Section9 is a ransomware threat group that emerged in mid-2026 and quickly appeared at a notable activity level in ransomware claim tracking. It was first observed in the available dataset with 13 claimed victims in week 28 of 2026, indicating an abrupt entrance into the ransomware ecosystem rather than a gradual buildup. The group has been linked to ransomware intrusions and associated data-breach activity, including victim claims involving organizations in the United States. Section9 was also tracked among active ransomware groups during week 28 before dropping out of the most active rankings in week 29. Available reporting supports classification of Section9 as a financially motivated cybercriminal actor engaged in extortion-oriented ransomware operations. High-confidence detail on its malware lineage, intrusion tradecraft, victimology by sector, affiliate structure, or relationship to other named ransomware brands is currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against a U.S.-based organization.
Ransomware group mentioned only for comparison with the prior week; present in week 28 but not among the most active in week 29.
Newly observed ransomware/extortion group in this dataset, debuting with a significant number of claimed victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.