Knight, also referred to in some reporting as Cyclops, is a ransomware-as-a-service operation active by 2023 that has been associated with a broader shared ransomware ecosystem rather than a clearly isolated standalone cluster. It has appeared in leak-site tracking and underground forum advertising, including promotion of a "Knight 3.0" program with a 90/10 affiliate-operator revenue split, indicating a mature affiliate model. Knight is notable for significant code overlap reported with other ransomware operations, especially RansomHub, and for technical artifacts observed alongside infrastructure associated with ALPHV, BianLian, Play, and 8Base. Reporting has described shared code, similar help-menu structures, and a distinctive string-obfuscation approach between Knight and RansomHub, complicating attribution and suggesting either code sharing, developer overlap, or common backend/tooling. Separate infrastructure analysis tied malware associated with multiple branded leak sites to common technical artifacts, reinforcing the assessment that Knight participated in a multi-brand ransomware ecosystem. Operationally, Knight is linked to extortion-oriented ransomware tradecraft that includes encryption and data-theft pressure via leak-site publication. Embedded malware strings observed in related shared tooling referenced exfiltration workflows, staged disclosure, proof-of-compromise materials, and media-pressure mechanisms, consistent with modern double-extortion operations. Knight has also been discussed in the context of successor and rebrand analysis involving post-ALPHV ransomware activity, although definitive attribution of such lineage remains unproven. Knight has been tracked among active ransomware groups affecting organizations across multiple sectors and geographies, but the available evidence here does not support a high-confidence country-of-origin attribution or a precise victim-country profile specific to Knight alone.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware operation sharing malware-hash overlap with infrastructure associated with 8Base, indicating possible common tooling or shared backend ecosystem.
RaaS program advertised on RAMP with a 90/10 affiliate/operator split, reflecting aggressive competition for affiliates.
Referenced as part of the cluster of ransomware operations sharing malware hashes with 8Base-associated infrastructure, consistent with a shared extortion ecosystem.
Referenced as a former ransomware group linked to RansomHub via code overlap; no additional details provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.