24 Active Groups

Threat Actor Profiles

In-depth profiles on active ransomware groups — TTPs, targets, IOCs and defence guidance.

← Back to Threat Intelligence

LockBit

ACTIVE

Active Since: 2019

Targets: Enterprise, critical infrastructure

LockBit 5.0

ACTIVE

Active Since: 2024

Targets: Enterprise, critical infrastructure

Clop

ACTIVE

Active Since: 2019

Targets: Large enterprises, MFT software users

BlackCat/ALPHV

DISRUPTED

Active Since: 2021

Targets: Global enterprises, healthcare

Play

ACTIVE

Active Since: 2022

Targets: SMBs, municipalities, healthcare

BianLian

ACTIVE

Active Since: 2022

Targets: Healthcare, professional services

Royal

ACTIVE

Active Since: 2022

Targets: Healthcare, education, critical infra

Qilin

ACTIVE

Active Since: 2022

Targets: Healthcare, critical infrastructure

Akira

ACTIVE

Active Since: 2023

Targets: SMBs, professional services, education

Rhysida

ACTIVE

Active Since: 2023

Targets: Healthcare, education, government

Medusa

ACTIVE

Active Since: 2023

Targets: Healthcare, education, government

Cactus

ACTIVE

Active Since: 2023

Targets: Manufacturing, technology, finance

8Base

ACTIVE

Active Since: 2023

Targets: SMBs, professional services

Hunters International

ACTIVE

Active Since: 2023

Targets: Global enterprises

INC Ransom

ACTIVE

Active Since: 2023

Targets: Healthcare, education, local govt

DragonForce

ACTIVE

Active Since: 2023

Targets: Retail, manufacturing, Asia-Pacific

Sarcoma

ACTIVE

Active Since: 2024

Targets: Professional services, manufacturing

Underground

ACTIVE

Active Since: 2023

Targets: Windows environments, enterprises

Interlock

ACTIVE

Active Since: 2024

Targets: Healthcare, technology, defence

RansomExx

ACTIVE

Active Since: 2020

Targets: Government, large enterprises

Lynx

ACTIVE

Active Since: 2024

Targets: SMBs, professional services

KillSec

ACTIVE

Active Since: 2023

Targets: Healthcare, government, finance

ThreeAM

ACTIVE

Active Since: 2023

Targets: SMBs, manufacturing, logistics

Vanir Group

ACTIVE

Active Since: 2024

Targets: Financial services, technology

Need Proactive Threat Monitoring?

Our dark web monitoring service tracks these groups and alerts you if your organisation appears on a leak site.

Dark Web Monitoring Get Help Now