Titan is a ransomware threat actor active by at least Q2 2026 and observed conducting victim-naming and extortion operations across multiple countries. Reported victims attributed to Titan include organizations in Italy, the Czech Republic, India, South Korea, Sri Lanka, and the United States, spanning construction, healthcare, manufacturing, business services, technology, transportation and logistics, and food-related sectors. Italy appears prominently in observed victim reporting, with multiple Italian organizations claimed in a concentrated period, and Titan was also listed among active ransomware groups in broader 2026 tracking. Titan has been associated with ransomware incidents described as data breaches, indicating extortion activity tied to unauthorized access and theft of victim data. Publicly attributed victim cases show a geographically diverse targeting pattern rather than a single-country focus. High-confidence reporting places the group among emerging or mid-tier ransomware actors seen alongside larger operations during 2026. No reliable attribution to a specific state sponsor or country of origin is established from the available facts. Known reporting identifies the actor under the name Titan. Based on confirmed victim attributions, Titan should be characterized as a financially motivated ransomware operator engaged in intrusion, data theft, and extortion against organizations in multiple sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group newly appearing in this week's top 10 with 9 claimed attacks.
Conducting a ransomware attack against Termotecnica Industriale S.r.l.
Conducting a ransomware attack against CTP S.r.l.
Conducting a ransomware attack against Tedesco & Partners STP srl.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.