Beast, also known as Beast Ransomware and Beast Ransomware Group, is a financially motivated ransomware-as-a-service operation that emerged publicly in 2024. Its ransomware belongs to a development lineage associated with Hyadina that includes Monster and the subsequent GodDamn family. Beast conducts double-extortion attacks, combining file encryption with data theft and publication threats through its dedicated BEAST LEAKS site. Its targeting includes healthcare providers and manufacturing organizations, with activity involving the United States, South Korea, and China. Healthcare incidents associated with Beast have involved confirmed exposure of personal and protected health information, although individual leak-site claims do not necessarily establish a verified compromise. Beast supports Windows, Linux, and VMware ESXi environments. Its intrusion methods include compromised RDP access, SMB scanning, and opportunistic exploitation. Operator tooling includes Advanced IP Scanner and Advanced Port Scanner for discovery; Mimikatz, LaZagne, and Automim for credential theft; PsExec and OpenSSH for lateral movement; and AnyDesk for persistent remote access. Operators use MEGASync and other file-transfer utilities to exfiltrate data before encryption. Beast aggressively impairs recovery by deleting volume shadow copies, disabling backup services, and terminating database, backup, and security-related processes. Its operations rely substantially on legitimate administrative utilities and widely available dual-use tools, making tool overlap alone insufficient for reliable attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The Beast ransomware operation lists M800 and CINNOX, a Hong Kong communications/IT provider, as a victim. The post contains only a business description and provides no claimed data volume, ransom demand, deadline, or proof of compromise.
The Beast ransomware leak site lists Cosmon, a US engineering-software provider, as a victim. The post provides a company description and domain but contains no claim regarding stolen-data volume, data types, ransom demand, deadline, or supporting sample data.
The Beast ransomware leak site lists Meridian Forest Services as a victim, identifying the organization as a Canadian natural resource consulting company. The post provides basic victim profiling and discovery/publication timestamps but does not state stolen data volume, ransom demand, deadline, or proof of compromise.
Listed only in the actor index/TTP section without substantive discussion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.