KillSec is a ransomware and extortion threat actor that evolved from an Anonymous-aligned hacktivist identity into a financially motivated operation. It is commonly tracked as KillSec and has also been referred to as KillSec ransomware. Reporting places it in the broader trend of hybrid actors that blend hacktivist branding, criminal monetization, and affiliate-style ransomware activity. KillSec has been associated with attacks across multiple regions and sectors, including healthcare, financial services, and other commercial organizations. Healthcare appears to be a recurring target set, with activity noted against providers and healthcare-related businesses in multiple countries, including Brazil, India, Ireland, Mexico, South Korea, and the United States. It has also been observed targeting non-healthcare organizations such as exhibition-management and industrial entities. The group is assessed to operate as a ransomware-as-a-service or affiliate-enabled extortion actor. It has been described as offering additional capabilities to affiliates, including distributed denial-of-service support and data-stealer tooling, indicating a broader extortion toolkit beyond file encryption alone. Its operations are consistent with modern double-extortion ransomware tradecraft, in which data theft and public leak pressure accompany disruptive attacks. KillSec is notable less for uniquely advanced malware engineering than for its adaptability and positioning within a fragmented ransomware ecosystem. It has been cited alongside other active ransomware groups targeting healthcare and has ranked among the more common strains affecting healthcare-related businesses during 2025. Some reporting also characterizes KillSec as part of a growing class of actors using AI-driven tools, further complicating attribution and operational analysis. No high-confidence public attribution links KillSec to a specific state, although its origins in hacktivist branding and later transition to profit-driven ransomware reflect the increasingly blurred boundaries between ideological, opportunistic, and criminal cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Origins IVF.
Named as the group responsible for a ransomware attack against Bulwark Exterminating.
Conducting a ransomware attack resulting in a data breach against cashcowboy.
Conducting a ransomware attack against a healthcare organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.