Ransomware & Threat Intelligence Radar

Surveillance of active ransomware syndicates, confirmed victim disclosures, and actively exploited vulnerabilities (CISA KEV).

LockBit 3.0 (Black)ONLINE
Darknet Status:Active on 4 Mirrors
Average Ransom:$2.8M USD
Encryption Type:Curve25519 + AES-128 in CTR mode
Total Leaked Victims:184 companies
Frequently Targeted Sectors
HealthcareManufacturingGovernment Contractors
Observed Tactic:Persistent affiliate ecosystem operating automated extortion portals with automated proof-of-leak generation.
BlackCat (ALPHV)INTERMITTENT
Darknet Status:Tor Circuit Congestion
Average Ransom:$3.4M USD
Encryption Type:ChaCha20-Poly1305 with per-victim public keys
Total Leaked Victims:96 companies
Frequently Targeted Sectors
Financial ServicesDefense LogisticsEnergy Grids
Observed Tactic:Highly structured syndicates deploying triple-extortion schemes including DDoS and customer notification harassment.
Akira SyndicateONLINE
Darknet Status:Active on Tor & I2P
Average Ransom:$1.6M USD
Encryption Type:RSA-4096 + ChaCha20
Total Leaked Victims:142 companies
Frequently Targeted Sectors
SME ManufacturingEducationLegal Networks
Observed Tactic:Specializes in exploiting legacy VPN appliances and Cisco Adaptive Security Appliances lacking multi-factor enforcement.
Play RansomwareONLINE
Darknet Status:Active Onion Gateway
Average Ransom:$1.9M USD
Encryption Type:Custom AES-RSA Hybrid
Total Leaked Victims:118 companies
Frequently Targeted Sectors
Automotive SupplyMunicipalitiesIT Service Providers
Observed Tactic:Known for custom tools like PlayCrypt and exploitation of ProxyNotShell and Fortinet SSL-VPN weaknesses.
RansomHubONLINE
Darknet Status:Fully Operational
Average Ransom:$4.2M USD
Encryption Type:XChaCha20 + Kyber Post-Quantum Draft
Total Leaked Victims:79 companies
Frequently Targeted Sectors
Critical InfrastructureHealthcare NetworksCloud SaaS
Observed Tactic:Emergent syndicate recruiting former ALPHV affiliates with aggressive 90% payout commission structures.
Medusa LockerONLINE
Darknet Status:Active Extortion Channel
Average Ransom:$950K USD
Encryption Type:AES-256 + RSA-2048
Total Leaked Victims:63 companies
Frequently Targeted Sectors
School DistrictsLocal GovernmentHospitality
Observed Tactic:Utilizes public Telegram disclosure channels alongside Tor leak blogs with live auction bidding options.