RA Group is a financially motivated ransomware-as-a-service operation first observed in late April 2023. It rebranded as RA World in January 2024. The operation uses ransomware derived from leaked Babuk source code and targets VMware ESXi environments. It maintains a data-leak site on which it publicly identifies victim organizations as part of its extortion activity. By June 14, 2023, RA Group had listed five victim organizations: three in the United States, one in South Korea, and one in Taiwan. Its activities include ransomware encryption and ransom demands. Its operators’ country of origin is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RA Group is discussed as a possible affiliate connection to the 'uploaded' ransomware variant. The leak-site link might instead have been included merely to intimidate victims; operational involvement is unconfirmed. The report's broader Proxima and BlackShadow activity cannot be attributed to RA Group.
Referenced as a predecessor lineage to the RaLord ransomware family; mentioned only in the context of Nova being a successor/offshoot rather than as an active operator in this incident.
Referenced as a predecessor lineage to the RaLord ransomware family; mentioned only in the context of Nova being a successor/offshoot rather than as an active operator in this incident.
RaaS group rebranded to RA World and linked to China-based threat actors through PlugX overlap with Mustang Panda.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.