J is a cybercriminal extortion actor that emerged in 2025 as part of the broader shift toward exfiltration-led ransomware and leak-site operations. The group is notable for relying on data theft and leak-based extortion without consistently deploying a ransomware locker, and is therefore better characterized by victimology and extortion behavior than by a stable, well-defined malware family. Reporting indicates that J has at times functioned primarily as a leak-site identity rather than a durable technical cluster. J is associated with extortion-only operations in which stolen data is used as the primary coercive mechanism. This places the actor within the growing set of groups that prioritize exfiltration over encryption and publicize victims through leak infrastructure. A malware strain referred to as J-Ransom has also been linked to the actor, indicating at least some association with ransomware tooling, but the actor’s defining operational pattern is data-theft extortion rather than consistent locker deployment. Available information does not support high-confidence attribution to a specific country of origin, nor does it establish a reliable set of targeted countries or industry verticals for J. The actor’s known behavior is most consistent with financially motivated cybercrime focused on extortion through stolen-data exposure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Poorly-defined ransomware actor/label; may function more as a leak-site identity/brand or reused label rather than a stable, well-documented single group.
'J' is a ransomware actor or group that, in 2025, focused on data theft and extortion via public leaks, without using ransomware encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.