A
Akira 1988 cyberpunk anime — the cultural reference for the Akira ransomware group
Active
Group 01 / RaaS
Akira
Active since 2023. Double-extortion RaaS targeting SMBs and enterprise. Retro terminal DLS aesthetic. Linked to former Conti affiliates.
View Profile
C
Conti ransomware group logo and branding
Defunct
Group 02 / RaaS
Conti
Dissolved 2022 following internal leaks. Russia-linked, FSB-connected. Parent organization to multiple successor groups including Black Basta, Royal, and Akira affiliates.
View Profile
BB
Black Basta data leak site victim listing page showing victim names and countdown timers
Inactive
Group 08 / Closed RaaS
Black Basta
Conti Team 3 direct successor. Active Apr 2022-Jan 2025. $107M+ confirmed revenue, 500+ victims. Collapsed following internal chat leak and leadership conflict.
View Profile
D
DragonForce cartel model announcement — the group's shift to a ransomware cartel structure
Active
Group 03 / RaaS Cartel
DragonForce
Active since 2023. Pioneered a ransomware cartel model offering white-label infrastructure to affiliates. Malaysia-linked leadership. Expanding rapidly in 2025.
View Profile
LB
LockBit infrastructure seized — Operation Cronos NCA takedown notice, February 2024
Disrupted
Group 04 / RaaS
LockBit
Largest RaaS operation globally. Infrastructure seized Feb 2024 (Operation Cronos). Administrator indicted. Attempted reconstitution under LockBit 4.0.
View Profile
L
Lynx ransomware logo — stylized shield bearing a lynx head silhouette in white on black, as used on the group's data leak site
Active
Group 05 / RaaS
Lynx / INC
Emerged 2024, absorbed INC Ransom operations. Double-extortion model with aggressive victim naming. Targeting critical infrastructure sectors.
View Profile
Q
Qilin ransomware group logo
Active
Group 06 / RaaS
Qilin
Active since 2022. GoLang-based encryptor. Aggressive healthcare sector targeting. Claimed NHS vendor breach (2024) exposing 300M+ patient records.
View Profile
R
Operation Checkmate seizure banner on the BlackSuit ransomware data leak site
Disrupted / Rebranded
Group 07 / Private → RaaS
Royal / BlackSuit / Chaos
Conti Team One lineage. $500M+ in demands. Disrupted by Operation Checkmate (Jul 2025). Assessed rebranded as Chaos RaaS (Feb 2025). Three-generation rebrand chain with no public arrests.
View Profile
C
Cl0p Linux ELF ransomware variant — SentinelOne Labs technical analysis header image
Active
Group 09 / Data Extortion
Cl0p
Active since 2019. FIN11/TA505 core. Mass MFT exploitation specialist: GoAnywhere, MOVEit, Cleo, Oracle EBS. 1,000+ victims. No confirmed arrests of core leadership.
View Profile
SR
Silent Ransom Group Luna Moth branding — SOCRadar 2024
Active
Group 10 / Callback Phishing
Luna Moth / SRG
Active since 2021. No encryption — pure data extortion via callback phishing. Rebranded as Luna Moth (2022). Targets legal, financial, and professional services sectors.
View Profile
TG
The Gentlemen ransomware group branding and data leak site — Check Point Research, April 2026
Active
Group 11 / RaaS
The Gentlemen
Qilin splinter, active since mid-2025. 420+ claimed victims across 50+ countries. 90/10 affiliate split. Go-based encryptor. Tracked by Microsoft as Storm-2697.
View Profile
NS
NightSpire team logo — AhnLab ASEC threat intelligence observation, 2025
Active
Group 12 / RaaS
NightSpire
Active since Feb 2025. Double extortion, transitioning to full RaaS. 259+ victims across 30+ countries. Predecessor to Rbfs. No confirmed law enforcement action.
View Profile
PL
Active
Group 13 / RaaS (unverified)
Payload
Babuk-derived ransomware that emerged February 2026. Double extortion against Windows and VMware ESXi; data exfiltrated before encryption, victims pressured via a Tor negotiation portal. Claimed the Royal Bahrain Hospital breach.
View Profile
WL
Active
Group 14 / Data Extortion (EaaS)
World Leaks / Hunters Intl
Launched on or about 1 January 2025 as the rebrand of Hunters International (Hive lineage). Pure data-extortion / extortion-as-a-service model; Group-IB assesses Hunters as a Hive successor with moderate confidence.
View Profile