SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 3,932 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 3,932 new IOCs ingested in last 24h
🔐

Ransomware Intelligence

Real-time tracking of ransomware victims, threat groups, and attack trends worldwide. Monitor active ransomware gangs, their targets by sector and country, and stay ahead of double-extortion campaigns with live data from 30+ group leak sites.

Active Ransomware Victims (30d)+9 today
747
▲ 170 in last 7 days
Known Ransomware Groups
125
45 active · 30 dark
Top Active Groups (7d)
qilinthegentlemenakira
Recent Ransomware Victims4,604 total
🔍
25 / 4,604
DateVictimSectorCountryGroupLink
2026-09-26
cipher.systems
TechnologyUnited Statesm3rx↗
2026-09-26
International Chemical Co.
Manufacturing—Barracuda↗
2026-09-26
M****n
Not FoundUnited Statespayoutsking↗
2026-09-26
Applied Composites
ManufacturingUnited StatesStorm↗
2026-09-26
Magna Legal Services
Professional ServicesUnited StatesStorm↗
2026-09-26
Ligue se Grupo
OtherPortugalthegentlemen↗
2026-09-26
Charles Keith
Retail & E-CommerceSingaporethegentlemen↗
2026-09-26
ENKEI*******
Manufacturing—thegentlemen↗
2026-09-26
FTAPI Software
TechnologyUnited Statesthegentlemen↗
2026-09-26
Crossett
OtherUnited Statestermite↗
2026-09-25
N...
Not Found—SilentRansomGroup↗
2026-09-25
S...
Not Found—SilentRansomGroup↗
2026-09-25
GE Vernova Inc.
Energy & UtilitiesUnited Statesmetaencryptor↗
2026-09-25
PKF Hadiwinata
Professional ServicesIndonesiametaencryptor↗
2026-09-25
Platinum Healthcare Staffing
HealthcareUnited Statesmetaencryptor↗
2026-09-25
Electrolux & Ontrac
Manufacturing—emperador↗
2026-09-25
Securitas Group
Professional ServicesSwedeneverest↗
2026-09-25
Morula IVF
HealthcareSouth Africaeverest↗
2026-09-25
Tobin & Company
Financial ServicesUnited StatesWallstreet↗
2026-09-25
Ar Valve Resources
Energy & UtilitiesUnited KingdomWallstreet↗
2026-09-25
GTFM
Not FoundUnited StatesWallstreet↗
2026-09-25
Beatus Cartons
ManufacturingUnited KingdomWallstreet↗
2026-09-25
Reliance Audit
Professional Services—everest↗
2026-09-25
UNIRITA
TechnologyJapaneverest↗
2026-09-25
CENELEC
Professional ServicesBelgiumeverest↗
Page 1 / 185
📈 Ransomware Trend — Last 30 Days747 victims
Daily victims
Ransomware Groups Overview125 total
45 active · 30 dark
Gang NameTotal30d7dStatusCountrySectorsLast Seen
qilin
641+85+17● Active—
—
2026-09-25
thegentlemen
562+78+5● Active—
—
2026-09-26
akira
194+40+9● Active—
—
2026-09-24
krybit
151+34+4● Active—
—
2026-09-24
incransom
196+31+8● Active—
—
2026-09-25
clop
Observed for the first time in Febuary 2019, variant from CryptoMix Family, itself a varia…
116+25+23● Active—
—
2026-09-23
Storm
ransomware
61+25+5● Active—
—
2026-09-26
lockbit5
101+24+4● Active—
—
2026-09-25
direwolf
62+20—● Dark—
—
2026-09-11
safepay
SafePay ransomware started in October 2024 as a new ransomware service, using some of the …
116+19—● Dark—
—
2026-09-15
emperador
28+19+5● Active—
—
2026-09-25
AuditTeam
33+18+2● Active—
—
2026-09-22
metaencryptor
24+18+9● Active—
—
2026-09-25
SilentRansomGroup
58+17+8● Active—
—
2026-09-25
Wallstreet
23+17+7● Active—
—
2026-09-25
Panzer
32+16—● Dark—
—
2026-09-18
Vexy Ransomware
16+16+1● Active—
—
2026-09-25
N0n
14+14+3● Active—
—
2026-09-25
play
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through do…
79+13+2● Active—
—
2026-09-21
shinyhunters
82+12+3● Active—
—
2026-09-24
everest
45+12+6● Active—
—
2026-09-25
BrainCipher
37+12+1● Active—
—
2026-09-23
rhysida
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group util…
21+11+2● Active—
—
2026-09-24
chaos
47+9—● Dark—
—
2026-09-17
medusalocker
Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilitie…
45+9+3● Active—
—
2026-09-23
dragonforce
Research on the operators of the DragonForce ransomware was conducted, and it was identifi…
207+8+3● Active—
—
2026-09-24
Booba Project
19+7+5● Active—
—
2026-09-23
anubis
49+6+2● Active—
—
2026-09-22
Global Secret Group
47+6+2● Active—
—
2026-09-21
pear
ABOUT US: <br/> <br/>"Pure Extraction And Ransom (PEAR) Team is the community of highly re…
38+6+3● Active—
—
2026-09-24
Orova
28+6+2● Active—
—
2026-09-20
Eclipse
10+6—● Dark—
—
2026-09-14
ShadowByt3$
8+6—● Dark—
—
2026-09-16
spacebears
29+5+1● Active—
—
2026-09-23
arcusmedia
15+5+1● Active—
—
2026-09-23
unsafe
12+5+1● Active—
—
2026-09-21
EndZone
5+5+3● Active—
—
2026-09-24
aurora
36+4—● Dark—
—
2026-09-07
Dark Project
17+4—● Dark—
—
2026-09-09
termite
13+4+4● Active—
—
2026-09-26
Barracuda
12+4+3● Active—
—
2026-09-26
Doommageddon
9+4+1● Active—
—
2026-09-21
Spirals
4+4+2● Active—
—
2026-09-24
nightspire
47+3+2● Active—
—
2026-09-21
kairos
22+3+1● Active—
—
2026-09-22
majinahanashi
14+3—● Dark—
—
2026-09-01
DYSPHOR1A
10+3—● Dark—
—
2026-09-06
iah6477
8+3—● Dark—
—
2026-09-15
insomnia
6+3—● Dark—
—
2026-09-15
global
Not a RaaS yet.
3+3—● Dark—
—
2026-09-12
Falcon
3+3—● Dark—
—
2026-08-31
genesis
Financial interests only. <br/> We do not provide or work with affiliate programs, no c…
52+2—● Dark—
—
2026-09-14
m3rx
39+2+1● Active—
—
2026-09-26
gunra
34+2—● Dark—
—
2026-09-04
threeam
27+2+1● Active—
—
2026-09-21
titan
25+2+2● Active—
—
2026-09-22
interlock
21+2—● Dark—
—
2026-09-07
bravox
20+2+1● Active—
—
2026-09-20
securotrop
12+2—● Dark—
—
2026-09-18
kazu
11+2—● Dark—
—
2026-09-07
moneymessage
7+2+1● Active—
—
2026-09-21
Black X
3+2—● Dark—
—
2026-08-30
fulcrumsec
25+1—● Dark—
—
2026-09-11
lynx
19+1—● Dark—
—
2026-08-29
blacknevas
14+1—● Dark—
—
2026-09-16
payoutsking
Payouts King Group. We are not RaaS. No affiliates are accepted. We use Tox messaging prot…
14+1+1● Active—
—
2026-09-26
killsec
10+1—● Dark—
—
2026-09-18
Gammax
5+1—● Dark—
—
2026-09-18
crypto24
aka Public Data Storage
4+1—● Dark—
—
2026-08-31
embargo
3+1—● Dark—
—
2026-09-09
tridentlocker
2+1—● Dark—
—
2026-09-04
cry0
2+1—● Dark—
—
2026-09-19
BlackLocks
1+1—● Dark—
—
2026-09-05
secp0
1+1+1● Active—
—
2026-09-22
ImNotAVillain
1+1+1● Active—
—
2026-09-24
Deadlock
91——● Dark—
—
2026-08-24
coinbasecartel
88——● Dark—
—
2026-08-23
nova
Rebrand of RALord
83——● Dark—
—
2026-07-25
apt73
A new ransomware group is said to have emerged in mid-April 2024, under the name "APT73." …
77——● Dark—
—
2026-07-24
payload
53——● Dark—
—
2026-08-20
cmdorganization
41——● Dark—
—
2026-07-31
CRPxO
37——● Dark—
—
2026-08-02
worldleaks
34——● Dark—
—
2026-07-21
lamashtu
34——● Dark—
—
2026-06-17
stormous
33——● Dark—
—
2026-07-01
AiLock
AiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025. It employ…
27——● Dark—
—
2026-08-26
Section9
20——● Dark—
—
2026-07-30
ExfilSquad
15——● Dark—
—
2026-07-26
shadowbyt3$
12——● Dark—
—
2026-06-16
Icarus
12——● Dark—
—
2026-06-23
blackwater
11——● Dark—
—
2026-08-24
LeakBazaar
9——● Dark—
—
2026-05-10
Helix
8——● Dark—
—
2026-08-22
handala
8——● Dark—
—
2026-04-08
morpheus
8——● Dark—
—
2026-07-30
xpl0itrs
7——● Dark—
—
2026-08-20
netrunner
6——● Dark—
—
2026-04-03
ransomhouse
6——● Dark—
—
2026-07-15
sinobi
6——● Dark—
—
2026-05-08
0day Syndicate
5——● Dark—
—
2026-05-29
lapsus$
Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile bre…
5——● Dark—
—
2026-06-23
ALP-001
5——● Dark—
—
2026-04-08
PrinzEugen
5——● Dark—
—
2026-06-26
settra
5——● Dark—
—
2026-06-30
secpo
5——● Dark—
—
2026-04-29
abyss
4——● Dark—
—
2026-08-26
cloak
4——● Dark—
—
2026-06-18
mnt6
3——● Dark—
—
2026-05-02
D1R
3——● Dark—
—
2026-07-13
ransomexx
We recently discovered a new file-encrypting Trojan built as an ELF executable and intende…
3——● Dark—
—
2026-06-20
blackout
Ransomware
3——● Dark—
—
2026-07-19
TiMc
3——● Dark—
—
2026-04-09
ms13089
2——● Dark—
—
2026-08-15
Redact
2——● Dark—
—
2026-06-28
beast
2——● Dark—
—
2026-05-16
nitrogen
2——● Dark—
—
2026-06-03
Blackfield
2——● Dark—
—
2026-07-03
radar
1——● Dark—
—
2026-04-29
orca
1——● Dark—
—
2026-04-27
ValenciaLeaks
1——● Dark—
—
2024-09-18
dispossessor
1——● Dark—
—
2024-04-19
L Group
1——● Dark—
—
2026-08-23
exitium
1——● Dark—
—
2026-04-14
vect
1——● Dark—
—
2026-04-15
Triple X
1——● Dark—
—
2026-08-05
⬡ Collector Health Grid32/32 online
🖥
Feodo
31m
📦
MalwareBazaar
31m
🔒
SSLBL
2h
🛡
ThreatFox
1m
🌐
URLhaus
31m
🛡
AbuseIPDB
1h
⬡
AL
2h
🕸
C2Intel
2h
⚡
CISA KEV
2h
💣
Exploit-DB
2h
📊
FIRST EPSS
1d
🌫
GreyNoise
14h
📰
Mandiant
31m
⬡
MI
1d
🗺
MITRE ATT&CK
14h
⬡
MS
2h
✨
AI Summaries
29m
📋
NVD CVE
2h
🎣
OpenPhish
2h
🔐
Ransomware.live
1m
⬡
RA
122d
📰
Sec.Blogs
1m
🔍
SigmaHQ
1d
👤
Hudson Rock
2h
🤖
Clustering
28m
⬡
TH
14h
⬡
TH
14h
🔗
Tor Exits
2h
🔬
VirusTotal
1h
⬡
YA
6h
⬡
YA
7h
⬡
YA
7h