LV is a ransomware threat actor associated with use of a modified REvil encryptor. Reporting has linked the group to patching REvil’s malware so that victims are encrypted with LV-controlled keys, indicating operational overlap with the broader post-REvil ransomware ecosystem. LV has been identified among active ransomware groups operating leak-site-based extortion models. The group has been observed abusing valid domain credentials, including compromised domain administrator accounts, to obtain domain admin privileges inside victim environments. This supports assessed capabilities in initial access through credential abuse, privilege escalation, persistence, lateral movement, and post-compromise operations conducted through legitimate accounts rather than software exploitation. The actor’s tradecraft is consistent with enterprise ransomware intrusion patterns centered on Active Directory compromise and broad control of Windows domains. LV is financially motivated and operates as a criminal ransomware actor rather than a state-sponsored espionage group. High-confidence public reporting in the supplied material does not establish a specific country of origin, named sub-groups, or a clearly attributed victim geography beyond general ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of multiple ransomware groups operating data leak sites and listing fresh victims.
Ransomware group obtaining domain admin via compromised domain administrator credentials to enable broader access and movement.
Referenced as a separate group that patched REvil’s encryptor to conduct its own ransomware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.