Ransomware Groups
Ransomware crews run their own extortion sites, and they publish there before anyone tells the victim. We watch 620 of those sites. This page is the reference on the groups behind them — what each one is, what it goes after, and whether it is still running.
What a ransomware leak site is
Most ransomware groups no longer just encrypt files. They copy the data out first, then threaten to publish it. To make the threat credible they run a public extortion site — usually on Tor — where they name the company, count down to a deadline and eventually release whatever they took.
That naming is the moment a breach stops being private. It happens without warning, it is often the first time a victim's customers and suppliers hear anything, and it can precede any regulatory filing by weeks.
How this list is built
Every group here has a leak site we check on a schedule. When one is reachable we record what changed on it and when. When a site stops answering we keep the group and mark it offline, because crews go quiet and come back under the same name more often than they disappear.
Group descriptions are compiled from open reporting; status and timing are ours. Treat a group's own claims about its size with suspicion — several exist mainly to look busy, list the same target twice, or post sandbox runs as victims.
Every group we track
- Mydecryptor5y ago
- N3tworm5y ago
- Nemty5y ago
- Onepercent5y ago
- Prolock5y ago
- Ransom Corp5y ago
- Ranzy5y ago
- Solidbit5y ago
- Vfokx5y ago
- Xinof5y ago
- Zeon5y ago
- 2023lockquiet
- A1projectquiet
- Amnesiaquiet
- Arcanequiet
- Arcrypterquiet
- Astralockerquiet
- Babylockerkzquiet
- Backmydataquiet
- Balletspistolquiet
- Bidonquiet
- Black Witchquiet
- Blackberserkquiet
- Blacksnakequiet
- Buddyransomequiet
- Catbquiet
- Cerberimposterquiet
- Cerbersyslockquiet
- Colossusquiet
- Corequiet
- Cryaklquiet
- Crynoxquiet
- Cryptedpayquiet
- Crysisquiet
- Cs-137quiet
- Cylancequiet
- Darkylockquiet
- Deadbydawnquiet
- Deathgripquiet
- Deathransomquiet
- Deltaquiet
- Desolatedquiet
- Dharmaquiet
- Elcometaquiet
- Elpacoquiet
- Encipheredquiet
- Encrypthubquiet
- Eruptionquiet
- Fakersaquiet
- Farattackquiet
- Fargoquiet
- Faustquiet
- Fivehandsquiet
- Freeworldquiet
- Frozenquiet
- Fusionquiet
- Gangbangquiet
- Gazpromquiet
- Ghostquiet
- Globequiet
Common questions
How many ransomware groups are there?
More than most lists suggest, and the number moves constantly. We track over six hundred distinct leak sites, but only a fraction are publishing at any given time. Crews rebrand after law-enforcement action, split into affiliates, and reappear under new names, so a count is a snapshot rather than a fact.
What does it mean when a leak site is offline?
Usually less than people hope. Sites go down for infrastructure trouble, deliberate quiet periods, or a takedown — and many come back weeks later under the same name. We keep the group listed and record the status rather than deleting the entry.
Does a group appearing here mean it is currently active?
No. This is the full list of leak sites we track, including dormant and defunct ones. Filter to sites that are responding, or sort by recent activity, to see who is actually moving.
Where do the group descriptions come from?
Public reporting and vendor research, compiled per group. They describe how a crew has historically operated, so they can lag its current behaviour. Live status and timing come from our own checks.
Can I be told when a specific company appears on one of these sites?
Yes, and that is what SINON is for. You give it the names, domains and suppliers you care about, and it watches these sites and other sources for them continuously instead of you refreshing a page.
Find out before the countdown starts
This page tells you who is out there. SINON watches these same sites for your company, your domains and your suppliers, and tells you the moment one of them appears.