Critical · active
LockBit 4.0
Most active RaaS against European markets. Double extortion, VPN/RDP exploits, aggressive lateral movement.
Critical · 9.8%
RansomHub
RaaS since 2024. 9.8% globally. Targeting critical infrastructure, healthcare, finance, government.
Closed RaaS
Play
Closed group, no public negotiation. Targeting manufacturing, government, transport, legal.
Linux + Windows
Akira
Double extortion, ransomware Linux + Windows + ESXi. Targeting SMEs, education, hospitality.
Ex-Conti
Black Basta
Conti heirs. QakBot distributor. Targeting healthcare, manufacturing, construction, finance.
Supply chain
Cl0p
Zero-day specialist: MOVEit, GoAnywhere, Accellion. Supply chain attacks on finance, healthcare, legal.
Active
Medusa
Public blog with countdown. Targeting education, public sector, manufacturing, healthcare.
VMware ESXi
Qilin · Agenda
Go & Rust, VMware ESXi. Targeting healthcare, critical infrastructure, manufacturing.
SME focus
8Base
Phobos-based. Targeting SMEs, construction, retail, transport.
Ex-Hive
Hunters Int.
Ex-Hive members. Data-theft focus: manufacturing, finance, logistics.
Public auctions
Rhysida
Public auctions of stolen data. Targeting public sector, healthcare, education, defence.
Triple extortion
BlackCat / ALPHV
Rust-based. Triple extortion (encryption + leak + DDoS). Healthcare, energy, manufacturing, finance.