KillSec is a ransomware and extortion threat actor that evolved from an Anonymous-aligned hacktivist identity into a financially motivated operation. By 2025 it was described as a hybrid actor blending hacktivist branding with cybercriminal monetization, and it has also been associated with offering affiliates ransomware-as-a-service capabilities alongside DDoS and data-stealer tooling. KillSec has been observed targeting organizations across multiple countries and sectors, with repeated victimization of healthcare entities and healthcare-related businesses. Reported victims and targeting references place its activity in India, the United States, Mexico, Peru, Brazil, South Korea, and Ireland. Healthcare is a particularly prominent focus, including hospitals, clinics, IVF providers, and other healthcare institutions, while additional observed targeting includes financial services, transportation, and other commercial organizations. Operationally, KillSec is associated with ransomware attacks accompanied by data theft and public victim listing, indicating extortion through both encryption and leak-site pressure. Reporting on individual incidents repeatedly characterizes its operations as ransomware-linked data breaches, and broader ransomware landscape reporting places KillSec among active healthcare-targeting groups and among the more common strains affecting healthcare businesses in 2025. The group has also been described as using AI-driven tools, and as part of the broader trend in which hacktivist, criminal, and potentially state-aligned narratives can overlap, complicating attribution and intent assessment. Known aliases include killsec, killsec_(killsec3), and killsec_ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Global Go, a transportation-sector organization in Peru.
Conducting a ransomware attack resulting in a data breach against Origins IVF.
Named as the group responsible for a ransomware attack against Bulwark Exterminating.
Conducting a ransomware attack resulting in a data breach against cashcowboy.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.