Beast is a ransomware-as-a-service operation and cybercriminal group that emerged in 2024 as a successor or rebrand of the Monster ransomware lineage. It has also been assessed as part of a broader Monster → Beast → GodDamn evolution associated with the developer or operator cluster tracked as Hyadina. Beast supports multi-platform ransomware deployment, with Windows and Linux encryptors observed, indicating the ability to target Linux and VMware ESXi environments in addition to Windows networks. The group operates a leak site known as BEAST LEAKS and has conducted double-extortion operations combining data theft with encryption and public shaming. Beast tradecraft relies heavily on common dual-use and commodity offensive tooling rather than uniquely distinctive malware. Observed tooling and workflows include reconnaissance and network mapping, credential theft using utilities such as Mimikatz and LaZagne, Kerberoasting-related activity, lateral movement with PsExec and OpenSSH for Windows, persistence through remote access software such as AnyDesk, and exfiltration using cloud-sync and file-transfer tools. Exposed operator infrastructure also showed scripts and utilities intended to delete backups, disable recovery mechanisms, stop security and backup processes, and wipe logs after execution. The group has been specifically associated with deleting volume shadow copies and impairing backup systems before or during ransomware deployment. Victimology indicates opportunistic targeting across multiple sectors and geographies. Confirmed or claimed victims and reporting place Beast activity against healthcare organizations, manufacturing firms, information technology-related entities, architecture and education organizations, retirement and skilled nursing providers, pharmaceutical companies, and battery-component manufacturers. Reporting also places Beast activity in the United States, South Korea, and China, with South Korean incidents including attacks on a pharmaceutical company and a battery safety component manufacturer, and healthcare-related victim claims in the United States. Broader ecosystem reporting also associates Beast with intrusion vectors such as compromised RDP, SMB scanning, and opportunistic exploitation. Beast has been advertised in underground ecosystems as a RaaS program and has been listed among active ransomware affiliate offerings on Russian-language cybercrime forums. Public reporting indicates the group began operating as a RaaS scheme in early 2025 and launched its leak site in mid-2025. The actor’s operational model, tooling overlap with other ransomware groups, and use of standard administrative and credential-access utilities complicate attribution unless ransomware binaries or direct infrastructure links are available. Aliases include Beast Ransomware and Beast Ransomware Group. Beast is financially motivated and there is no high-confidence evidence of state sponsorship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in the actor index/TTP section without substantive discussion.
Earlier ransomware branding in the Monster -> Beast -> GodDamn lineage; described as an enhanced version of Monster and the immediate predecessor to GodDamn.
Mentioned as a ransomware family using NirSoft tools; also noted as a predecessor iteration in the Hyadina lineage.
Ransomware group active against South Korean organizations during the quarter.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.