Key Group, also known as keygroup777, is a ransomware threat actor active since at least April 2022. The group is notable for repeatedly switching among multiple ransomware families rather than relying on a single proprietary strain, with at least eight different ransomware families linked to its operations. This pattern indicates an opportunistic operating model that leverages available ransomware tooling while making incremental changes to tradecraft across campaigns. Key Group has been associated with comparatively unsophisticated but effective operational infrastructure. Its activity has been linked through consistent ransom-note artifacts, and its command-and-control and operator communications have included use of public and mainstream services rather than dedicated covert infrastructure. Across observed campaigns, the group maintained persistence consistently, especially through autorun mechanisms in the Windows registry and, in some cases, the Windows Startup folder. Observed Key Group tradecraft includes persistence via registry-based autoruns and startup-folder execution. Variants associated with the actor have used multiple persistence locations, demonstrating adaptation of tactics to the ransomware family in use while preserving a stable post-compromise objective of maintaining execution. The actor is therefore best characterized as a flexible ransomware operator that reuses available malware ecosystems, adjusts TTPs between campaigns, and emphasizes persistence over bespoke tooling. Key Group is described as a Russian-speaking ransomware actor and as an exception to the common pattern of Russian-speaking cybercriminal groups avoiding operations connected to Russia. High-confidence reporting supports treating the group as operating from Russia or within the Russian-speaking cybercriminal ecosystem. Its dominant motivation is financial gain through ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.