Knight
Knight is a ransomware-as-a-service (RaaS) operation referenced in the provided content as an active ransomware brand present by at least 2023. It is listed as “Knight 3.0” on the RAMP cybercrime forum in May 2023 with a 90/10 affiliate/operator split, indicating an affiliate-based business model. Dragos observed Knight for the first time in Q4 2023, where it accounted for 1.9% of incidents in the cited reporting. Knight is also mentioned in infrastructure and malware-overlap analysis involving 8Base: malware hashes tied to 8Base infrastructure were also observed on onion sites associated with ALPHV, BianLian, Knight, and Play, and extracted malware strings explicitly referenced onion URLs and communication channels associated with those brands, including Knight. This supports the conclusion in the source material that Knight participated in a shared-backend ransomware ecosystem rather than being fully isolated from other ransomware brands. The content also states that RansomHub has significant code overlaps with the former Knight ransomware group, further linking Knight to later ransomware development lineage. No additional aliases or sub-groups beyond “Knight” are directly provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware operation sharing malware-hash overlap with infrastructure associated with 8Base, indicating possible common tooling or shared backend ecosystem.
RaaS program advertised on RAMP with a 90/10 affiliate/operator split, reflecting aggressive competition for affiliates.
Referenced as part of the cluster of ransomware operations sharing malware hashes with 8Base-associated infrastructure, consistent with a shared extortion ecosystem.
Referenced as a former ransomware group linked to RansomHub via code overlap; no additional details provided.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.