Threat Actor Profiles
In-depth profiles on active ransomware groups — TTPs, targets, IOCs and defence guidance.
LockBit
ACTIVEActive Since: 2019
Targets: Enterprise, critical infrastructure
LockBit 5.0
ACTIVEActive Since: 2024
Targets: Enterprise, critical infrastructure
Clop
ACTIVEActive Since: 2019
Targets: Large enterprises, MFT software users
BlackCat/ALPHV
DISRUPTEDActive Since: 2021
Targets: Global enterprises, healthcare
Play
ACTIVEActive Since: 2022
Targets: SMBs, municipalities, healthcare
BianLian
ACTIVEActive Since: 2022
Targets: Healthcare, professional services
Royal
ACTIVEActive Since: 2022
Targets: Healthcare, education, critical infra
Qilin
ACTIVEActive Since: 2022
Targets: Healthcare, critical infrastructure
Akira
ACTIVEActive Since: 2023
Targets: SMBs, professional services, education
Rhysida
ACTIVEActive Since: 2023
Targets: Healthcare, education, government
Medusa
ACTIVEActive Since: 2023
Targets: Healthcare, education, government
Cactus
ACTIVEActive Since: 2023
Targets: Manufacturing, technology, finance
8Base
ACTIVEActive Since: 2023
Targets: SMBs, professional services
Hunters International
ACTIVEActive Since: 2023
Targets: Global enterprises
INC Ransom
ACTIVEActive Since: 2023
Targets: Healthcare, education, local govt
DragonForce
ACTIVEActive Since: 2023
Targets: Retail, manufacturing, Asia-Pacific
Sarcoma
ACTIVEActive Since: 2024
Targets: Professional services, manufacturing
Underground
ACTIVEActive Since: 2023
Targets: Windows environments, enterprises
Interlock
ACTIVEActive Since: 2024
Targets: Healthcare, technology, defence
RansomExx
ACTIVEActive Since: 2020
Targets: Government, large enterprises
Lynx
ACTIVEActive Since: 2024
Targets: SMBs, professional services
KillSec
ACTIVEActive Since: 2023
Targets: Healthcare, government, finance
ThreeAM
ACTIVEActive Since: 2023
Targets: SMBs, manufacturing, logistics
Vanir Group
ACTIVEActive Since: 2024
Targets: Financial services, technology
Need Proactive Threat Monitoring?
Our dark web monitoring service tracks these groups and alerts you if your organisation appears on a leak site.
Dark Web Monitoring Get Help Now