Wednesday, July 3, 2024
Are You Trollin Me?
/Conti_Royal_BlackSuit/
Wednesday, January 17, 2024
Where Are They Now?
The Conti Boys
Royal on The Run
100 Days Without Fam
| Karakurt Team in high level discussions. |
Black Byte Bitten
Akira Ransomware
Black Basta
Sunday, April 23, 2023
Top 10 All Time Active Ransomware Groups
The Current Top 10 Active Ransomware Group Post Count
By Dominic Alvieri
April 23rd, 2023
Quantifying ransomware group activity over the past few years there is no doubt that LockBit is the numerical leader all credibility issues aside. LockBit averages posting over one company per day since their initial formation as ABCD. No one else comes close.
Conti members are still around but this list comprises of active groups with quantifiable active leak sites.
Posts that are somewhat quantifiable...
Up and Coming Groups
New groups in 2023
Most Dangerous Groups
Friday, March 17, 2023
SpaceX Contractor Allegedly Breached
LockBit leaves a message for Elon Musk
LockBit message to Elon in the post below.
What is it worth?
Mutual non-disclosure agreement
What happens when a ransomware group discloses an NDA?
Friday, February 3, 2023
I Can Name That Exploit in One Note
Another New Day and Another New Way...
Redacted
Monday, January 30, 2023
Undisputed LockBit
LockBit is clearly the leading group left standing...for now.
By Dominic Alvieri
January 30th, 2023
In the early morning hours of Thursday, January 26th a multi-governmental offensive seized the Hive Ransomware leak site. No arrests have been made in the never ending ransomware whack-a-mole game. LockBit is now the undisputed leading ransomware operation.
That evening LockBit was ready with a new game, comments and plenty of leaks ready to go. The Hive Ransomware leak site was seized early Thursday morning and the first comment or post from LockBit was a freaking game below.
The post above was removed by LockBit. Researchers at VX Underground were able to get a comment from Mr. LockBit about the post and the news that followed. LockBit is one group I do not have communications with and do not care to.
By Sunday evening it was business as usual as LockBit posted affiliate offerings of 14 new victims not willing to pay them from around the world.
Spain
France
Mexico
Austria
Albania
Portugal
Australia
United States
United Kingdom
Low lights from the new posts include PBS member television station KVIE in Sacramento, California, Air Albania, CPL Industries...
LockBit is clearly the top operation remaining and is arrogantly making it known. Alphv Black Cat Ransomware is behind LockBit and there is a clear distinction from the remaining groups including new up and coming Play Ransomware, Black Basta, Vice Society...
Several other groups and former members are not included in this article including Black Matter, DarkSide and the other variations, spinoffs and new groups pending like Endurance Ransomware.
No Hive arrests to date.
Affiliates have to go somewhere...
The never ending ransomware whack-a-mole game continues in 2023.
The Cyber Show
Thursday, September 8, 2022
Los Angeles School District Claimed by Vice Society
Ransomware Roundup
Everest v Brazil?
| photo courtesy @darktracer_int Twitter |
Ragnar v Air Portugal?
Going Backwards, the LockBit Tattoo
Vice Society
![]() |
| New Vice Society alternate logo. You're welcome. |
Cl0P
The Kremlin, Politics and Ransomware
Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...
-
Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...
-
The Conti Boys By Dominic Alvieri 1/14/2024 @AlvieriD Ransomware groups have come and gone but few have continued to resonate across the cr...
-
Seek deep and ye shall find by Dominic Alvieri February 1st, 2025 @AlvieriD Malware, credential phishing, fake meme coins, exposed data... ...







