Ruthless Mantis, also known as PTI-288, is a financially motivated ransomware group specializing in double extortion, combining data theft and encryption with threats to disclose stolen information. It collaborates with ransomware affiliate programs, including Ragnar Locker and INC Ransom, and is publicly identified as a Qilin affiliate. Its tooling includes Ragnar Loader, a malware loader also used by other financially motivated threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a publicly known Qilin affiliate. The report does not connect it to the investigated intrusion or describe its individual operations.
Cybercrime actor (noted as ex-REvil) using Ragnar Loader for persistent access and ransomware operations.
Financially motivated ransomware/double-extortion group that collaborates with affiliate programs; uses a mix of legitimate and custom tooling and C2 frameworks to support the full attack lifecycle (discovery through lateral movement and execution).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.