Silent Ransom Group Leaks Reveal Physical Infiltration Plans and Extortion Money Flows
Purported SRG chats reveal discussions of kidnapping executives and threatening families
What ransomware crews are doing right now — the groups picking up momentum, the breaches they're posting, and the stories tracking their operations. Aggregated from vendor reports, leak sites, researcher analysis, and underground chatter.
Actors ranked by Mallory's mention-velocity model across sources.
Qilin, formerly known as Agenda and also tracked as GOLD FEATHER, Phantom Mantis, and Water Galura, is a financially motivated ransomware-as-a-service operation active since 2022. Its operators provide ransomware, affiliate infrastructure, and negotiation services in exchange for a share of ransom proceeds. Qilin conducts double extortion by stealing sensitive information, encrypting systems, and threatening publication through a Tor-based leak site. Its victims span healthcare, manufacturing, professional services, technology, financial services, retail, transportation, media, and government organizations worldwide. The June 2024 attack against pathology provider Synnovis significantly disrupted NHS hospital services in London. Qilin evolved from Go-based Agenda ransomware into Rust-based payloads, with variants targeting Windows, Linux, and VMware ESXi environments. Affiliates obtain initial access through phishing, compromised remote-access credentials, brute-force attacks against VPN services, and exploitation of internet-facing appliances. Documented exploitation includes Fortinet vulnerabilities and CVE-2023-27532 in Veeam Backup & Replication, which enables theft of stored credentials and subsequent compromise of backup infrastructure. Post-compromise activity includes browser credential theft, privileged token impersonation, Active Directory discovery, and lateral movement using legitimate administrative tools. The ransomware supports propagation through PsExec and VMware vCenter. Qilin attacks systematically undermine recovery by deleting shadow copies, disabling backup jobs, and compromising online backup systems. Defense-evasion techniques include clearing event logs, stopping security services, and deploying Killer Ultra, an endpoint-defense impairment tool that abuses a vulnerable Zemana driver through CVE-2024-1853. Scheduled tasks and legitimate remote-administration software support persistence and continued access. Affiliates exfiltrate data using tools such as Rclone, WinSCP, and FileZilla. Qilin's ransomware supports configurable, multithreaded and intermittent encryption, using AES-256-CTR or ChaCha20 with RSA-4096 protection for encryption material.
ShinyHunters, also known as BLING LIBRA, ShinyHunter and Shiny_Hunters, is a financially motivated cybercriminal data-theft and extortion group active since at least 2020. It operates as a persistent criminal brand with changing membership rather than a fixed organization. Its targets include software-as-a-service providers, cloud-platform customers, government agencies, healthcare organizations, telecommunications companies, retailers and other enterprises. The group obtains initial access through phishing, social engineering and compromised credentials. Its social-engineering techniques include impersonating IT support personnel to obtain access to corporate identity systems such as Okta. ShinyHunters compromises corporate SaaS accounts and cloud data environments, particularly accounts lacking multifactor authentication, and abuses legitimate OAuth mechanisms to extract information while blending into ordinary application traffic. Its operations have also exploited unpatched enterprise systems. Significant activity includes data theft and extortion affecting Snowflake customer environments and the theft of sensitive personnel information from the FBI's third-party-managed recruitment platform in 2026. ShinyHunters primarily monetizes stolen information through encryption-less extortion, threatening publication unless victims pay. It uses a public leak site, victim listings and payment deadlines to pressure organizations, and has published stolen datasets. The group has also distributed valuable stolen databases through cybercriminal forums such as Raid Forums. International law-enforcement arrests and infrastructure disruptions have affected its operations, but the ShinyHunters brand has persisted through membership changes.
The Gentlemen, also known as The Gentleman, Gentlemen, and Storm-2697, is a financially motivated, Russian-speaking ransomware-as-a-service operation first publicly observed in September 2025. It emerged from Qilin’s affiliate programme through the breakaway affiliate ArmCorp. Its affiliate model offers a 90 percent share of ransom proceeds and combines centrally supplied access, encryption, propagation, and endpoint-security disruption capabilities with affiliate-selected intrusion tools. Manufacturing is its most consistently targeted sector, alongside healthcare, government, education, technology, retail, and financial services. Its targeting is international and opportunistic, with the United States representing its largest reported victim population. Initial access includes exploitation of vulnerable perimeter devices, particularly Fortinet FortiGate appliances, exploitation of CVE-2024-55591, stolen or purchased VPN credentials, phishing, and access obtained from initial-access brokers. The operation maintains a shared pool of compromised FortiGate devices and validated VPN credentials for affiliates. Intrusions involve credential dumping, browser credential extraction, LDAP enumeration, legitimate administrative utilities, and SOCKS tunnels. Associated tools include Mimikatz, a modified Velociraptor deployment, and the G-BOT command-and-control framework. The Gentlemen conducts double extortion by stealing sensitive information before encrypting systems and publishing victim information through a leak site. Data collection spans network shares, servers, business applications, and cloud-connected environments, with transfers using tools such as Rclone and WinSCP. Its ransomware uses XChaCha20 and Curve25519 and propagates through Active Directory environments using WMI, PowerShell, PsExec, and Group Policy Objects. Attack workflows disable endpoint defenses, establish scheduled-task persistence, and stop virtual machines, databases, backup services, and containers to impede recovery and increase disruption. Affiliate activity includes deployment of EtherRAT through living-off-the-land techniques, scheduled tasks, and MSI packages for persistence, credential theft, privilege escalation, and lateral movement. The affiliate Azazel abused Model Context Protocol execution interfaces in an AI coding assistant as a command-and-control channel. His intrusions harvested secrets from GitLab CI/CD variables and repository history and involved substantial data exfiltration. Azazel also operated the independent LEAKNED leak and extortion service rather than sharing all proceeds with the central operation. No direct state tasking or control has been established for The Gentlemen.
Arcus Media, also tracked as arcusmedia and arcus_media, is a financially motivated ransomware and extortion group. It publishes victim claims on a dedicated leak site and associates victim listings with deadlines, using public disclosure as part of its extortion activity. Its claimed victims span the Americas, Europe, Africa, and Southeast Asia, with repeated targeting of organizations in Brazil, Canada, and the United States. The group targets multiple sectors, including manufacturing, transportation and logistics, information technology, consumer services, agriculture and food production, healthcare, government, and water-supply services. Named targets include Ladrillera Mecanizada, Pantaneiro Capas, Schneider’s Computing, COREBI (NowVertical), AGROFRUTO SAC, Distribox, and Malaysia’s Malacca Public Library Corporation. Its activity includes industrial and critical-infrastructure targets but is not confined to those sectors. Documented technical behavior includes harvesting browser-stored credentials. Victim listings establish the group's public claims rather than independently confirming every compromise; they do not consistently establish initial-access methods, ransomware variants, encryption scope, or the extent of stolen data.
Rhysida is a financially motivated ransomware-as-a-service operation that emerged in May 2023. Also known as the Rhysida ransomware group or Rhysida ransomware gang, it operates through actors and affiliates using the Rhysida brand. Its victims span healthcare, government, education, manufacturing, technology, professional services, and other sectors. Rhysida combines file encryption with data theft and threats of public disclosure, maintains a dedicated leak site, and also conducts data-theft extortion without confirmed encryption. Observed initial-access methods include phishing, compromised VPN accounts lacking multifactor authentication, purchased VPN and RDP access, and SEO poisoning that directs users to trojanized software downloads. Rhysida actors have also exploited Zerologon, CVE-2020-1472. Intrusions have involved establishing persistence, enumerating networks with Advanced Port Scanner, moving laterally through RDP, and using AzCopy to exfiltrate data to attacker-controlled Azure storage. Before ransomware deployment, operators have attempted to disable security software, terminate application and backup services, manipulate local accounts, enable remote administration, delete backups and volume shadow copies, disable recovery, and clear event logs and PowerShell history. Notable incidents include the December 2023 attack against Insomniac Games, which exposed game-development material, and the August 2026 theft of data from two Berlin Senate administrations. Berlin refused the ransom demand, after which Rhysida published the stolen material. Rhysida's encryption implementation contained a random-number-generation weakness that enabled a free decryptor for affected earlier variants; this does not establish decryptor coverage for newer variants. Its country of origin and any state sponsorship are not established.
SafePay is a ransomware and extortion group also referred to as the SafePay ransomware gang, SafePay ransomware group, SafePay ransomware actors, and SafePay team. It operates a dedicated leak site and has posted healthcare organizations as victims. Its reported targeting spans Europe, the Americas, and other regions, with Germany and the United States featuring prominently. Reported victims include technology providers, construction and infrastructure businesses, architectural and professional-services firms, manufacturers, retailers, hospitality businesses, agricultural enterprises, healthcare institutions, and municipal government organizations. Its victim disclosures demonstrate broad cross-sector targeting rather than a narrowly defined industry focus. No established country of origin, state affiliation, or named subgroup is identified.
DeadLock is a financially motivated ransomware operation first observed in July 2025. It conducts double extortion by encrypting victim systems and threatening to publish exfiltrated data through the DeadLock blog. Its victims span Europe, Asia, North America, South America, and Africa, with a substantial concentration in Europe. Targeted sectors include information technology, mining, manufacturing, transportation and logistics, hospitality, consumer goods, healthcare, and telecommunications. Multiple threat actors have deployed DeadLock, including an affiliate previously associated with the Lynx and INC ransomware ecosystems; these associations do not establish that those operations are aliases of DeadLock. DeadLock uses decentralized victim-facing infrastructure to support negotiations and data disclosure. An interactive HTML ransom application retrieves a replaceable messaging-proxy address from a Polygon smart contract through read-only blockchain queries, with fallback RPC gateways providing redundancy. Victim communications pass through the Session messaging network. A separate Polygon contract supplies leak-blog content and attachment references, while advertised stolen files are hosted on Wasabi. Operators can replace the communications proxy without modifying the victim-facing application. This architecture improves resistance to infrastructure takedowns but still depends on accessible blockchain gateways, a custom proxy, and removable cloud-hosted files. The Rust-based encryptor uses unique per-file XChaCha20 keys protected with Curve25519 and selectively encrypts files, including intermittent encryption of larger files. It applies resource-aware throttling and geographic or language exclusions covering former Soviet and CIS-linked environments and selected Middle Eastern countries. Observed Windows activity includes AnyDesk-based remote control, log clearing and logging suppression, service termination, deletion of backups and Volume Shadow Copies, and removal of scripts and the ransomware executable to reduce forensic evidence. DeadLock changes desktop presentation and supplies ransom notes directing victims to encrypted negotiations. It requests payment in Bitcoin or Monero and offers decryption alongside promises to delete stolen data.
Panzer is a ransomware and extortion operation active by August 2026. It maintains a victim leak site and uses double extortion, combining ransomware-related system disruption with threats to expose stolen data. Its leak site listed 32 victims between August 5 and September 23, 2026; such listings represent claims of compromise rather than independent verification of successful intrusions. Panzer's reported targets span technology providers, professional services, universities, healthcare, manufacturing, automotive businesses, and renewable energy. Reported victims include organizations in the United States, Germany, Brazil, Peru, France, Spain, the United Kingdom, and Bulgaria. Named targets include the University of Rostock, Universität Hamburg, SweetRush, Paes Soluções, K3G Solutions Brazil, Scenario Management, Honda Peru, and Konica Minolta Bulgaria. Panzer's geographic origin, operator identities, initial-access methods, and ransomware payload are not established. No verified aliases or subgroups are known, and an operational relationship with Galago has not been established.
Conti, also known as the Conti Gang, Conti Group, and Conti Ransomware Group, was a financially motivated, Russia-associated cybercriminal syndicate operating a ransomware-as-a-service program. First identified in 2020, it supplied affiliates with ransomware, operational guidance, and support in exchange for a share of ransom proceeds. Its attacks included U.S. healthcare and emergency-service networks, Ireland’s Health Service Executive in May 2021, and Costa Rican government organizations in 2022. The operation shut down in 2022 following internal disclosures and a political rift between members supporting Russia and Ukraine. Conti combined network-wide encryption with theft of sensitive information to support double extortion. Affiliates prioritized financial records, client information, security policies, and cyberinsurance documents to assess victims’ ability to pay and strengthen negotiation leverage. Karakurt functioned as a related data-extortion operation within the syndicate: when Conti encryption was blocked, attackers used the Karakurt name to demand payment over already-stolen information. Conti actors also began selling access to compromised victim networks in October 2021. Initial access involved malware-delivery relationships with Emotet, IcedID, and TrickBot, initial access brokers such as EXOTIC LILY, and exploitation of vulnerable internet-facing systems. Post-compromise operations emphasized Active Directory reconnaissance, credential dumping, Kerberoasting, password guessing, privilege escalation, and lateral movement to obtain domain-wide administrative access. Tooling included Cobalt Strike, Mimikatz, AdFind, BloodHound, network scanners, and legitimate remote-access applications used to maintain access. Affiliate guidance covered exploitation of Zerologon and PrintNightmare, bulk exfiltration with Rclone, deletion of shadow copies, interference with security tools, and coordinated ransomware deployment. An affiliate training-playbook leak in August 2021 and disclosures of internal communications and source code in early 2022 exposed Conti’s organizational structure and attack procedures. Its dissolution dispersed personnel into the wider cybercrime ecosystem rather than ending the activity of all former members.
Akira is a financially motivated ransomware and extortion operation active since March 2023. Associated tracking names include PUNK SPIDER, GOLD SAHARA, Howling Scorpius, and Storm-1567. PUNK SPIDER identifies the adversary responsible for developing and maintaining Akira ransomware and its dedicated leak site, while GOLD SAHARA identifies activity involving Akira deployment. The operation includes core developers and intrusion affiliates operating under a ransomware-as-a-service model. Its victims span North America, Europe, Australia, and South America, including manufacturing, healthcare, education, financial services, telecommunications, construction, retail, hospitality, professional services, and government organizations. Akira typically employs double extortion, exfiltrating sensitive information before encrypting systems and threatening public disclosure if victims refuse payment. It has also conducted data-theft-only extortion. Its operators maintain a dedicated leak site and have published stolen financial records and customer information following unsuccessful negotiations. Payloads target Windows, Linux, and VMware ESXi environments and include C++-based Akira ransomware, Rust-based Megazord, and Akira_v2 variants. Akira uses hybrid ChaCha20 and RSA encryption and deletes volume shadow copies to impede recovery. Operators have also encrypted files remotely over SMB shares from unmanaged systems. Initial access commonly involves compromised VPN credentials, accounts without multifactor authentication, exposed remote services, spearphishing, and exploitation of perimeter vulnerabilities. Confirmed intrusion techniques include exploitation of Cisco ASA vulnerabilities CVE-2020-3259 and CVE-2023-20269. After entry, operators harvest credentials, escalate privileges, enumerate networks and domain relationships, create accounts for persistence, and move laterally through remote services such as RDP. Their toolkit includes Mimikatz, LaZagne, network scanners, legitimate remote-access applications, and Rclone, WinSCP, and FileZilla for exfiltration. Akira operators impair endpoint defenses, including through bring-your-own-vulnerable-driver attacks using PowerTool and a signed Zemana anti-malware driver to disable EDR at kernel level.
NightSpire, also tracked as Nightspire and nightspire_ransomware, is a financially motivated ransomware and data-extortion group that emerged in March 2025. It conducts double-extortion operations, stealing sensitive information and encrypting compromised systems before demanding payment and threatening public disclosure. Its dedicated dark-web leak site lists victim organizations and uses publication countdowns to increase pressure. The group also uses direct pressure emails and public shaming through Telegram to encourage negotiations. NightSpire targets organizations across North America, Europe, Asia, the Middle East, and South America. Its targets include healthcare and pharmaceutical organizations, educational institutions, manufacturers, technology providers, retailers, hospitality businesses, professional services firms, transportation and logistics companies, and government bodies. Its geographically dispersed targeting includes the United States, United Arab Emirates, Japan, France, United Kingdom, Canada, Brazil, India, South Korea, Argentina, Colombia, Hong Kong, Taiwan, and Thailand. NightSpire's intrusion methods include exploitation of exposed FortiOS appliances through CVE-2024-55591, an authentication-bypass vulnerability that enables super-administrator access. Its operations include network and file discovery, lateral movement through remote services and file-transfer mechanisms, and abuse of legitimate administrative utilities to reduce detection. Tools associated with its activity include PowerShell, WinSCP, MEGACmd, 7-Zip, and the Everything search utility. Stolen data is transferred to cloud storage, including MEGA, before ransomware deployment and extortion.
Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, UNC3753, Storm-0252, and Silent Ransom, is a Russia-based, financially motivated cyberextortion group active since 2022. It emerged following the dissolution of Conti. Despite its name, the group conducts data-theft extortion without encrypting victims’ systems, threatening to publish or sell stolen information unless payment is made. The group primarily targets law firms and professional services organizations, particularly in the United States, exploiting the sensitivity of confidential client information and the reputational consequences of disclosure. Its victim population also includes financial services and real estate organizations. SRG maintains a public leak site to publish stolen information and pressure organizations that refuse payment. SRG uses callback phishing and telephone-based social engineering to obtain access. Early campaigns employed fraudulent subscription invoices that induced recipients to call attacker-controlled telephone numbers. Operators subsequently adopted internal IT-support, help-desk, and data-migration impersonation, persuading employees to initiate screen-sharing sessions or grant remote access through legitimate administration software. The use of legitimate remote-management and file-transfer tools helps the group blend into ordinary business activity and reduces its reliance on custom malware. After obtaining access, operators collect confidential documents and exfiltrate them using file-transfer tools and consumer file-sharing services. The group has also used people posing as IT personnel to seek physical access to victims’ offices and computers, extending its social-engineering operations beyond remote interactions.
Breaches attributed to ransomware activity, most recently reported first.
Purported SRG chats reveal discussions of kidnapping executives and threatening families
Qilin attacks Japanese carmaker Nissan
Kaspersky GERT discovers the PAYLOAD extortion campaign
Judge grants one-month delay in Pinhasi case amid plea negotiations
WaterISAC publishes Warlock campaign alert detailing SYSVOL ransomware distribution