Silent Ransom Group Leaks Reveal Physical Infiltration Plans and Extortion Money Flows
Check Point reveals coordinated vishing workflow in purported SRG archive
What ransomware crews are doing right now — the groups picking up momentum, the breaches they're posting, and the stories tracking their operations. Aggregated from vendor reports, leak sites, researcher analysis, and underground chatter.
Actors ranked by Mallory's mention-velocity model across sources.
Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, UNC3753, Storm-0252, and Silent Ransom, is a Russia-based, financially motivated cybercriminal group that emerged in 2022 following Conti's shutdown. Its operators previously conducted BazarCall callback-phishing operations that supplied access to Ryuk and Conti. Despite its name, SRG primarily conducts data-theft extortion without encrypting victims' files. The group has focused heavily on U.S. law firms since 2023, exploiting the sensitivity of privileged client documents and the reputational consequences of disclosure. Its targeting also includes other professional services organizations, financial services, and real estate. SRG steals confidential information and threatens to publish or sell it unless victims pay, maintaining a leak site to expose non-paying organizations. Initial access centers on callback phishing and telephone-based impersonation. Fraudulent subscription invoices induce recipients to call operators, while other approaches impersonate internal IT personnel using help-desk or data-migration pretexts. Operators persuade employees to initiate screen-sharing sessions or grant remote access through legitimate administration software. They use legitimate file-transfer tools and consumer file-sharing services to collect and exfiltrate documents, reducing reliance on conspicuous malware. The group has also used impostors posing as IT personnel to seek physical access to victims' offices and computers.
ShinyHunters is a financially motivated cybercriminal operation specializing in large-scale data theft, stolen-database distribution, and encryption-less extortion. Also known as ShinyHunter, Shiny_Hunters, and Bling Libra, its associated activity is tracked under the identifiers UNC6040 and UNC6240. Criminals using the name have claimed breaches dating to at least 2019. Its original membership was predominantly French, while later operations evolved into a franchise-like network with changing operators and affiliates supplying stolen corporate SaaS credentials in exchange for shares of extortion proceeds. ShinyHunters targets technology and cloud-service providers, healthcare organizations, government agencies, transportation businesses, agricultural organizations, food distributors, retailers, and telecommunications companies. Initial-access methods include social engineering, voice phishing, impersonation of IT support personnel to obtain Okta access, abuse of OAuth tokens, and exploitation of internet-facing enterprise applications. In 2026, the operation mass-exploited Oracle PeopleSoft vulnerability CVE-2026-35273 to steal information from dozens of systems across multiple sectors. It also used URL encoding to bypass defensive web application firewall rules. A compromise of the FBI recruitment platform exposed sensitive information concerning more than 5,000 personnel. The operation monetizes stolen personal information and corporate records through underground database distribution and pay-or-leak demands. It uses a public leak site, imposes negotiation deadlines, and publishes stolen information to pressure victims. Its extortion activity has included Neogen and data-center operator CyrusOne. Pressure tactics also include threatening calls and messages, harassment of victims and their relatives, swatting, and fabricated claims of possessing compromising material. ShinyHunters has participated in underground database-sharing communities, including Raid Forums, and operators associated with it have been linked to the Scattered Lapsus$ Hunters coalition.
Qilin, formerly known as Agenda and also tracked as GOLD FEATHER and Water Galura, is a Russian-speaking, financially motivated ransomware-as-a-service operation active since 2022. Its core operators develop ransomware and maintain affiliate infrastructure, negotiation portals, and data-leak services, while affiliates compromise networks, steal data, and deploy encryption payloads. Qilin uses double extortion, combining encryption with threats to publish stolen information. Its targets include healthcare providers, manufacturers, professional-services firms, financial institutions, government entities, and cloud service providers across multiple continents. The June 2024 attack on UK pathology provider Synnovis severely disrupted services at several London NHS hospitals. Qilin's original Go-based ransomware evolved into Rust-based variants, including Qilin.B, supporting Windows, Linux, and VMware ESXi environments. Its configurable lockers support intermittent and percentage-based encryption, selective targeting, and propagation through PsExec and VMware vCenter. Encryption uses AES-256-CTR or ChaCha20, with RSA-4096 protecting encryption key material. Operators compromise backup infrastructure, delete shadow copies, stop backup and security services, and clear event logs to impede recovery and investigation. Affiliates obtain access through phishing, exposed remote-access services, purchased or compromised credentials, brute-force attacks, and exploitation of vulnerable internet-facing systems. Documented activity includes exploitation of Fortinet appliances and CVE-2023-27532 in Veeam Backup & Replication, credential harvesting with Mimikatz and browser-password theft, Active Directory reconnaissance, privilege escalation, and lateral movement using legitimate administrative tools. Data-exfiltration tools include Rclone, WinSCP, and FileZilla. Qilin attacks have also used Killer Ultra, which exploits a vulnerable Zemana driver through bring-your-own-vulnerable-driver techniques to terminate endpoint security processes and maintain startup persistence. Documented affiliates include Devman and Hastalamuerte. The North Korean state-sponsored actor Moonstone Sleet has deployed Qilin ransomware, but that use does not establish state sponsorship or North Korean origin for the Qilin operation itself.
Payload, also known as Payload ransomware and tracked as payload_ransomware, is a financially motivated ransomware and data-extortion operation first identified in February 2026. It targets mid-to-large-sized organizations internationally, including manufacturing, technology, healthcare, telecommunications, financial services, logistics, retail, and professional services. Its country of origin is not established. Payload affiliates obtain initial access through compromised VPN credentials, including access supplied by initial access brokers associated with the FortiBleed campaign against Fortinet FortiGate devices. In an attack against a Middle Eastern manufacturer, Payload obtained domain administrator privileges and abused Active Directory Group Policy Objects linked at the domain root to distribute ransom notes, change desktop wallpapers, deactivate local administrator accounts, and disable Windows Firewall. That operation involved data exfiltration and publication on the dark web without file encryption or deployment of conventional ransomware executables, demonstrating an encryption-less extortion approach alongside its ransomware operations. Payload's ransomware family includes Windows and Linux variants, with the Linux variant targeting VMware ESXi environments. Both use Curve25519 key exchange and ChaCha20 encryption, multithreaded processing, and partial encryption of large files. The ESXi variant enumerates virtual machines, powers them off, and encrypts large virtual disk files. The Windows variant can encrypt local drives and network shares, terminate backup, database, and security services, delete Volume Shadow Copies, disable Event Tracing for Windows, clear event logs, and delete itself. String obfuscation and anti-debugging checks further impede analysis. Encryption and key generation occur locally without requiring an online key-exchange service.
Sandworm is a Russian state-sponsored cyber threat actor associated with the Main Intelligence Directorate (GRU), military Unit 74455. It is also tracked as Sandworm Team, APT44, Voodoo Bear, Seashell Blizzard, IRIDIUM, FROZENBARENTS, TeleBots, BlackEnergy Group, Electrum, Iron Viking, and Blue Echidna. The group conducts destructive and disruptive operations, alongside credential theft, information collection, and data exfiltration. Its documented targets include Ukrainian electricity infrastructure and software providers, Georgian government and non-government organizations, and organizations associated with the 2018 Winter Olympics in South Korea. Sandworm gains access through spearphishing links and malicious Microsoft Office attachments, exploitation of client vulnerabilities, compromised software updates, stolen credentials, and trusted connections between organizations. It compromised the Ukrainian accounting application M.E.Doc to distribute NotPetya through a malicious software update. Its reconnaissance includes vulnerability scanning, employee research, Active Directory enumeration through LDAP, and collection of network diagrams and remote-access information. Credential-harvesting methods include modified Mimikatz tooling, browser-password collection, keylogging, network-traffic interception, and password spraying. The group maintains access through newly created domain accounts, account manipulation, web shells, and backdoored SSH services. It transfers tools through network shares and has distributed Prestige ransomware through Active Directory Group Policy. Its command-and-control infrastructure uses encrypted or encoded communications, proxying, and legitimate services. Defense-evasion behaviors include disabling event logging, deleting attack artifacts, disguising binaries, and executing credential-harvesting tools in memory. Sandworm's destructive operations include NotPetya, Olympic Destroyer, and BlackEnergy's KillDisk component. It has overwritten files and corrupted boot records on industrial systems, maliciously operated electricity breakers using remote administration or industrial-control software, and defaced approximately 15,000 Georgian websites in 2019. It has also stolen internal documents and disseminated sensitive victim information through social media.
Conti was a financially motivated, Russia-associated ransomware syndicate that emerged in 2020 and operated a ransomware-as-a-service ecosystem. Also known as the Conti gang, Conti group, and Conti ransomware group, it supplied ransomware and operational guidance to deployers and maintained relationships with initial access brokers, including EXOTIC LILY. Conti attacked organizations internationally, including U.S. healthcare and emergency-service networks, Ireland's Health Service Executive, and Costa Rican government institutions. By February 2022, reported Conti attacks exceeded 1,000. Conti combined network-wide encryption with data theft and threats of public disclosure. Its operators obtained access through spearphishing, compromised remote-access credentials, malware distribution networks, and exploitation of exposed systems. Attack chains involved malware such as TrickBot, Emotet, and IcedID. After entry, operators used Cobalt Strike, Mimikatz, AdFind, and BloodHound for post-exploitation, credential theft, and Active Directory reconnaissance. They exploited vulnerabilities including Zerologon and PrintNightmare to obtain elevated privileges, used password guessing and Kerberoasting, and moved laterally to enable broad ransomware deployment. Legitimate remote-access applications provided persistent access, while Rclone and cloud storage supported data exfiltration. Operators disabled security and backup services and deleted shadow copies to obstruct detection and recovery. The syndicate also sold access to compromised networks beginning in October 2021. Karakurt functioned as an associated data-extortion operation: when Conti encryption was blocked, attackers could demand payment under the Karakurt brand using information already stolen. Leaks of affiliate documentation in 2021 and internal communications and source code in 2022 exposed substantial operational detail. Conti shut down its branded operation in 2022, while former members continued participating in other cybercriminal operations.
LockBit is a financially motivated ransomware-as-a-service (RaaS) operation active under that name since early 2020, with a lineage extending to ABCD ransomware in 2019. Its core operators develop ransomware and maintain affiliate infrastructure, while affiliates compromise organizations, steal information, and deploy encryptors. The operation typically allocates 80% of ransom proceeds to affiliates and 20% to its operators. LockBit became one of the most prolific ransomware operations and was identified by an international joint advisory as the most active ransomware in 2022. Major ransomware generations include LockBit 2.0, also called LockBit Red; LockBit 3.0, or LockBit Black; and LockBit Green, which incorporated encryption code derived from leaked Conti source code. Its tooling includes encryptors for Windows, Linux, and VMware ESXi, with macOS samples also observed. LockBitSupp is the operation's public representative rather than a separate ransomware family or affiliate group. LockBit affiliates use vulnerability exploitation, compromised remote-access credentials, exposed RDP services, phishing, drive-by compromise, and access purchased from initial access brokers. Documented exploitation includes Citrix Bleed (CVE-2023-4966), PaperCut vulnerabilities, and ConnectWise ScreenConnect vulnerabilities. Citrix Bleed campaigns enabled authentication bypass through compromised sessions, persistent access, and lateral movement. The operation has also recruited insiders to provide corporate credentials or infect employer devices. Affiliates use living-off-the-land techniques, legitimate administration tools, StealBit, rclone, and external file-sharing services for post-compromise activity and data exfiltration. LockBit primarily uses double extortion, combining encryption with threats to publish stolen information, and also supports data-theft-only extortion partners. Its leak infrastructure provides victim-specific countdowns, stolen-data samples, negotiation facilities, and paid publication extensions or data access. Defense-evasion capabilities include disabling security software, Safe Mode execution, anti-analysis measures, and tampering with Windows event-channel access permissions; its ransomware can also delete shadow copies. Documented targeting includes Boeing, Portugal's Port of Lisbon Administration, and nonprofit customers exposed through a compromised managed service provider. A publicly leaked LockBit 3.0 builder enabled unrelated actors to generate working encryptors and decryptors, so use of LockBit-derived malware does not by itself establish affiliation with the operation. Law-enforcement disruption and subsequent compromises reduced LockBit's prominence by the first half of 2025.
NetRunner is a financially motivated cybercriminal threat actor associated with ransomware, data exfiltration, and extortion operations. Its documented targeting includes organizations in Japan, the United States, and Malaysia, spanning healthcare, marine construction and transportation services, and retail. During 2026, its healthcare activity included targeting providers and healthcare-related service organizations, with an emphasis on stealing sensitive information for extortion. NetRunner demanded $100 million from Nippon Medical School Musashi Kosugi Hospital in Japan in an incident affecting 131,700 people; the ransom was not paid. Other attributed victims include Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates, Precon Marine Inc, and Main Place Mall. Its country of origin, organizational structure, initial-access methods, and specific malware tooling are not established.
Xuanye Group is a previously unknown threat actor that claimed responsibility for an October 2026 data breach affecting ASOS, a UK-based online fashion retailer. The group used unauthorized push notifications delivered through ASOS’s own mobile application to demand contact from the company and threaten publication of customer data. It maintained a Telegram channel to publicize its claims and communicate its threats. The ASOS intrusion involved impersonating a trusted contact to obtain an employee’s login credentials. Credentials obtained through the compromised account were subsequently used to access third-party platforms containing customer information. ASOS confirmed exposure of customer names, contact details, and certain non-personal account-related information, while stating that payment-card information and customer account passwords were not accessed. The attackers abused customer-facing messaging infrastructure to publicize the incident directly to customers and pressure the retailer. Xuanye Group’s observed activity centers on credential-based intrusion and threatened data disclosure rather than confirmed ransomware deployment. Its geographic origin, organizational structure, and relationship to other threat actors are not established.
APT38 is a North Korean state-sponsored threat actor active since at least 2014, specializing in financially motivated operations against banks and other financial institutions. Associated tracking names include Bluenoroff, BlueNoroff, Stardust Chollima, and Nickel Gladstone. It shares tools and malware with other North Korean actors, including Lazarus Group and TEMP.Hermit, but is distinguished by its focus on financial theft. Its operations include fraudulent SWIFT transfers, bank fraud, cryptocurrency-exchange intrusions, and cryptocurrency theft. APT38 conducts preparatory reconnaissance of target personnel, infrastructure, and third-party vendors, particularly those connected to SWIFT systems. Documented initial-access methods include watering-hole attacks and exploitation of vulnerable Linux servers. After gaining access, it scans compromised environments, performs internal reconnaissance, and moves toward financial transaction infrastructure. It installs backdoors and reconnaissance malware on SWIFT servers and uses specialized malware to insert fraudulent transactions and manipulate financial data. Its tooling includes Mimikatz for credential theft and NACHOCHEESE for tunneling and remote shell access. Other documented behaviors include keylogging, clipboard collection, command-shell execution, and persistence through Windows services and scheduled tasks. APT38 uses log deletion, file deletion, software packing, and disk wiping to conceal activity and obstruct investigation. It has also deployed Hermes ransomware to encrypt files with AES-256, with encryption and destructive activity used to hinder detection and recovery following financial theft.
Lazarus Group is a North Korean state-sponsored threat actor associated with financially motivated cybercrime, espionage, and destructive operations. Its activities include cryptocurrency theft, attacks against financial institutions, and compromise of software supply chains. Associated tracking names include HIDDEN COBRA, ZINC, Diamond Sleet, Labyrinth Chollima, Nickel Academy, Black Artemis, Guardians of Peace, APT-C-26, Selective Pisces, TA404, and TEMP.Hermit; these designations do not necessarily represent identical operational scopes. APT38 is a separately tracked North Korean financial threat actor whose malware arsenal overlaps with Lazarus and TEMP.Hermit. Lazarus has been associated with the destructive 2014 Sony Pictures Entertainment attack, the 2016 Bangladesh Bank theft involving fraudulent SWIFT transactions, and the 2017 WannaCry ransomware outbreak. More recent targeting includes cryptocurrency companies, cryptocurrency engineers, and aerospace professionals, with individuals targeted to obtain access to their employers’ networks. The group compromised the 3CX software supply chain to distribute trojanized Windows and macOS applications, selectively deploying the modular Gopuram backdoor to cryptocurrency-company victims. Its techniques include spearphishing with malicious Microsoft Word attachments, command-shell execution, reflective DLL injection, and persistence through Windows services and scheduled tasks. Lazarus malware propagates using RDP and attempts lateral movement through Windows shares using generated administrative usernames and weak passwords. Defense evasion includes payload encryption and encoding, malicious templates disguised as images, timestomping, and deletion of malware artifacts. Lazarus uses sophisticated kernel-level evasion. FudModule has exploited CVE-2021-21551 in a legitimately signed Dell driver through bring-your-own-vulnerable-driver techniques to interfere with security callbacks, monitoring, and forensic tracing. The group also exploited the Windows vulnerability CVE-2024-38193 as a zero-day and used FudModule to conceal its activity.
The Com, also known as The Community, is a loosely affiliated, predominantly English-speaking online criminal ecosystem rather than a single centrally directed threat group. It encompasses thousands of participants, commonly teenagers and young adults, with members operating in the United States, United Kingdom, Canada, and other Western countries. Participants form smaller groups that cooperate, compete, and exchange access, tools, and stolen data through platforms including Telegram and Discord. Its activities span financially motivated cybercrime, cryptocurrency theft, extortion, sexual exploitation, and physical violence; no single motivation characterizes the entire community. The ecosystem has three principal subdivisions: Hacker Com, In Real Life Com, and Extortion Com. Scattered Spider is a prominent cybercriminal subset, while BlackFile is an affiliated extortion group operating through the Redact, Pink, Helix, and Falcon brands. Scattered Lapsus ShinyHunters has also operated within the community. The affiliated 764 network and its offshoots, including Harm Nation and 8884, conduct coercive sexual exploitation and abuse, particularly against minors and other vulnerable people. In Real Life Com includes participants offering physical violence for hire. Cybercriminal participants specialize in social engineering, including help-desk impersonation, voice phishing, SMS phishing, SIM swapping, and abuse of password-reset and multifactor-authentication enrollment procedures. These methods enable credential theft, unauthorized access to enterprise identity and cloud services, lateral movement, data exfiltration, and cryptocurrency theft. Associated groups have deployed partner ransomware and conducted extortion involving stolen data. Victims include organizations in technology, telecommunications, hospitality, retail, financial services, healthcare, transportation, logistics, and consumer goods. Some participants intensify extortion through threats against employees and relatives, doxing, swatting, and physical intimidation. These activities vary substantially across the community and should not be attributed uniformly to every member or affiliated group.
Breaches attributed to ransomware activity, most recently reported first.
Check Point reveals coordinated vishing workflow in purported SRG archive
Judge grants one-month delay in Pinhasi case amid plea negotiations
Researchers report FortiBleed credentials chained with FortiSandbox exploitation
State breach filings identify affected residents in three states
Sen. Hassan questions Trump Mobile's security and FCC compliance
WaterISAC publishes Warlock campaign alert detailing SYSVOL ransomware distribution