Securotrop is a ransomware and data-extortion threat actor that emerged in 2024 and has been publicly linked to multiple intrusions against U.S. organizations. It is described as a ransomware-as-a-service operation associated with the Qilin ecosystem, including reporting that it splintered from the main Qilin gang while continuing to use Qilin network resources and code but maintaining its own leak infrastructure. Securotrop has operated a dedicated leak site since at least August 2025 and has publicly claimed attacks across sectors including manufacturing, energy, transportation and logistics, retail, and technology. The group’s operations are characterized by ransomware deployment combined with theft of victim data and public shaming on a leak site. Reported tradecraft supports the use of double extortion, with an apparent emphasis on closely examining and leveraging exfiltrated data to pressure victims. Publicly attributed incidents indicate repeated compromises of U.S.-based organizations, with claimed victims including industrial and manufacturing firms, an energy-sector drilling company, transportation and logistics businesses, media or technology-related organizations, and a retailer. Available reporting supports extortion-driven criminal activity rather than espionage or destructive state objectives. Known aliases include securotrop and securotrop_ransomware. Securotrop is best understood as a financially motivated ransomware crew operating in the broader Qilin-linked criminal ecosystem, using ransomware, data theft, leak-site publication, and extortion to monetize intrusions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Lepi Enterprises, with the incident report indicating a data breach and 692 GB of data associated with the event.
Conducting a ransomware attack against MAG USA Inc.
Conducting a ransomware attack and associated data breach against Advantage Sintered Metals.
Conducting a ransomware attack resulting in a data breach against ProDirectional Drilling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.