J Group is a ransomware threat actor first observed as a new entrant in May 2024. Public reporting places it among the wave of ransomware brands that emerged during 2024, a period marked by rapid proliferation of short-lived and newly branded extortion operations. High-confidence information directly attributes J Group to ransomware activity and identifies it as operating under the aliases jgroup and j_group. Beyond its appearance in victim-claim listings and its identification as a distinct ransomware variant or group, publicly corroborated details about its tooling, intrusion methods, victimology, geographic focus, organizational structure, or extortion model are currently not available. Its inclusion alongside other contemporary ransomware groups indicates financially motivated criminal activity is the most likely characterization, but specific tactics such as encryption-only extortion, double extortion, leak-site operations, or affiliate-based ransomware-as-a-service are not established here at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware crew that emerged in 2025; no additional details provided.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in May 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.