Threats Tagged 'ransomware-as-a-service'
View all threats tagged with 'ransomware-as-a-service'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ransomware-as-a-service'
Click on any threat for detailed analysis and mitigation recommendations
The Gentlemen ransomware-as-a-service group emerged as a top-10 threat actor in the first half of 2026. The group exploits vulnerabilities in internet-facing devices like VPNs and firewalls, potentially collaborating with initial access brokers. They employ comprehensive reconnaissance using tools like SharpADWS, NetScan, and Advanced IP Scanner, capturing network traffic with netsh. The attackers disable security products through BYOVD techniques using vulnerable drivers, and deploy custom Go-based backdoors and ransomware variants. They spread laterally via GPO deployment and PsExec, encrypt files using Curve25519 and XChaCha20, and recently developed a C-based ransomware variant using AES256-GCM and RSA. The group targets multiple industries worldwide, particularly in Brazil, China, Indonesia, Taiwan, and Thailand, with attacks focusing on manufacturing, IT services, healthcare, and financial sectors. Join the discussion | AlienVault OTX General | 06/29/2026, 11:01:00 UTC Added: 06/30/2026, 06:51:30 UTC |
The Gentlemen is a ransomware-as-a-service operation tracked as Storm-2697, distinguished by combining robust per-file encryption using Curve25519 with XChaCha20 stream cipher alongside aggressive self-propagation capabilities designed for broad network compromise. Emerging in mid-2025 and transitioning to RaaS by September 2025, the operation recently partnered with BreachForums to recruit affiliates including penetration testers and initial access brokers. Written in Go and obfuscated with Garble, the ransomware employs double extortion tactics, encrypting data while exfiltrating sensitive information. It utilizes 21 distinct lateral movement techniques per target host, including PsExec, WMI, scheduled tasks, services, and PowerShell remoting. The malware disables defenses, deletes shadow copies and forensic artifacts, and can optionally wipe free disk space to prevent recovery, impacting organizations globally across education, transportation, healthcare, and finance sectors. Join the discussion | AlienVault OTX General | 05/28/2026, 19:56:31 UTC Added: 05/29/2026, 10:48:34 UTC |
Vect ransomware emerged in January 2026 as a new threat actor operating a Ransomware-as-a-Service program with strategic partnerships that significantly expand its reach. The group has partnered with TeamPCP, known for supply chain attacks compromising security tools like Trivy, KICS, and LiteLLM, and BreachForums, distributing affiliate keys to forum members. With 25 published victims primarily targeting the United States and Technology sector, Vect maintains an open affiliate program requiring only a $250 invite code. The operation offers multi-platform ransomware payloads for Windows, Linux, and ESXi with sophisticated lateral movement capabilities and tiered commission structures reaching 89% for top affiliates. Analysis reveals connections to the defunct Devman ransomware through shared code strings and ransom note similarities, suggesting possible rebranding or code reuse. Join the discussion | AlienVault OTX General | 04/30/2026, 23:40:32 UTC Added: 05/04/2026, 14:06:24 UTC |
Trigona ransomware affiliates have developed and deployed a custom exfiltration tool named uploader_client.exe, observed in attacks during March 2026. This tool uses parallel data streams, connection rotation, and file filtering to evade detection and streamline data theft. Attackers disable endpoint protections at the kernel level using multiple utilities before exfiltration. Remote access and credential theft are facilitated by AnyDesk and tools like Mimikatz. This represents a more technically sophisticated approach than typical ransomware affiliate operations. Join the discussion | AlienVault OTX General | 04/23/2026, 14:37:51 UTC Added: 04/24/2026, 09:06:03 UTC |
The Gentlemen ransomware-as-a-service program has rapidly expanded since mid-2025, claiming over 320 victims with 240 attacks occurring in early 2026. The service provides multi-platform lockers for Windows, Linux, NAS, BSD, and ESXi, enabling comprehensive coverage of corporate environments. During an incident response engagement, an affiliate deployed SystemBC proxy malware for covert tunneling and payload delivery. Analysis of the SystemBC command-and-control server revealed a botnet of over 1,570 victims, primarily corporate and organizational targets. The intrusion progressed from domain controller compromise through credential validation, remote execution via administrative shares, and deployment of Cobalt Strike payloads. Attackers disabled defenses, established persistence through scheduled tasks and services, and ultimately deployed ransomware via Group Policy. The operation demonstrates sophisticated lateral movement capabilities, defense evasion techniques, and integration of mature post-exploit... Join the discussion | AlienVault OTX General | 04/20/2026, 15:00:35 UTC Added: 04/20/2026, 16:31:09 UTC |
NightSpire ransomware, first discovered in February 2025, presents a categorization challenge regarding whether it operates as Ransomware-as-a-Service (RaaS). Analysis of two incidents from December 2025 and March 2026 reveals significant variations in tactics, techniques, and procedures between attacks. The March 2026 incident involved threat actors installing Chrome Remoting Desktop and AnyDesk for persistence, using Everything and 7Zip for data staging, MEGASync for exfiltration, and deploying VMWare Workstation and WPS Office. The attacker accessed systems via RDP days before detection. Comparison with the December 2025 incident shows evolution in the ransomware encryptor, including modified ransom note filenames and contents. These variations in TTPs and indicators suggest either operational evolution or involvement of multiple affiliates, demonstrating that ransomware indicators aren't consistent across campaigns. Join the discussion | AlienVault OTX General | 04/08/2026, 09:15:51 UTC Added: 04/08/2026, 11:05:57 UTC |
RansomHouse, a ransomware-as-a-service operated by the Jolly Scorpius group, has upgraded its encryption capabilities with a new version of its Mario ransomware component. This upgrade introduces a sophisticated two-stage encryption process, enhanced memory management, and dynamic file processing, making the ransomware more efficient and harder to analyze. The attack chain involves MrAgent managing deployments and Mario performing file encryption, primarily targeting virtualized environments such as ESXi servers. Although no known exploits are currently in the wild, the improvements signal a trend toward more resilient ransomware variants. European organizations using virtualized infrastructure are at risk, especially those with ESXi deployments. The threat requires no known CVE but poses a medium severity risk due to its complexity and potential impact on availability and data confidentiality. Mitigation should focus on securing virtualization platforms, monitoring for indicators of compromise, and implementing robust backup and recovery strategies. Countries with high virtualization adoption and critical infrastructure reliance on virtual environments are most likely to be affected. Join the discussion | AlienVault OTX General | 12/17/2025, 14:28:36 UTC Added: 12/17/2025, 22:30:09 UTC |
A new Ransomware-as-a-Service (RaaS) group called GLOBAL GROUP has emerged, likely a rebranding of the BlackLock RaaS operation. The group targets various sectors across the US and Europe, with a focus on healthcare providers. GLOBAL GROUP utilizes Initial Access Brokers to gain entry to vulnerable edge appliances and employs brute-force tools for Microsoft Outlook and RDWeb portals. Their ransom negotiation panel features AI-driven chatbots, enabling non-English-speaking affiliates to engage victims more effectively. The group offers an 85% revenue share to affiliates and provides a mobile-friendly control panel. GLOBAL GROUP's infrastructure has been traced to a Russia-based VPS provider, and their operations show similarities to previous Mamona ransomware activities. MediumCampaign Join the discussion | AlienVault OTX General | 07/16/2025, 16:10:12 UTC Added: 07/16/2025, 19:16:11 UTC |
Anubis is a new ransomware-as-a-service (RaaS) group that combines file encryption with file destruction capabilities. Active since December 2024, it features a 'wipe mode' that permanently erases files, making recovery impossible even if ransom is paid. The group operates a flexible affiliate program, offering negotiable revenue splits and supporting additional monetization paths like data extortion and access sales. Anubis has claimed victims in multiple sectors including healthcare and construction, across regions such as Australia, Canada, Peru, and the U.S. The ransomware uses spear-phishing for initial access, employs command-line execution, privilege escalation, and shadow copy deletion. Its encryption algorithm is similar to EvilByte/Prince ransomware, using Elliptic Curve Integrated Encryption Scheme (ECIES). Join the discussion | AlienVault OTX General | 06/13/2025, 14:04:22 UTC Added: 06/13/2025, 20:19:24 UTC |
Showing 1 to 9 of 9 results