Keeling is a financially motivated ransomware actor associated with ransomware-as-a-service activity and affiliate-driven operations. The group has been observed targeting organizations where downtime and regulatory pressure can increase the likelihood of payment, including financial institutions, healthcare organizations, legal firms, and managed service providers. Reported intrusion patterns include exploitation of older, unpatched Fortinet vulnerabilities, particularly in smaller environments and MSP-managed networks. Keeling is associated with modern ransomware tradecraft that emphasizes stealth, business-impact-driven victim selection, and layered extortion. Its operations align with broader high-value ransomware campaigns that prioritize data theft and exfiltration alongside encryption, and may apply double- or triple-extortion pressure through leak-site operations and outreach intended to intensify negotiations. The actor is also described within the ransomware-as-a-service ecosystem as using affiliate and revenue-sharing models. Observed behaviors associated with Keeling-class operations include reconnaissance, stealthy lateral movement, abuse of legitimate administrative tools, persistence through overlapping backdoors, and defense evasion techniques designed to impair security tooling. Reported methods used in comparable operations include safe mode encryption, telemetry suppression, and BYOVD to tamper with endpoint protections. The actor’s operational model reflects the broader industrialization of ransomware, with longer dwell times, multi-stage intrusion activity, and post-compromise actions focused on maximizing extortion leverage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keeling is a ransomware group whose affiliates exploit unpatched Fortinet vulnerabilities, especially in smaller IT environments and MSP-managed networks.
Keeling is a ransomware group known for targeting high-value environments such as financial institutions, healthcare, legal firms, and managed service providers. They employ strategic, business-driven extortion models, focusing on fewer but more lucrative victims, and utilize data theft and multi-layer extortion tactics.
Keeling is a ransomware group known for targeting high-value environments such as financial institutions, healthcare, legal firms, and managed service providers. They employ strategic, business-driven extortion models, focusing on fewer but more lucrative victims, and utilize data theft and multi-layer extortion tactics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.