Cyclops is a ransomware-as-a-service operation associated with the Cyclops ransomware family. In 2023, its operators introduced a substantially updated variant known as Ransom Knight, described as a rewrite from scratch and offered to affiliates as part of the service. Reporting also indicates the service integrated a custom information stealer into the attack kit provided to affiliates, reflecting a broader trend toward multifunctional ransomware tooling. Cyclops operates in the RaaS model, with separate affiliates conducting intrusions and deploying payloads. Activity linked to QakBot affiliates indicates Cyclops/Ransom Knight has been used in phishing-led campaigns delivering ransomware alongside remote-access tooling to preserve attacker access. Observed tradecraft in those affiliate operations included malicious archive attachments, shortcut-based download chains, script execution, and use of a backdoor for persistence and post-compromise access. Cyclops should be understood primarily as a financially motivated cybercriminal service rather than a state-sponsored actor. Its known role is as a ransomware platform rented to affiliates, enabling initial access obtained by other actors to be monetized through ransomware deployment. Available information directly supports its operation as a RaaS program, but does not provide high-confidence attribution to a specific country or a well-defined victim geography beyond limited indications from affiliate campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the ransomware-as-a-service behind the updated Ransom Knight variant used by Qakbot affiliates; the content says Qakbot actors are customers rather than the operators of this service.
RaaS program referenced as bundling a custom infostealer into the affiliate kit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.