Ruthless Mantis, also tracked as PTI-288, is a financially motivated ransomware threat actor associated with double-extortion operations. The group has been linked to collaboration with ransomware affiliate ecosystems, including operations involving Ragnar Locker and INC Ransom. Reporting also associates Ruthless Mantis with use of Ragnar Loader and notes an "ex-REvil" connection, indicating overlap with experienced ransomware operators and tooling common to the Russian-speaking cybercrime ecosystem. High-confidence public reporting supports characterization of Ruthless Mantis as an extortion-focused actor rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime actor (noted as ex-REvil) using Ragnar Loader for persistent access and ransomware operations.
Financially motivated ransomware/double-extortion group that collaborates with affiliate programs; uses a mix of legitimate and custom tooling and C2 frameworks to support the full attack lifecycle (discovery through lateral movement and execution).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.