Knight is a ransomware family and ransomware-as-a-service operation active by 2023 and notable for code reuse relationships with later ransomware strains. It has been referenced in connection with broader ransomware ecosystem shifts in 2024, particularly because its source code was reportedly sold in February 2024 and subsequently repurposed by other actors. Security reporting has identified significant code overlap between Knight and RansomHub, including similarities in encryptor logic, help-menu structure, and string-obfuscation techniques, making Knight relevant to attribution discussions around successor or derivative ransomware operations.
Knight primarily targeted enterprise environments and is associated with multi-platform ransomware activity through its code lineage and reuse by later families that support Windows, Linux, and ESXi systems. Its role in the criminal ecosystem appears especially important as a precursor whose codebase enabled follow-on ransomware development rather than solely as an isolated campaign. Knight has also been discussed alongside other contemporary extortion groups in analyses of the fragmented post-ALPHV and post-LockBit ransomware landscape.
High-confidence public reporting in the supplied material supports Knight’s classification as ransomware, but does not provide sufficiently detailed, direct evidence on its own delivery vectors, victim sectors, or a fuller standalone capability profile beyond file-encrypting extortion activity typical of ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a former ransomware group with reported code overlap/linkage to RansomHub; no further technical details provided.
A ransomware family mentioned because RansomHub shares substantial code overlap with it, weakening attribution of RansomHub solely to BlackCat.
A ransomware family whose source code was sold in February 2024 and later repurposed as the basis for the RansomHub encryptor.
Ransomware family listed among active groups impacting industrial organizations in Q4 2023; also noted as first observed by Dragos in Q4 2023.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.