Skira, also referred to as Skira Team, is a ransomware threat actor first observed as a new entrant in the 2024 ransomware ecosystem and later tracked among emerging groups active into 2025. Public reporting places it among the wave of newly emerged ransomware brands that contributed to the fragmentation and rapid turnover of the extortion landscape. High-confidence information on Skira remains limited. The group has been identified in ransomware victim-claim tracking and in monitoring of emerging ransomware actors affecting industrial organizations. Available reporting supports classifying Skira as a ransomware/extortion actor, but does not provide sufficient corroborated detail on its malware family design, intrusion playbook, access vectors, affiliate structure, or whether it operates as a standalone crew or a ransomware-as-a-service program. Specific technical behaviors such as credential theft, lateral movement, persistence, or defense evasion are not established at high confidence from the available facts. Known aliases include Skira Team. Publicly attributed victim claims indicate activity against organizations in sectors including real estate-related services, legal services, information technology services, consumer products, and local government. The actor should be treated as an emerging ransomware cluster with sparse confirmed attribution and limited publicly corroborated TTP reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in March 2024.
Emerging ransomware group listed as active in Q1 2025 targeting industrial sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.