Arkana
Arkana is a ransomware group/family identified in 2025 as part of a highly fragmented ransomware ecosystem composed of many short-lived operations. The provided reporting places Arkana among newly emerged ransomware groups and notes it accounted for 1 incident in the cited industrial-sector reporting. Arkana is described alongside groups such as RansomHub, CrazyHunter, and NightSpire as establishing operations using reused codebases and recycled infrastructure, indicating limited technical novelty and likely dependence on shared tooling and access ecosystems rather than unique malware development. More broadly, the source material characterizes these 2025-era groups as commonly operating under a Ransomware-as-a-Service model, frequently relying on identity-based compromise for initial access, including stolen VPN credentials, MFA fatigue, session token hijacking, and OAuth abuse; secondary access via exploited VPN/firewall edge infrastructure; phishing and SaaS abuse such as HTML smuggling and fake login portals; and cloud/SaaS misconfigurations including over-permissioned IAM roles and exposed API tokens. The same reporting states that such groups often used lightweight, minimally obfuscated or open-source malware, and that data theft and extortion frequently replaced or preceded encryption. Targets were primarily small and mid-sized enterprises, organizations with cyber insurance, and cloud-first environments with weak identity governance; industrial entities were also affected in the cited Dragos reporting. No specific Arkana-exclusive indicators of compromise, malware capabilities, victimology, or threat actor attribution beyond these ecosystem-level characteristics are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family that emerged in 2025, known for exploiting edge infrastructure such as VPN appliances and firewalls, often followed by credential harvesting.
Ransomware operation referenced as minimal activity in Q2 2025 (no additional detail provided).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.