity and exfiltration of victim data. Available information supports ransomware-linked post-compromise activity and data theft, but does not provide high-confidence detail on initial access vectors, persistence mechanisms, privilege-escalation methods, lateral movement tradecraft, or malware-specific techniques. Known aliases include direwolf and dire_wolf. No high-confidence attribution to a nation state or a specific country of origin is currently available.
DragonForce is a cyber threat actor associated with both hacktivist and ransomware activity. The group has been described as Malaysia-based and appears to have evolved from pro-Palestinian hacktivism into a ransomware-as-a-service and extortion operation with global reach. Known aliases include DragonForce, Dragon Force, DragonForce Ransomware Cartel, Dragon Force Ransomware Group, and Slippery Scorpius. DragonForce has conducted ideologically motivated operations as well as financially motivated cybercrime. In 2022, it was linked to hacktivist campaigns against Indian government and related targets, using target discovery through search-engine and internet-exposed-service reconnaissance, exploitation of CVE-2022-26134, and HTTP-flooding distributed denial-of-service activity. It has also been linked to attacks against Israeli entities and has used propaganda and recruitment messaging through public channels. As a ransomware actor, DragonForce operates a RaaS model in which affiliates receive a substantial share of proceeds, and it has presented itself as part of a broader ransomware cartel structure. Its extortion model includes data theft and public pressure via a leak site, countdown timers, and publication of stolen data and negotiation material when victims do not pay. Reporting in 2026 placed DragonForce among the most active ransomware groups globally and across the Americas, with especially heavy victimization in the United States. DragonForce ransomware has been assessed as likely derived in part from leaked Conti or LockBit-era codebases, depending on the cluster or sample analyzed, and its tooling shows mature tradecraft for enterprise disruption. Observed capabilities include file encryption, network share enumeration, process and service termination, shadow-copy discovery, anti-forensics options, and operation across local and network-accessible resources. The group has also demonstrated advanced post-compromise tradecraft. In a 2025 intrusion against a major U.S. services firm, DragonForce operators reportedly maintained access for up to two months before ransomware deployment. During that intrusion they used a Go-based remote access trojan known as Backdoor.Turn to conceal command-and-control traffic within Microsoft Teams TURN relay infrastructure, combined with bring-your-own-vulnerable-driver-style evasion using a Huawei driver vulnerability. Reported behaviors included code execution, internal scanning, credential theft from browsers, creation of user accounts, firewall-rule modification, lateral movement, data exfiltration, and eventual encryption. DragonForce intrusions have also been associated with rapid operational tempo, supply-chain-aware targeting, and use of tooling seen in other ransomware ecosystems, including EDR-disruption tradecraft. Victim reporting and activity summaries indicate targeting of manufacturing, business services, healthcare, technology, construction, financial services, and industrial organizations, including aerospace- and defense-related manufacturers. The actor should be understood as a hybrid threat: originally hacktivist in some campaigns, but predominantly a financially motivated ransomware and extortion operation in its current form.
APT28 is a Russian state-linked cyber espionage threat actor widely tracked under aliases including Fancy Bear, Sofacy, Sednit, Pawn Storm, Strontium, Forest Blizzard, BlueDelta, Fighting Ursa, Tsar Team, Group 74, and Iron Twilight. The group is associated with long-running intelligence collection and influence-related operations aligned with Russian state interests, and is frequently linked by governments and industry to Russian military intelligence activity. APT28 has been implicated in operations against government, defense, diplomatic, political, and critical infrastructure targets, including activity directed at Ukraine and the United States. APT28 is known for spearphishing-led initial access, particularly malicious Microsoft Office attachments and macro-enabled documents, as well as the use of spoofed or lookalike infrastructure themed around organizations of geopolitical interest such as NATO and the OSCE. The group has also exploited Windows vulnerabilities, including zero-days, and has been associated with UEFI bootkit activity through LoJax. Its malware ecosystem has included families such as Zebrocy and CHOPSTICK, along with Delphi backdoors, staged downloaders, and modular implants that retrieve second-stage payloads from command-and-control infrastructure. Operationally, APT28 demonstrates mature post-compromise tradecraft. Reported behaviors include process discovery, PowerShell-based execution, staged payload delivery, screenshot capture, keylogging, collection of internal documents, and exfiltration of victim data. The group has used defense-evasion measures such as concealed PowerShell execution, hidden file attributes, payload decoding with built-in utilities, and deletion of files to cover tracks. Implants have used HTTP and HTTPS for command and control, and loaders have enumerated processes to identify suitable execution contexts. APT28 has been publicly tied to cyber espionage campaigns against Ukrainian state entities, including targeting of officials connected to Ukraine’s Asset Recovery and Management Agency. The group has also been associated with the compromise of U.S. political organizations during the 2016 election cycle. Across reporting, APT28 is consistently characterized as a highly capable Russian espionage actor focused on strategic intelligence collection, credential and document theft, and support to broader Russian information and geopolitical objectives.
INC Ransom is a financially motivated ransomware operation active since at least 2023 and commonly tracked under aliases including INC, INC Ransomware, INCRansom, Gold Ionic, and G1032. The group is associated with ransomware and data-theft extortion activity and has been linked to an affiliate-based ecosystem. Reporting also describes Lynx as an evolution of the INC ransomware lineage, and separate reporting has tied affiliates associated with the INC ecosystem to deployment of other ransomware families such as DeadLock. INC Ransom has repeatedly targeted organizations in North America and other regions, with a notable concentration on professional services firms, particularly law firms. Confirmed victim reporting also shows activity against financial services, healthcare, technology, engineering and construction-related organizations. Publicly documented targeting spans the United States, Canada, the United Kingdom, Germany, the United Arab Emirates, Australia, Malaysia, and Brazil, indicating broad international reach. The group has been associated with exploitation of internet-facing remote access infrastructure for initial access, including SSL VPN appliances and SonicWall SMA1000 devices. This aligns with broader ransomware tradecraft focused on exploiting exposed enterprise access points. INC Ransom has also been linked to use of AdFind, indicating Active Directory and enterprise environment reconnaissance during intrusions. Observed behavior supports a double-extortion operating model in which victim data is stolen and victims are pressured through threatened publication of exfiltrated information. Multiple incidents attributed to the group were explicitly described as ransomware attacks accompanied by data breaches, and victim data categories reportedly included client, financial, contractual, operational, and medical information. The operation is also publicly tracked through leak-site claims, consistent with extortion-driven ransomware activity. Overall, INC Ransom is best characterized as a cybercriminal ransomware actor focused on monetizing intrusions through encryption-linked extortion and theft of sensitive business data, with a demonstrated preference for service-sector targets and use of common enterprise intrusion and ransomware affiliate tradecraft.
Chaos is a ransomware-as-a-service operation active since at least early 2025 and associated with data theft and extortion against organizations in multiple countries. The group has been linked to dedicated leak-site activity and public victim shaming, including countdown-based publication threats, and has conducted both encryption-backed and data-theft-led extortion. Reported victims span health care, technology, professional services, education, transportation and logistics, manufacturing, energy, and construction-related organizations. Chaos has been associated with financially motivated intrusion activity that frequently relies on social engineering for initial access. Observed tradecraft includes impersonation of IT support personnel over Microsoft Teams, use of remote assistance and remote monitoring tools to gain footholds, PowerShell-delivered malware, secondary remote-access channels, reverse proxying for internal access, attempted Remote Desktop enablement, and rapid progression from compromise to ransomware deployment. At least some intrusions tied to the broader Chaos ecosystem culminated in simultaneous file encryption across multiple systems, while others involved theft of sensitive data prior to extortion. The group has also been linked to msaRAT, a Rust-based remote access trojan used before ransomware deployment. msaRAT delegates external communications to the victim’s Chrome or Microsoft Edge browser via the Chrome DevTools Protocol, then establishes covert command-and-control over WebRTC DataChannels relayed through TURN infrastructure. This browser-mediated design supports command execution and covert data movement while reducing visibility of attacker-controlled infrastructure. The use of headless browser control, WebRTC tunneling, and legitimate cloud and communications services reflects a strong emphasis on defense evasion and post-compromise operational flexibility. Chaos is believed to have ties to former members of the BlackSuit and Royal ransomware gangs. Reporting also indicates that activity branded as Chaos has at times diverged into distinct operations, and the brand has been abused as false-flag cover by Iran-linked MuddyWater to disguise espionage and data-exfiltration activity as financially motivated ransomware. Separately, Desorden has described itself as composed of former Chaos associates. These overlaps indicate that the Chaos name can refer both to the core ransomware operation and to activity conducted under or adjacent to its brand, so attribution of individual incidents requires care.
PurpleDelta is a designation for a North Korean state-directed network of fraudulent IT workers that uses stolen, borrowed, fabricated, and synthetic identities to obtain remote employment and freelance access at organizations worldwide. The operation is associated with revenue generation for the North Korean regime and also presents espionage and insider-threat risk through access to corporate systems, source code, internal communications, and sensitive data. PurpleDelta operators pose as software developers, contractors, and other technical workers across hiring platforms, professional networking sites, and freelance marketplaces. They maintain multiple fabricated personas simultaneously, including personas supported by AI-generated profile images, falsified employment histories, illicitly sourced identity documents, and deepfake-assisted interview techniques. Operators have used custom AI assistants, real-time transcription, and chatbot tooling during interviews to answer technical questions and improve deception at scale. The group targets remote-friendly employers, especially software and technology firms, staffing and consulting companies, healthcare and biotechnology organizations, and fintech-related employers. Activity has been observed at large scale, including applications to more than a thousand companies by a single cluster and likely successful placement at multiple organizations. Targeting has been concentrated in North America, particularly the United States, but extends globally. Operational tradecraft includes high-volume job applications, multi-account browser environments, separate browser profiles for persona management, tracking spreadsheets, screen recording during interviews, remote access tooling, and coordination over messaging and collaboration platforms. PurpleDelta also relies on facilitators and identity brokers to receive company-issued hardware, maintain devices, provide local presence, lend identities or accounts, and help operators sustain employment. The operation has shown the ability to maintain simultaneous employment at multiple organizations and to rapidly reconstitute by rotating personas and infrastructure. Once embedded, PurpleDelta operators have reportedly recorded internal meetings, coordinated work with other operators in real time, and attempted to justify use of personal devices or financial accounts. This creates risk of unauthorized access, data exfiltration, sanctions exposure, and downstream compromise, particularly where operators obtain privileged technical roles. Recruitment activity has also sought third parties in multiple regions to create freelancer accounts or provide device access in exchange for a share of earnings. PurpleDelta overlaps with other reporting names including Wagemole, Famous Chollima, Jasper Sleet, and UNC5267. Multiple points of intersection have also been observed between PurpleDelta and the North Korean threat cluster tracked as PurpleBravo, indicating broader integration between fraudulent employment schemes and state cyber operations.
Silent Ransom Group is a financially motivated cyber extortion actor known for data-theft-led operations that emphasize social engineering over malware-driven network encryption. The group is widely tracked under the aliases Luna Moth, UNC3753, Chatty Spider, Storm-0252, SRG, and Silent Ransom. Reporting associates the actor with Russia at high confidence. Silent Ransom Group is notable for conducting encryption-less extortion in which stolen data, rather than file locking, is used as the primary leverage against victims. The actor has repeatedly targeted U.S. law firms and other professional-services organizations, with additional targeting noted in insurance-related verticals. Victimology and campaign reporting show a sustained focus on legal-sector organizations, including multiple prominent law firms in the United States. The group has also been linked to broader professional-services targeting and has used infrastructure themed around helpdesk and IT-support impersonation for law-firm brands. Silent Ransom Group commonly gains access through callback phishing, voice phishing, and fake IT-support workflows. Operators impersonate internal IT staff or third-party help desks, persuade targets to contact attacker-controlled support channels, and direct victims to install legitimate remote access and remote monitoring tools. Commercial tools abused in these operations have included Atera, AnyDesk, Syncro, Splashtop, and Zoho Assist. After obtaining access, the group has been observed staging and exfiltrating data and using tools associated with network discovery and file transfer, including SharpShares, SoftPerfect Network Scanner, WinSCP, and Rclone. The actor’s tradecraft has evolved beyond remote social engineering. High-confidence reporting states that Silent Ransom Group operatives have, in some cases, appeared in person while posing as IT technicians, visited victim offices, and connected USB devices directly to target machines. Separate reporting also indicates recruitment of local gig workers to approach victims under a helpdesk pretext and induce USB insertion. These tactics distinguish the group from many extortion actors by blending cyber intrusion with physical-world impersonation and social manipulation. Operationally, Silent Ransom Group is best characterized as an extortion-focused actor rather than a conventional ransomware encryptor. Its campaigns center on theft of sensitive legal and business records followed by pressure to pay in exchange for non-disclosure. The group has been cited as a prominent driver of large extortion payments in 2026, particularly through campaigns against high-profile law firms. Observed behaviors support capabilities in initial access, credential theft or abuse of trusted workflows, reconnaissance, exfiltration, persistence through remote access tooling, and post-exploitation activity oriented toward data collection and coercive extortion.
TheHatman is a cybercriminal seller and intrusion actor associated with the advertising and sale of allegedly stolen internal employee directory data from multiple large enterprises. The actor has been linked to listings for data purportedly taken from Microsoft Azure and Microsoft Entra environments belonging to organizations including McDonald’s, Vodafone, Kyndryl, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels. Reported datasets contained corporate directory and organizational information such as employee names, work email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, reporting structures, group memberships, service accounts, and in some cases accounts with Global Administrator privileges. The actor claims to have obtained the data through compromised credentials and to have downloaded it directly from victim cloud identity environments. Independent reporting assessed sample data as likely authentic and structurally consistent with standard Azure or Entra directory exports, but the precise initial access mechanism has not been conclusively established. Plausible access paths discussed in connection with this activity include use of valid accounts obtained from infostealer infections, theft or abuse of session tokens, phishing, weak or inconsistently enforced multifactor authentication, and abuse of overprivileged third-party integrations or APIs. TheHatman’s activity is notable for monetizing exposed enterprise identity and directory data rather than publicly emphasizing ransomware deployment. The exposed information would support follow-on operations including spear-phishing, executive impersonation, business email compromise, account discovery, privilege escalation targeting, and broader post-compromise mapping of victim environments. Available information supports characterization of TheHatman as a financially motivated cybercriminal actor focused on unauthorized access to cloud-linked enterprise identity data, exfiltration, and underground sale of stolen records.
Evil Corp, also tracked as Indrik Spider, GOLD DRAKE, DEV-0243, Manatee Tempest, and UNC2165, is a Russia-linked cybercriminal group best known for operating Dridex and for later targeted ransomware campaigns including BitPaymer, WastedLocker, and Hades. The group has been active since at least the late 2000s and has been publicly associated with Maksim Yakubets. U.S. government reporting has stated that Yakubets worked for the FSB while the organization also conducted financially motivated intrusions, making Evil Corp a notable example of overlap between Russian cybercrime and state interests. Evil Corp initially gained prominence through large-scale malspam and phishing operations distributing banking malware, especially Dridex, to steal online banking credentials and facilitate fraud. Dridex evolved into a modular platform with capabilities including credential theft, keylogging, browser injection, screenshot capture, peer-to-peer communications, payload delivery, and follow-on ransomware deployment. Reporting has also linked the group to Locky-related activity and to broad malware spam operations. From roughly 2017 onward, Evil Corp increasingly used existing access for targeted enterprise ransomware intrusions. BitPaymer marked the group’s transition from banking malware operations to high-value ransomware attacks, and later campaigns used WastedLocker and Hades against enterprise victims. WastedLocker has been attributed to Evil Corp with high confidence and was used in post-compromise attacks focused on organizations with substantial assets, particularly in North America. Hades has been assessed as a later variant derived from WastedLocker and used in part to distance operations from sanctioned Evil Corp tooling. The group has repeatedly used fake software-update lures as an initial access vector, including browser and plugin update themes delivered through compromised legitimate websites. SocGholish has been closely associated with Evil Corp and Indrik Spider activity and has served as a major initial access and malware delivery framework. In observed intrusion chains, SocGholish profiled victim systems and delivered follow-on tooling such as custom loaders, Cobalt Strike, Dridex, NetSupport RAT, Hades, and WastedLocker. Operationally, Evil Corp has demonstrated capabilities spanning initial access, execution, persistence, credential theft, reconnaissance, lateral movement, defense evasion, and exfiltration. The group has used PowerShell Empire in earlier operations and later shifted toward customized Cobalt Strike tooling. It has used PowerShell and batch scripts for execution, downloaded additional scripts and malware onto compromised hosts, searched files for credentials, abused compromised servers and websites as delivery infrastructure, and moved laterally with both offensive frameworks and legitimate administrative tools. In ransomware intrusions, the group has prioritized critical business systems such as file servers, databases, virtualized environments, and backup-related infrastructure. Victimology shows a strong emphasis on financial institutions during Dridex operations and later a broader enterprise focus including professional services, manufacturing, utilities and energy, technology, pharmaceuticals and life sciences, transportation and logistics, wholesale and retail, and other large organizations. Public reporting indicates most ransomware victims were in North America, especially the United States, with additional victims in Western Europe and the United Kingdom. Evil Corp’s dominant motivation is financial gain. Although the group is primarily a cybercrime actor, public allegations of ties between its leadership and the Russian state distinguish it from purely independent ransomware and banking-trojan operators.
Akira is a ransomware operation that emerged in March 2023 and is widely tracked under aliases including Gold Sahara, Howling Scorpius, Punk Spider, and Storm-1567. It operates as a ransomware and data-theft extortion threat, with affiliate-driven activity consistent with the broader ransomware-as-a-service ecosystem. Akira has targeted organizations worldwide, with especially heavy victimization in the United States and broader North America, and has affected sectors including healthcare, manufacturing, technology, construction, financial services, legal services, education, consulting, agriculture, and other professional services. Akira commonly gains initial access through exposed or unpatched edge infrastructure and stolen credentials, including SSL VPN appliances and enterprise remote-access systems. Reported intrusion paths include exploitation of Cisco ASA/FTD and VMware vCenter vulnerabilities, abuse of Fortinet appliance weaknesses, and access through VPN accounts lacking multifactor authentication. After entry, Akira operators and affiliates conduct reconnaissance and Active Directory enumeration, establish persistence with legitimate remote administration tools, create additional accounts, and move laterally through RDP, SMB administrative shares, WMI, PowerShell, and related administrative mechanisms. The group is notable for extensive use of living-off-the-land and legitimate tools during post-compromise operations, including remote administration software, SSH tooling, archive utilities, file-transfer clients, network scanners, and tunneling utilities. Observed behavior includes credential theft, domain enumeration, file-share collection, staging of data into archives, and exfiltration prior to encryption. Akira has also been observed abusing Safe Mode with Networking to impair endpoint defenses before launching its encryptor, and attempting to disable security tooling, remove shadow copies, delete evidence, and interfere with backup systems such as Veeam. In some incidents, operators leveraged virtual infrastructure in a sophisticated way, including creating virtual machines on compromised VMware environments and extracting Active Directory database material from copied virtual disks to obtain highly privileged credentials. Akira uses double extortion: it steals data before encrypting systems and threatens public release or sale of stolen information through a leak site if victims do not pay. Its leak infrastructure and negotiation portals are central to its coercion model. Ransom demands have ranged from hundreds of thousands of dollars to multimillion-dollar amounts. The malware encrypts files, appends a dedicated extension, drops a ransom note, and uses Windows mechanisms such as the Restart Manager API to close processes and services that would otherwise block encryption. Reporting has also linked Akira activity to affiliate overlap and tradecraft sharing with other ransomware ecosystems, including possible operational intersections involving actors associated with Snatch. Despite such overlap, Akira is consistently tracked as a distinct ransomware brand and one of the most active ransomware groups in 2023 through 2026. Its dominant motivation is financial gain through encryption, data theft, and extortion.
Satanic is a threat actor name associated with alleged data-breach and data-sale activity on underground forums. The actor has been observed claiming unauthorized access to a Saudi-based multinational dairy company and advertising the purportedly stolen database for sale, including claims of live database access. Based on the available reporting, Satanic is best characterized as a data-leak or access-sale actor involved in criminal marketplace activity rather than a well-profiled intrusion set with publicly documented malware, infrastructure, or sustained campaign history. High-confidence public information about the actor’s tooling, operational maturity, victimology beyond the reported Saudi target, or links to a nation-state sponsor is currently not available.
Qilin is a ransomware-as-a-service operation active since at least 2022 and also tracked under aliases including Agenda, Gold Feather, Phantom Mantis, Water Galura, Qiring, and Qiling. It is one of the most active ransomware brands observed in 2026, with sustained high victim volumes across multiple reporting periods and broad international reach spanning at least 25 countries. Qilin operates as an affiliate-based criminal enterprise rather than a single tightly bounded intrusion crew. Its activity is associated with leak-site victim disclosures and data-breach-style extortion, consistent with the broader ransomware ecosystem’s shift toward theft of data and pressure through publication threats in addition to, or instead of, encryption. The group has been described as an established RaaS operation able to maintain scale over multiple quarters. Victimology indicates broad, opportunistic targeting across business services, healthcare, manufacturing, technology, construction, financial services, transportation, education, hospitality, retail, and food-related organizations. Confirmed victim countries in the supplied reporting include the United States, Germany, Italy, Belgium, Canada, Chile, Malaysia, the Philippines, and Trinidad and Tobago, and broader reporting places the United States among the most affected countries in Qilin-linked ransomware activity. Qilin should be assessed primarily as a financially motivated cybercriminal actor. The supplied reporting supports ransomware and extortion operations with leak-site publication and data-theft pressure, but does not provide high-confidence, actor-specific technical detail on initial access, persistence, lateral movement, or other intrusion tradecraft beyond its role as a mature affiliate-driven ransomware operation.
LockBit is a long-running ransomware-as-a-service operation active since 2019 and one of the most prolific leak-site extortion groups of the past several years. It has operated through multiple major versions, notably LockBit 2.0 and LockBit 3.0, the latter also known as LockBit Black, and relies on an affiliate model in which operators provide ransomware tooling and extortion infrastructure to partners. Known aliases and related labels include LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and LockBit affiliates. The group has remained highly active despite law-enforcement disruption, including the 2024 Operation Cronos takedown of its infrastructure, after which it rapidly re-established leak-site operations.
The Gentlemen is a ransomware-as-a-service operation that emerged in mid-2025 and became one of the most active ransomware actors during 2026. Multiple investigations have linked its formation to former Qilin affiliates who split off and established an independent operation. Leaked internal communications indicate a compact core team supported by affiliates, with a revenue-sharing model that delegated many intrusions to partners while the central operators maintained the platform and extortion infrastructure. The group conducts financially motivated double-extortion attacks, combining data theft with system encryption and public leak-site pressure. Its operations have targeted organizations across North America, Europe, Asia, and South America, with especially strong activity reported in the United States and notable prevalence in South America. Reported victim sectors include business services, healthcare, manufacturing, technology, construction, retail, financial services, energy, and professional services. The Gentlemen commonly pursues initial access through internet-exposed SSL VPN appliances, especially Fortinet and FortiGate environments, as well as brute-force activity and the use of stolen credentials obtained from access brokers or credential leaks. Internal chat reporting and incident investigations show follow-on use of Active Directory abuse for privilege escalation, internal reconnaissance, lateral movement, backup discovery and disruption, security-tool interference, data exfiltration, and ransomware deployment. Observed tradecraft includes use of common post-exploitation utilities such as Mimikatz and network-scanning tools, as well as reconnaissance against enterprise services associated with file sharing, databases, and virtualization infrastructure. A documented 2026 intrusion cluster attributed with medium confidence to a suspected affiliate showed extensive operational use of generative AI to support nearly every stage of the attack lifecycle. In those cases, the operator used AI assistance to compromise VPN appliances, capture domain-linked credentials through LDAP pass-back abuse, create covert remote access, enumerate internal networks, identify domain controllers and backup systems, prioritize high-value SQL databases, and stage data for exfiltration. This demonstrates that The Gentlemen ecosystem is capable of integrating AI-assisted tooling into hands-on-keyboard ransomware operations. Leaked Russian-language chats portray a structured criminal enterprise that prioritizes victims based on revenue, sector, geography, and business continuity pressure rather than indiscriminate targeting. The group has shown interest in critical infrastructure and other organizations where operational disruption increases extortion leverage. Available reporting indicates that The Gentlemen relies primarily on established ransomware intrusion paths and operational discipline rather than novel exploitation techniques.
313 Team, also known as Islamic Cyber Resistance in Iraq, is an Iraq-based, pro-Iran hacktivist and resistance-branded disruption actor operating within the broader Iran-aligned cyber proxy ecosystem. The group is associated with coalition-style operations coordinated through Telegram and has been described as an affiliate or participant in the Cyber Islamic Resistance milieu alongside other pro-Iran and opportunistic actors. Its activity is characterized by high-volume, low-to-moderate sophistication disruptive operations, symbolic targeting, propaganda amplification, and coercive messaging rather than advanced intrusion tradecraft. The group is primarily known for distributed denial-of-service operations against public-facing services, especially government portals, major online platforms, and high-visibility symbolic targets. Reported targeting has included government entities in Gulf states, social media platforms, e-commerce services, open-source software infrastructure, and other organizations associated with countries viewed as aligned with the United States or Israel. During the 2026 Iran-related conflict surge, 313 Team was repeatedly identified as one of the most active actors by incident volume and as a central node in coalition campaigns spanning multiple countries. 313 Team has claimed or been linked to disruptive campaigns against Jordanian, Kuwaiti, Emirati, Australian, Israeli-linked, U.S.-linked, and UK-linked targets, as well as attacks affecting Canonical and Ubuntu infrastructure, Bluesky, and eBay. In the Canonical/Ubuntu case, the group paired service disruption with extortion-style demands, threatening continued attacks unless the victim engaged, indicating that its operations can blur from hacktivism into coercive disruption. The actor has also been associated with use of commercial DDoS-for-hire infrastructure, including Beamed, illustrating reliance on outsourced attack capacity to generate outsized operational impact. Tradecraft attributed to 313 Team centers on DDoS, symbolic target selection, public claims of responsibility, Telegram-based propaganda, coalition amplification, and intimidation messaging. Broader reporting also associates the group with defacement, phishing, and data-leak claims, though its most consistently corroborated capability is disruptive DDoS activity. Assessments of the wider ecosystem note frequent exaggeration of impact and the need to distinguish verified outages from propaganda claims. The group’s operational role appears to be sustained nuisance and pressure operations that create visibility, psychological effect, and cumulative disruption during geopolitical crises. Known aliases include Islamic Cyber Resistance in Iraq and Islamic Cyber Resistance. The actor is widely assessed as Iraq-based and aligned with pro-Iranian interests, likely functioning as part of a deniable proxy layer rather than as a top-tier state intrusion unit.
Kimsuky is a North Korean state-sponsored cyber espionage group widely associated with the Reconnaissance General Bureau and tracked under numerous aliases including APT43, Emerald Sleet, Velvet Chollima, Thallium, TA406, TA408, TA427, Black Banshee, Springtail, Sparkling Pisces, and Opal Sleet. The group has been active for more than a decade and is known for sustained intelligence collection operations centered on social engineering, credential theft, malware deployment, and long-term access to victim environments. Kimsuky primarily targets South Korean entities, but has also targeted U.S. and other foreign government-related organizations. Reported victim sectors include government and public policy organizations, think tanks, academia, diplomatic missions, military and security institutions, civil society organizations focused on North Korean issues, security researchers, and virtual asset-related organizations. The group has shown particular interest in individuals and institutions connected to Korean Peninsula policy, North Korean human rights, unification issues, and scientific or engineering research. Its operations commonly begin with spearphishing, including malicious document attachments, ZIP archives containing disguised LNK files, and credential-harvesting lures. More recent reporting also ties Kimsuky to QR-code spearphishing against think tanks, academic institutions, and government entities. Kimsuky frequently uses decoy documents and impersonation themes involving government correspondence, research materials, embassy communications, legal or financial documents, and event-related content to induce execution or credential submission. Kimsuky tradecraft repeatedly features obfuscated PowerShell execution, hidden windows, scheduled-task persistence, abuse of legitimate cloud and web services for payload hosting or command and control, and use of Windows-native utilities such as regsvr32. In Operation GitPower, the group used phishing-delivered LNK files to launch concealed PowerShell loaders, display decoy documents, establish persistence via scheduled tasks, and retrieve additional payloads from GitHub-hosted infrastructure, including AsyncRAT. Reporting also describes broader Kimsuky use of browser credential and cookie theft, PowerShell-based keylogging, system information discovery, and persistent access mechanisms. The group has operated malware families and tooling including AppleSeed and other RAT capabilities, and has conducted multi-stage intrusions involving credential theft, internal access expansion, lateral movement, post-exploitation activity, and data exfiltration. In Operation Newton, Kimsuky reportedly targeted scientific and engineering researchers, stole webmail and VPN credentials, accessed internal networks, deployed Windows and Linux tooling, moved laterally, and exfiltrated research data. Separate reporting has linked Kimsuky-aligned tradecraft to Android malware using Firebase Cloud Messaging for command and control, and to AutoIT-based malware targeting North Korean human rights defenders. Recent reporting indicates Kimsuky is integrating publicly available local AI tooling into its espionage workflow to improve lure generation, document analysis, translation, automation, and handling of stolen information. This appears to represent an evolution in operational efficiency rather than a fundamental change in the group’s core intrusion methods. Kimsuky’s dominant motivation is espionage, with operations focused on political, diplomatic, strategic, and security intelligence collection in support of North Korean state interests.
STAC4749 is a Sophos-tracked cybercriminal activity cluster associated with financially motivated Microsoft Teams voice-phishing campaigns and linked operationally to the Chaos ransomware ecosystem. The cluster was active at least from February through June 2026 and targeted dozens of organizations in North America, with observed targeting concentrated in Canada and the United States. Reported victim sectors included services, manufacturing, energy, construction and engineering, and legal organizations focused on intellectual property services. STAC4749 operators impersonate helpdesk or IT support personnel in Microsoft Teams chats and voice calls, using plausible employee-style identities and IT-themed cloud domains to make their accounts appear legitimate. The objective is to socially engineer users into approving remote support sessions through Microsoft Quick Assist or alternative remote-management tools such as RemSupp. After obtaining remote access, the actors conduct host and security-product discovery, deploy malware through PowerShell, establish persistence, and attempt to expand access within the environment. Observed tooling included a custom loader, a Python-based backdoor, Golang implants, secondary remote-access utilities, and a reverse SOCKS proxy used to communicate with internal systems. The actors attempted to enable Remote Desktop Protocol for lateral movement and used multiple persistence approaches, including Run-key and Startup-folder mechanisms disguised as benign audio or system components. The cluster showed a pattern of rapidly changing filenames, persistence methods, and deployment workflows to evade signature-based detection. In at least one intrusion, the actors also experimented with DLL sideloading. Multiple intrusions attributed to STAC4749 culminated in deployment of Chaos ransomware. Observed ransomware activity included data exfiltration in at least some cases and encryption of victim systems, with one intrusion progressing from initial access to ransomware execution in less than 17 hours. STAC4749 is assessed with high confidence as financially motivated and likely either directly deploying Chaos ransomware or coordinating with affiliates in the Chaos ransomware-as-a-service ecosystem. Limited artifacts have suggested a possible Russian-language connection, but attribution to a specific country or state sponsor remains unconfirmed.
xpl0itrs is a cybercriminal extortion and ransomware threat group active by 2026. Reported victimology links the group to ransomware incidents and associated data breaches affecting organizations in Australia, Germany, and the United States, including retail and e-commerce, manufacturing, and technology targets. In at least one case, the group allegedly published stolen victim data after an extortion attack, indicating use of data-theft-based pressure in addition to ransomware claims. Observed activity attributed to xpl0itrs includes ransomware deployment, extortion, and post-compromise data exposure. The group has been associated with attacks on enterprise victims and with publication of allegedly stolen information, supporting assessment of exfiltration as part of its operations. xpl0itrs has also been described as cooperating with TeamPCP and, by extension, with other criminal actors in adjacent extortion ecosystems. Available reporting does not establish a confirmed national affiliation, malware family lineage, or a broader organizational structure beyond these criminal collaborations. The actor is best characterized as financially motivated and engaged in ransomware-linked extortion operations against private-sector organizations.
Mabna Institute is an Iran-based hacking organization and alleged contractor that has conducted coordinated computer intrusion campaigns since at least 2013. It is widely associated with large-scale credential theft and cyber espionage operations targeting academia, government, private-sector entities, and non-governmental organizations. U.S. authorities have alleged that members of the group operated on behalf of Iran’s Islamic Revolutionary Guard Corps and other Iranian government and university clients, combining state-directed collection with monetization of stolen academic resources. The group is best known for a multi-year campaign against universities worldwide. Its operators reportedly targeted more than 100,000 professor accounts, compromised thousands of academic email accounts, and used stolen credentials to access research, journals, theses, dissertations, electronic books, and other intellectual property. Reported victims included large numbers of universities in the United States and abroad, as well as private companies, U.S. federal and state government agencies, the United Nations, UNICEF, and non-governmental organizations. The operation resulted in the theft and exfiltration of tens of terabytes of academic data and intellectual property. Mabna Institute’s tradecraft has included spearphishing, credential theft, password spraying, unauthorized access to email accounts and online library systems, and data exfiltration. The group has also been linked by U.S. authorities to intrusions against private-sector and government entities beyond academia. Some members were additionally alleged to have participated in the HBO intrusion and attempted extortion operation, indicating overlap between espionage-oriented intrusion activity and financially motivated criminal conduct by individual operators. The organization has also been accused of monetizing stolen academic access by selling or brokering access to compromised university resources for customers in Iran. Known individuals associated by U.S. authorities with Mabna Institute include founders Gholamreza Rafatnejad and Ehsan Mohammadi, along with multiple alleged hackers-for-hire such as Behzad Mesri and others named in U.S. indictments. Overall, Mabna Institute is best characterized as an Iranian intrusion group focused primarily on cyber-enabled theft of academic and commercial information, with strong alleged ties to Iranian state interests.
Lazarus Group is a North Korean state-sponsored threat actor associated with the DPRK’s intelligence apparatus and widely tracked under aliases including Hidden Cobra, Zinc, Diamond Sleet, Labyrinth Chollima, Nickel Academy, TA404, UNC2970, and Guardians of Peace. The cluster encompasses multiple operational lines and subgroups, including financially motivated and espionage-focused activity, and reporting has also linked Famous Chollima as a Lazarus subdivision involved in fraudulent remote IT worker operations. Lazarus has conducted a broad range of operations spanning cyber espionage, disruptive attacks, software supply-chain compromise, cryptocurrency theft, and infrastructure hijacking. The group has targeted government and defense-related entities, financial and cryptocurrency organizations, software developers and open-source ecosystems, security companies, and South Korean entities. Reported activity includes industrial espionage against an Israeli security company, spearphishing campaigns using malicious Microsoft Word documents, and abuse of trusted or compromised web infrastructure, including repurposed WordPress-based sites for phishing or command-and-control. The group is known for developing and deploying custom malware families and loaders across Windows, macOS, and Linux environments. Observed tradecraft includes host and user discovery, process enumeration, collection of system information, downloading and executing additional payloads, use of encoded command-and-control traffic including Base64, keylogging in some malware families, and signed-binary proxy execution through tools such as mshta and regsvr32. Lazarus-linked malware has also demonstrated remote shell execution, process injection, and other post-exploitation capabilities. In more recent reporting, Lazarus was attributed to an npm supply-chain intrusion involving poisoned package versions that delivered a cross-platform remote access trojan linked to WAVESHAPER. Financial gain is a major operational objective for Lazarus alongside state-directed intelligence collection. The group has been repeatedly associated with theft from financial institutions and cryptocurrency platforms, and with DPRK revenue-generation schemes. Separate Lazarus-linked activity has also been tied to fraudulent employment operations in which suspected North Korean operators sought remote developer roles, conducted host reconnaissance on employer-provided systems, and exposed indicators consistent with later data theft or malware deployment.
Play, also known as PlayCrypt and tracked by Symantec as Balloonfly, is a ransomware operation first observed in June 2022. It is described as a ransomware-as-a-service operation and is known for double-extortion attacks that combine data theft with encryption and threats to publish stolen information on a leak site. The group has also been associated with intermittent or partial encryption, a technique that accelerates impact while potentially reducing some forms of static detection. Play has targeted organizations across North America and Europe and has been repeatedly linked to attacks against U.S.-based victims. Reported victim sectors include technology, financial services, retail, healthcare, education, professional services, information technology manufacturing, managed service providers, and government entities. Early reporting also noted a focus on Latin America, especially Brazil, before the group broadened its targeting. The group has demonstrated strong capability in exploiting public-facing systems for initial access, including Microsoft Exchange vulnerabilities such as CVE-2022-41080 and CVE-2022-41082 and Citrix Bleed (CVE-2023-4966). Intrusions have also involved access through valid VPN credentials. After compromise, Play operators have conducted extensive internal reconnaissance, including enumeration of users, computers, domain accounts, trusted domains, permission groups, remote systems, installed software, backup tools, remote administration tools, and security products. Play uses custom tooling to support post-compromise operations. A notable example is Grixba, a .NET tool used for network scanning, software and service discovery, security software discovery, and collection of environment data for later exfiltration. Grixba has also been used to clear logs on local and remote systems, indicating deliberate defense evasion. Another observed tool leverages Volume Shadow Copy Service snapshots to copy files that are normally locked by the operating system prior to encryption. Reporting has also linked Play intrusions to remote access and administration tooling, including SystemBC in related cases. Observed operator tradecraft includes manual deployment over RDP, remote execution via PsExec, use of PowerShell, DNS-based command-and-control-related behaviors in ATT&CK mappings, and rapid hands-on-keyboard execution that can move from access to widespread encryption within a single day. The group has published stolen victim data on its leak site when extortion demands were not met. Some reporting suggests affiliate variation within the operation, including a suspected affiliate cluster active in Europe.
ShinyHunters is a financially motivated cybercriminal data-theft and extortion group active since at least 2020 and widely associated with large-scale breaches, stolen-data sales, and leak-site extortion. The group is also referenced alongside aliases and cluster names including ShinyHunter, Shiny Hunters, UNC6040, UNC6240, and Bling Libra. It has been linked to activity overlapping with broader socially engineered intrusion ecosystems and has been described in some reporting as operating within a loose collective associated with Scattered Spider and LAPSUS$-style tradecraft, although such relationships are not consistently established across all incidents. ShinyHunters primarily targets organizations holding large volumes of customer, donor, or business data, with repeated victimology in technology and cloud-service ecosystems, telecommunications, financial and consumer platforms, higher education, and healthcare. Reported victims and claimed victims include SaaS and communications providers, universities, logistics and fulfillment providers, analytics platforms, and organizations exposed through third-party service relationships. The group is best known for data-theft-first operations rather than disruptive encryption-centric ransomware. Its operations commonly involve social engineering to obtain initial access, followed by credential theft, session abuse, access to SaaS or internal platforms, bulk collection of sensitive records, and extortion backed by threatened or actual publication on a leak site. In multiple reported incidents, ShinyHunters claimed or was linked to sophisticated social-engineering campaigns, including voice phishing against employees, impersonation of IT or support personnel, real-time credential capture, MFA bypass through push approval or one-time-code theft, and hijacking of active sessions. The actor has also been associated with gathering personally identifiable information from database infrastructure and with abuse of exposed or weakly protected cloud and enterprise data environments. Extortion is a defining feature of ShinyHunters operations. The group has repeatedly issued pay-or-leak demands, set deadlines for victims, and published stolen data when demands were not met. Reporting ties the actor to a dedicated leak site and to encryption-less data-theft extortion, with some incidents explicitly framed as ransomware-related by victims or observers even when the core pressure mechanism was data exposure rather than widespread file encryption. ShinyHunters has also been linked in reporting to broader campaigns affecting customers of major cloud and enterprise platforms, including Salesforce- and Snowflake-related victim clusters, and to incidents involving third-party compromise chains. Some claims around specific victim counts, collective affiliations, or individual incident attribution remain contested or unconfirmed by victims, so only the recurring pattern is high confidence: ShinyHunters is a prominent cybercriminal extortion actor specializing in large-scale theft of sensitive data, social-engineering-enabled access, and public leak pressure to monetize intrusions.