SevyWare is a ransomware threat actor that emerged publicly by mid-2026. It is associated with a ransomware leak site, indicating participation in extortion-oriented operations, but publicly available corroborated detail on its tooling, victimology, operational tempo, and tradecraft remains limited. Reporting has noted the appearance of a law-enforcement seizure banner on SevyWare’s leak infrastructure, although no official confirmation of such a seizure was available at the time, so that status remains unverified. SevyWare has also been identified among newly emerged ransomware groups during the 2026 threat landscape, but high-confidence attribution to a specific country, targeting pattern, or distinctive technical capability is currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Its ransomware leak site displayed an apparent law-enforcement seizure banner, though the report notes this was unconfirmed by official statement.
Newly emerged ransomware/extortion group noted in June 2026.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.