Kuiper is a ransomware-as-a-service operation first observed in September 2023. It has been advertised on Russian-language cybercrime forums and has been associated with the moniker RobinHood, an actor involved in both selling corporate network access and operating the Kuiper RaaS program. Affiliates were reportedly offered a high revenue share along with support for data exfiltration and cryptocurrency laundering services, indicating an organized affiliate model rather than a single-operator campaign. Kuiper is a cross-platform ransomware family written in Go and designed to target Windows, Linux, and macOS systems, with reporting also indicating support for ESXi, NAS, and FreeBSD environments in its broader RaaS positioning. Its encryption scheme uses asymmetric and symmetric cryptography, including RSA-4096 together with AES or ChaCha20. Windows-focused functionality includes attempts to disable backup mechanisms and terminate processes that could interfere with encryption or incident response. Operational evidence links Kuiper to exploitation of Microsoft Exchange ProxyLogon vulnerabilities, followed by deployment of Cobalt Strike for access maintenance and post-compromise activity. Recovered source code also showed early self-propagation capability over SMB within local subnets using remote execution via Windows management tooling. Observed infrastructure and logs indicate infections across multiple countries. Although the operators publicly claimed to prohibit targeting Commonwealth of Independent States entities, infections were also observed from Russian IP space, suggesting either weak enforcement of affiliate rules or opportunistic compromise prior to victim vetting. Kuiper has been tied to exfiltration activity and appears to support extortion beyond file encryption. At the time it was documented, the operation claimed a leak site was prepared but not yet publicly active. Known targeting evidence includes financial-sector entities and at least one African government financial department. Overall, Kuiper is best characterized as a financially motivated cybercriminal ransomware enterprise with initial access, post-exploitation, lateral movement, encryption, and data-theft capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS program operated by RobinHood while also brokering access; targets multiple platforms including Windows, Linux, ESXi, NAS, macOS, and FreeBSD.
Ransomware-as-a-Service operators developing and operating Kuiper ransomware, with evidence of their own infrastructure, exfiltrated data, decryption keys, and control tooling. The group appears to target organizations including the financial sector and at least one African government financial department, and uses exploitation plus post-exploitation tooling before deploying ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.