Hyflock is a ransomware-as-a-service (RaaS) operation that emerged in 2026 and operates through Tor-based infrastructure. Its platform supports the full affiliate ransomware workflow, including affiliate registration and authentication, a payload builder for customized ransomware builds, victim-specific negotiation rooms, payment tracking, and a public data-leak site. The operation uses separate affiliate and victim portals; negotiations include operator approval of victim counteroffers, indicating centralized control over affiliate deal-making. The platform supports Bitcoin, Zcash, and Monero payments and presents Russian-language interface elements, while exposed developer documentation contained Simplified Chinese comments. Hyflock’s ransomware is written in Rust. Reported functionality includes prioritizing database files, enumerating network shares, propagating through Windows domains by using Group Policy, deleting shadow copies, disabling Microsoft Defender, interrupting cloud-sync services, and removing execution traces. The operation’s leak-site functionality supports publication of stolen-data previews and categorized file listings, consistent with data-theft-enabled ransomware extortion. Hyflock has also marketed an LLM-driven command-and-control platform, but the advertised autonomous intrusion and post-compromise capabilities have not been independently validated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation marketing a Rust encryptor together with a large-language-model-driven C2 platform intended to automate and orchestrate compromise activity for less-skilled affiliates. The AI-agent capabilities are operator claims and remain unconfirmed by buyers according to the content.
A newly launched ransomware-as-a-service program recruiting affiliates on Duty-Free. It claims former LockBit and Qilin experience and advertises an all-in-one panel with integrated access-broker purchasing, automated negotiation rooms, automated revenue sharing, AI-driven victim analysis, red-team support, GPO deployment, and cloud-backup file encryption.
Competitor RaaS program mentioned in passing.
Mentioned only as a dismissed candidate ransomware program.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.