6 активных и архивных групп в базе.
Exploits Fortinet and Exchange vulnerabilities; no public leak site, direct negotiation only.
First major Rust-based ransomware; FBI disruption reduced operational tempo in 2024.
Specializes in mass exploitation of file transfer zero-days for bulk data theft.
Emerging group targeting SMBs with double extortion and ESXi-focused encryption.
Former Conti splinter group; operations wound down after leadership arrests.
Dominant RaaS ecosystem with leak site and automated negotiation portal.