Kill Security is a ransomware and extortion threat actor that emerged in late 2024 and became operationally visible at scale in 2025. It is tracked as one of the more active newer entrants in the 2025 ransomware ecosystem and has been identified among major groups appearing in dedicated leak site reporting and ransomware trend analyses. The actor is associated with victim listing activity on leak infrastructure and is assessed to participate in the broader ransomware economy rather than isolated opportunistic intrusion. Available reporting places Kill Security among groups active during a period when many ransomware operations shifted toward exfiltration-first coercion and public disclosure pressure, although direct evidence tying this actor specifically to encryption, double extortion, or triple extortion tactics is not established at high confidence from the available facts. Known victim reporting links Kill Security to activity affecting organizations in South Korea, including a university application platform. Broader trend references also associate the group with substantial victim volume in India. Kill Security has been discussed alongside other contemporary ransomware actors such as Qilin and INC RANSOM as part of the expanding and fragmented 2025 threat landscape. High-confidence attribution to a specific country of origin, state sponsorship, or a distinct sub-group structure is not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer extortion/ransomware actor that became visible at scale in 2025 via DLS claims.
Ransomware group with a focus on India, promoting RaaS and maintaining steady attack volume.
Kill Security is identified as a major ransomware group active in September 2025.
Ransomware operations claiming new victims; specifically lists a South Korean university application platform as a victim.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.