Researchers reported that a server believed to be operated by the developers of the Kuiper ransomware exposed source code, decryption keys, control tooling, and exfiltrated victim data, offering an unusual inside view of the ransomware-as-a-service operation. Kuiper was marketed on underground forums from September 2023 by an actor using the name RobinHood, which allegedly promised affiliates 90% of profits along with data-theft and cryptocurrency-mixing support. Stairwell said logs on the recovered server tied infections to 29 unique IP addresses across 11 countries and showed activity from Russian IP space despite the group’s stated ban on targeting CIS entities; the firm also recovered 10 private keys and said organizations hit before 4 December 2023 could obtain compiled decryptors.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Trellix published an analysis of Kuiper on January 17, 2024. The report said the malware's advertised capabilities were exaggerated, documented versions A, B, and C, and described added propagation and Windows-focused functionality in later builds.
On 1 December 2023, Stairwell researchers acquired a server they believed was operated by Kuiper's developers. The server contained source code, decryption keys, control tooling, and exfiltrated data.
Logs from a cracked Cobalt Strike instance tied to Kuiper showed activity from 21 November 2023 through 1 December 2023. Stairwell said the logs reflected infections associated with 29 unique IP addresses in 11 countries, including Russian IP space despite the group's stated CIS targeting ban.
On September 22, 2023, the actor RobinHood advertised Kuiper on an underground forum. The post claimed the ransomware was ready to use, offered operational help for a commission, and promoted double-extortion capabilities despite the leak site not being finished.
Kuiper was first observed in September 2023 as a new ransomware-as-a-service operation. The malware family was described as Golang-based and marketed by the actor using the RobinHood moniker.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.