Punisher is a small, short-lived ransomware or extortion crew identified as part of the broader fragmentation of the ransomware ecosystem. It has been cited alongside groups such as Termite, The Gentlemen, and Obscura as an example of newer crews operating with lower visibility than earlier large cartel-style brands. Available reporting supports only limited attribution and operational detail. No high-confidence public evidence in the supplied material establishes Punisher’s country of origin, specific victim geography, sector focus, or distinctive tradecraft beyond its placement within the contemporary ransomware landscape. The group’s mention in the context of ecosystem splintering and increasing brand confusion indicates it should be treated cautiously for attribution purposes until further corroborated intelligence is available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.