[{"id": 3, "name": "qilin", "status": "online", "description": "Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion \u2013 dem", "claim_count": 187, "ttp_count": 15}, {"id": 4, "name": "thegentlemen", "status": "offline", "description": "The Gentlemen is a RaaS group that emerged in July\u2013August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, ", "claim_count": 134, "ttp_count": 16}, {"id": 2, "name": "akira", "status": "offline", "description": "The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, sever", "claim_count": 60, "ttp_count": 16}, {"id": 11, "name": "krybit", "status": "online", "description": "Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with ri", "claim_count": 59, "ttp_count": 0}, {"id": 7, "name": "direwolf", "status": "offline", "description": "Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ", "claim_count": 55, "ttp_count": 0}, {"id": 5, "name": "Storm", "status": "online", "description": "", "claim_count": 54, "ttp_count": 0}, {"id": 6, "name": "incransom", "status": "offline", "description": "INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 2", "claim_count": 53, "ttp_count": 14}, {"id": 24, "name": "lockbit5", "status": "online", "description": "LockBit 5.0 (\"ChuongDong\") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enha", "claim_count": 40, "ttp_count": 0}, {"id": 10, "name": "SilentRansomGroup", "status": "unknown", "description": "A former Conti team\naka Chatty Spider and UNC3753", "claim_count": 35, "ttp_count": 9}, {"id": 32, "name": "emperador", "status": "online", "description": "", "claim_count": 30, "ttp_count": 0}, {"id": 14, "name": "clop", "status": "online", "description": "The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively fi", "claim_count": 29, "ttp_count": 15}, {"id": 25, "name": "Panzer", "status": "online", "description": "", "claim_count": 27, "ttp_count": 0}, {"id": 12, "name": "shinyhunters", "status": "online", "description": "ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offerin", "claim_count": 26, "ttp_count": 7}, {"id": 37, "name": "metaencryptor", "status": "offline", "description": "MetaEncryptor is a ransomware group first observed in mid-2023, targeting medium-to-large enterprises in legal, technology, logistics, manufacturing, and finance sectors primarily in the UK, Europe, and Southeast Asia, u", "claim_count": 24, "ttp_count": 0}, {"id": 27, "name": "everest", "status": "offline", "description": "Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks th", "claim_count": 23, "ttp_count": 8}, {"id": 34, "name": "safepay", "status": "offline", "description": "SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profi", "claim_count": 23, "ttp_count": 16}, {"id": 36, "name": "AuditTeam", "status": "online", "description": "AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and Southeast Asia across technology and manufacturing sectors, operating a data leak site consistent wi", "claim_count": 21, "ttp_count": 0}, {"id": 18, "name": "coinbasecartel", "status": "offline", "description": "CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration\u2014our operations never involve system encryption or operational disruption.", "claim_count": 21, "ttp_count": 13}, {"id": 23, "name": "medusalocker", "status": "online", "description": "Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.\n", "claim_count": 19, "ttp_count": 1}, {"id": 31, "name": "dragonforce", "status": "online", "description": "DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a \"ransomware cartel\" in 2025, gaining notorie", "claim_count": 18, "ttp_count": 5}, {"id": 35, "name": "play", "status": "offline", "description": "Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares", "claim_count": 18, "ttp_count": 16}, {"id": 29, "name": "pear", "status": "online", "description": "Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors. We've been monitoring this field", "claim_count": 17, "ttp_count": 15}, {"id": 21, "name": "rhysida", "status": "online", "description": "Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<b", "claim_count": 16, "ttp_count": 14}, {"id": 33, "name": "Orova", "status": "online", "description": "First seen 2026-07-07", "claim_count": 13, "ttp_count": 9}, {"id": 20, "name": "anubis", "status": "offline", "description": "Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates a flexible revenue split model and an option", "claim_count": 12, "ttp_count": 0}, {"id": 9, "name": "majinahanashi", "status": "online", "description": "", "claim_count": 12, "ttp_count": 0}, {"id": 30, "name": "kazu", "status": "offline", "description": "Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations primarily in Southeast Asia, the Middle East, and Lati", "claim_count": 11, "ttp_count": 0}, {"id": 28, "name": "DYSPHOR1A", "status": "online", "description": "Suspicious group. We did not manage to confirm any victims.", "claim_count": 10, "ttp_count": 0}, {"id": 26, "name": "titan", "status": "offline", "description": "Founded 4 April 2026", "claim_count": 10, "ttp_count": 0}, {"id": 22, "name": "xpl0itrs", "status": "online", "description": "", "claim_count": 9, "ttp_count": 0}, {"id": 17, "name": "Deadlock", "status": "online", "description": "", "claim_count": 6, "ttp_count": 0}, {"id": 8, "name": "blacknevas", "status": "online", "description": "BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pa", "claim_count": 6, "ttp_count": 0}, {"id": 15, "name": "AiLock", "status": "online", "description": "AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates a", "claim_count": 5, "ttp_count": 0}, {"id": 13, "name": "payload", "status": "online", "description": "Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and ", "claim_count": 5, "ttp_count": 8}, {"id": 16, "name": "genesis", "status": "online", "description": "Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, f", "claim_count": 4, "ttp_count": 0}, {"id": 19, "name": "interlock", "status": "online", "description": "Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extor", "claim_count": 4, "ttp_count": 0}, {"id": 1, "name": "lockbit", "status": "offline", "description": "LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every ", "claim_count": 0, "ttp_count": 14}]