Desolator is a ransomware operation first observed in August 2024. It is one of the newer ransomware groups that emerged during the 2024 surge in new extortion actors and has been publicly associated with naming victims on a leak site. Available reporting supports classifying Desolator as a ransomware and extortion threat actor, but little corroborated detail is presently available about its operators, malware lineage, geographic origin, tooling, intrusion methods, or victimology beyond a small number of publicly claimed victims. Based on the confirmed activity, Desolator should be tracked as a distinct ransomware brand with extortion-oriented operations involving public victim disclosure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in August 2024.
Desolator is a new ransomware group conducting attacks and leaking victim data on the dark web.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.