Threat library
Ransomware family library
Profiles of the families we see most often in China plus the globally active ones: identification markers, encryption behavior, an honest recoverability assessment and what to do next. Identify the family first, then decide how to recover.
70 families matched
More common in China (endpoints / servers)17
The families we handle most in Chinese enterprise environments. They usually get in through RDP brute force, weak database credentials or an exposed edge device, and go straight for file servers and production databases.
LockBit
Some versions decryptable.abcd .lockbit .lockbit3
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
Recent activityPhobos
Free decryptor available.phobos .eking .faust
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
Recent activityMallox
Some versions decryptable.mallox .malox .mallab
Mallox (also known as TargetCompany) breaks in mainly through brute-forced MS SQL Server credentials, targets database servers specifically, and has a Linux/ESXi variant. Files encrypted between 2023 and early 2024 may be decryptable with Avast's free tool; later builds have no public decryption method.
Recent activityTellYouThePass
No public decryptor.locked .locked1 .sorry
TellYouThePass is the archetypal vulnerability-driven ransomware family in China, mass-deployed against internet-facing ERP, OA, finance and middleware systems. It appends .locked and hits both Windows and Linux servers. No public decryptor exists.
Recent activityBeijingCrypt
No public decryptor.beijing .360 .520
BeijingCrypt takes its name from the .beijing extension used by early builds. It is a persistently prevalent family in China, deployed by hand after brute-forcing remote desktop or database credentials, and has cycled through .beijing, .360, .520, .halo and .bixi variants. No public decryptor exists.
Recent activityMakop
No public decryptor.makop .mkp .baseus
Makop has operated as a RaaS since 2020, with affiliates breaking in mainly through brute-forced remote desktop credentials and deploying by hand. Extensions include .makop, .mkp and .baseus, with a readme-warning.txt note. It ranks consistently high in Chinese infection statistics and has no public decryptor.
Recent activityWannaCry
Some versions decryptable.WNCRY .WCRY .WNCRYT
WannaCry is the ransomware worm that spread worldwide in May 2017 by exploiting the EternalBlue SMB vulnerability (MS17-010), appending .WNCRY. The original campaign is long over, but unpatched legacy networks still get hit by residual samples that continue to spread automatically.
GlobeImposter
Some versions decryptable.Dragon4444 .Snake4444 .Rat4444
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
Recent activityCrysis / Dharma
Some versions decryptable.cezar .arena .bip
Crysis (CrySiS) and its successor Dharma have been active since 2016, breaking in through brute-forced RDP and spawning many variants including .cezar, .arena, .bip, .combo and .java. Early versions have free decryptors; the .cezar family from 2017 onward does not.
Recent activitySTOP / Djvu
Some versions decryptable.djvu .rumba .radman
STOP/Djvu is one of the highest-volume ransomware families worldwide, infecting individuals and micro-businesses mainly through software cracks, activators and game cheats. Extensions are typically four random lowercase letters and the note is _readme.txt. Files encrypted with an offline key can be decrypted free with Emsisoft's tool.
Currently dormantRecent activityWeaxor
No public decryptor.rox .weax .wxx
Weaxor emerged in late 2024 as a same-lineage successor to Mallox, continuing its focus on MS SQL Server and exposed web services. It appends .rox, .weax or .wxx and drops a RECOVERY INFO.txt note. It has led infection volume in China through 2025 and 2026 (45.45% in July 2026, 65.74% in August 2026) and has no public decryptor.
Recent activityQilin
No public decryptor.qilin .[受害者专属随机字符串]
Qilin (formerly Agenda) is a Rust-rewritten cross-platform RaaS operation focused on VMware ESXi and Linux estates. It has ranked as the world's most active ransomware group for several consecutive quarters since 2025, with confirmed victims among electronics manufacturers in Taiwan and Hong Kong.
Recent activityBrzCrypt
No public decryptor.brz .flex .(__{ID}__).(__{email}__).brz
BrzCrypt surfaced in late May 2026 and, so far, spreads only inside China. It appends .brz or .flex and drops an information.html note. The crew behind Wmansvcs launched it after 360 broke their previous locker; entry is RDP brute force followed by lateral movement, and no free decryptor exists.
Actively operatingRecent activitySorry
No public decryptor.sorry
Sorry is a Go-based Linux ransomware that broke out in 2026, mass-deployed through the cPanel/WHM authentication bypass CVE-2026-41940. It appends .sorry, drops a README.md note in every directory and negotiates only over Tox. Attribution is contested: AsiaInfo and some Chinese responders treat it as a new TellYouThePass variant, while China's CVERC and Western researchers treat it as a new family that appeared in 2026.
Actively operatingRecent activitySnowSoul
Some versions decryptable.snowsoul .qinglong .[5位随机字符(0-9 与 a-z)]
SnowSoul is a China-focused ransomware family that surfaced in September 2025. It combines AES-CBC with RSA-2048 and has used .snowsoul, .qinglong and 5-random-character extensions. 360 built a decryptor covering some versions, and variants resumed spreading domestically from July 2026.
Back in actionRecent activityGoodLock
No public decryptor.goodLock
GoodLock is a low-volume Windows encryptor, captured by Antiy in September 2025 and listed by 360 as a newly seen family in June 2026. It appends .goodLock and drops ___RECOVER__FILES__.goodLock.txt. A traditional encrypt-only family with no leak site, very little public record, and no free decryptor.
Newly emergedRecent activityWmansvcs
Some versions decryptable.wman .peng .[[设备ID]].[[攻击者邮箱]].wman
Wmansvcs appeared in June 2025 and ranked among China's most-seen ransomware families for a stretch. It is marked by .wman / .peng extensions and a DECRYPTION_INFORMATION.html note, spreads through RDP brute force with hands-on deployment, and carries a keystream-reuse flaw that free decryptors exploit under conditions. After the break the crew rebranded as BrzCrypt.
RebrandedRecent activity
Leak-site regulars worldwide15
International crews run as ransomware-as-a-service that keep a running victim list on their dark web leak site. Most steal data before encrypting, and virtualization platforms are a priority target.
Akira
Some versions decryptable.akira .powerranges .akiranew
Akira is a ransomware-as-a-service operation that emerged in March 2023, breaking in through VPNs without MFA and edge-device flaws, then encrypting Windows estates and VMware ESXi clusters under double extortion. CISA's November 2025 advisory update calls it an imminent threat to critical infrastructure.
Recent activityPlay
No public decryptor.play .PLAY
Play (PlayCrypt / Balloonfly) has been active since June 2022 and is one of the few closed-group ransomware operations, recompiling its encryptor for every victim. It targets FortiOS and Exchange flaws, RDP and VPN, and maintains a dedicated ESXi encryptor. CISA counted roughly 900 victims as of May 2025, and public leak-site trackers list over 1,200 entries as of September 2026.
Recent activityMedusa
No public decryptor.MEDUSA .medusa
Medusa appeared in June 2021 and shifted to a ransomware-as-a-service model from 2023, using the .MEDUSA extension and !!!READ_ME_MEDUSA!!!.txt note. It specialises in exploiting remote-management and file-transfer components such as ScreenConnect, Fortinet EMS and GoAnywhere, and applies pressure through a countdown clock with paid extensions.
Recent activityClop
Some versions decryptable.clop .C_L_O_P
Clop (CL0P) has been active since February 2019 and is linked to TA505 and FIN11. It is known for mass zero-day exploitation of enterprise file-transfer, ERP and PLM platforms such as Accellion, GoAnywhere, MOVEit, Oracle E-Business Suite and PTC Windchill, and since 2021 has primarily run data-theft extortion without encrypting files.
Recent activityRhysida
Some versions decryptable.rhysida
Rhysida is a RaaS operation active since 2023, marked by the .rhysida extension and a CriticalBreachDetected.pdf ransom note. It hits healthcare, education, manufacturing and government, ships an ESXi encryptor, and a subset of early Windows samples can be recovered with a free decryptor.
Recent activityDragonForce
No public decryptor.dragonforce_encrypted .df_win .[9位随机字符]
DragonForce is one of the most active ransomware cartels today. Since 2025 it has offered white-label encryptors and infrastructure to affiliates, hits virtualisation estates hard, and became widely known through the chain of UK retail attacks. No public decryptor exists.
Recent activityINC Ransom
No public decryptor.INC .inc
INC Ransom emerged in 2023 and has passed 800 claimed victims by 2026, making it a top-tier RaaS operation. Marked by the .INC extension and INC-README notes, it exploits Citrix and SonicWall edge flaws and ships an ESXi encryptor. No public decryptor exists.
Recent activityLynx
No public decryptor.LYNX .lynx
Lynx is a RaaS operation that emerged in mid-2024 and shares extensive code with INC Ransom. It ships encryptors for Windows, Linux and ESXi through an affiliate panel with an 80/20 split and had passed 400 claimed victims by 2026. No public decryptor exists.
Recent activityInterlock
No public decryptor.interlock .1nt3rlock
Interlock emerged in September 2024 as a double-extortion crew marked by .interlock / .1nt3rlock extensions and the !__README__!.txt note. It relies on drive-by downloads, ClickFix fake-CAPTCHA social engineering and edge-device zero-days, and was covered by a CISA #StopRansomware advisory in 2025. No public decryptor exists.
Recent activitySafePay
No public decryptor.safepay
SafePay emerged in late 2024 and rose sharply through 2025-2026 as a closed, non-RaaS crew. Marked by the .safepay extension and readme_safepay.txt note, it enters mainly through valid credentials on VPN gateways and has passed 500 claimed victims. No public decryptor exists.
Recent activityThe Gentlemen
Some versions decryptable.umc16h .[6位字符]
The Gentlemen is a RaaS operation that surfaced in mid-2025 and reached the top tier of global ransomware activity in 2026. It is marked by README-GENTLEMEN.txt notes and a six-character extension (.umc16h in the publicly analysed build), ships Windows and Linux/ESXi lockers, and combines self-propagation with an in-house EDR-killing framework.
Actively operatingRecent activityDireWolf
No public decryptor.direwolf
DireWolf (Dire Wolf) is a Go-based ransomware crew that surfaced in May 2025, marked by the .direwolf extension and a HowToRecoveryFiles.txt note. It runs double extortion from a Tor leak site, ships a Windows-only encryptor, and encrypts just the first 1 MB of files larger than 1 MB - which leaves real repair space for databases and virtual disks.
Actively operatingRecent activityKryBit
No public decryptor.KRYBIT
KryBit is a cross-platform RaaS operation launched in late March 2026 with an 80/20 affiliate split. Its builders cover Windows, Linux, VMware ESXi and NAS, append a fixed .KRYBIT extension and drop a RECOVER-README.txt note. It steals data before encrypting, and no free decryptor exists.
Actively operatingRecent activityEverest
No public decryptor.everest .EVEREST
Everest is a Russian-speaking closed crew active since December 2020, marked by the .everest extension and an EVERESTRANSOMWARE.txt note. It also sells network access and openly recruits corporate insiders, and many recent cases involve data theft with no encryption at all. No public decryptor exists.
Actively operatingRecent activityMetaEncryptor
No public decryptorMetaEncryptor is a double-extortion crew that has run a dark-web leak site since August 2022. Its encryptor shares lineage with SFile2, and the gang rebranded as LostTrust in late 2023 - yet the original site was never abandoned and has kept posting victims at a low rate through 2026. Public technical data is thin: no confirmed extension, note filename or decryptor.
Actively operatingRecent activity
Emerging or resurgent in recent months23
Families that have just appeared or come back after a quiet spell. Their samples and tooling are still changing quickly and public research is thin, so have a sample identified before you act.
JadePuffer
No public decryptor.locked
JadePuffer is the operation Sysdig disclosed in July 2026 and described as the first fully documented case of agentic ransomware. An LLM-driven agent moved from a Langflow flaw into an Alibaba Nacos configuration centre, then deployed the Go payload ENCFORGE (.locked) against AI model weights and training data.
Newly emergedRecent activityDeadLock
No public decryptor.dlock .[十六进制受害者ID].dlock
DeadLock is an emerging ransomware operation first seen in July 2025, marked by the .dlock extension, negotiation over the Session messenger and decentralised infrastructure hosted on Polygon smart contracts. It runs a Rust encryptor with double extortion and had listed more than a hundred victims by September 2026. No public decryptor exists.
Newly emergedRecent activityStorm
No public decryptorStorm is a ransomware brand that surfaced in August 2026, running a Tor leak site called Storm Blog. It named around 50 organisations in roughly five weeks - mostly manufacturing, healthcare and financial services, predominantly in the United States with cases in Canada, Australia and Germany - leaning on stolen-data pressure. Public technical material is scarce and no decryptor exists.
Newly emergedRecent activityPanzer
No public decryptorPanzer is an emerging ransomware-as-a-service operation first seen in August 2026, advertising encryptors for Windows, Linux, VMware ESXi and FreeBSD and running a steal-then-encrypt double-extortion model. Payload-level detail remains scarce and no free decryptor exists.
Newly emergedRecent activityAuditTeam
No public decryptorAuditTeam is an emerging data-extortion crew active since February 2026 that dresses its demands in audit-and-remediation language and pressures victims through a Tor leak site. No encryptor sample is public, so response centres on exposure assessment, credential rotation and breach notification.
Newly emergedRecent activityEmperador
No public decryptorEmperador is an emerging crew that first appeared on a dark-web leak site in August 2026. It runs a ransomware-as-a-service affiliate programme, steals data before encrypting, and named more than a dozen government, energy, manufacturing and education victims in its first month. No public analysis of its locker exists yet.
Newly emergedRecent activityFulcrumSec
No public decryptorFulcrumSec is a data-theft extortion crew that surfaced in September 2025. It deploys no encryptor, changes no extensions and causes no outage - it harvests leaked API keys and cloud misconfigurations, then squeezes victims through staged publication on its leak site.
Newly emergedRecent activityPayload
No public decryptor.payload
Payload is an emerging double-extortion family that surfaced in February 2026. Built on leaked Babuk source, it marks files with .payload and drops RECOVER_payload.txt, ships both Windows and ESXi encryptors, and has no public decryptor.
Newly emergedRecent activityAPT73
No public decryptorAPT73 - later operating as Bashe, earlier known as Eraleig / Eraleign - is a data-extortion crew that surfaced in April 2024 with a leak site imitating LockBit. It is best known for claiming breaches it did not carry out and republishing recycled leak data; no encryptor sample or file extension has ever been documented publicly.
Actively operatingRecent activityLamashtu
No public decryptorLamashtu is a data-theft extortion crew that became publicly visible in April 2026, pressuring victims through staged disclosure on a Tor leak site and threats of regulatory penalties. Its ransom note claims encryption, but no encryptor or file extension has ever surfaced in public analysis. Its last listing dates to June 2026 and the group is currently quiet.
Currently dormantRecent activitySettra
No public decryptorSettra is an extortion crew that surfaced in June 2026, negotiating over Tox and publishing long-form, expose-style victim write-ups on its Tor leak site. It has named roughly 64 organisations in three months. No encryptor sample has been publicly analysed and no decryptor exists.
Newly emergedRecent activityAurora
No public decryptorAurora (Aur0ra) is an emerging double-extortion crew that surfaced in late April 2026. Its most unusual trait is that encrypted files keep their original names with no extension appended, leaving only !!!README!!!DO_NOT_DELETE.txt behind. It ships Windows and Linux/ESXi encryptors with configurable partial encryption, and no public decryptor exists.
Newly emergedRecent activityNightSpire
No public decryptor.nspire
NightSpire is an emerging double-extortion crew active since February 2025, marked by the .nspire extension and a readme.txt note. It breaks in mainly through Fortinet appliance flaws and weak RDP, sets deadlines as short as 48 hours, and has no free public decryptor.
Newly emergedRecent activityVexy
No public decryptorVexy (written as New Vexy by some feeds) is an emerging extortion crew that surfaced in early September 2026. It runs its own Tor leak site and pressures victims with full-leak threats, mostly IT service and hosting providers and manufacturers in India and Latin America. Public technical data is minimal: no confirmed extension, note or decryptor.
Newly emergedRecent activityWallstreet
No public decryptorWallstreet is an emerging extortion crew that surfaced in mid-2026. It runs its own Tor leak site, negotiates over Tox, and mostly names US county hospitals, small manufacturers and local public bodies. Public technical data is minimal: no confirmed extension, ransom note or decryptor.
Newly emergedRecent activityChaos
No public decryptor.chaos
Chaos is a cross-platform ransomware-as-a-service crew that surfaced in February 2025 and is assessed by Cisco Talos, with moderate confidence, to be a regrouping of former BlackSuit (Royal) members. It appends .chaos, drops README.chaos.txt, breaks in through Teams vishing, and layers DDoS threats on top of encryption and leak-site extortion.
Back in actionRecent activityAnubis
No public decryptor.anubis
Anubis is a RaaS operation that surfaced in December 2024, marked by the .anubis extension and a RESTORE FILES.html note. Its defining feature is a built-in /WIPEMODE that permanently zeroes file contents; 2026 attacks on an Adriatic port authority and Coca-Cola's Fairlife brought it mainstream attention.
Newly emergedRecent activityGunra
Some versions decryptable.ENCRT .CRYPT .GNRA
Gunra is a double-extortion family that surfaced in April 2025, built on the leaked Conti source code. Its Windows encryptor appends .ENCRT and drops R3ADM3.txt; a Linux variant (.GNRA) encrypts without leaving a note. It turned RaaS in January 2026 and was named in a US-Korea joint advisory that August.
Newly emergedRecent activityGlobal Secret Group
No public decryptorGlobal Secret Group (GSG) is an emerging data-extortion crew that surfaced in late July 2026. It steals corporate documents, contracts and HR records and pressures victims through staged publication on a Tor leak site. No decryptor exists and sample-level intelligence is scarce.
Newly emergedRecent activityEclipse
No public decryptorEclipse is a ransomware-as-a-service family that surfaced in August 2026. Its operators advertise coverage of Windows, Linux, NAS, VMware ESXi and Hyper-V with double extortion, but sample-level public research remains very limited.
Newly emergedRecent activitySpace Bears
Some versions decryptable.id[8位ID-4位版本].[联系邮箱].faust .faust
Space Bears is a double-extortion leak-site brand launched in April 2024 and attributed by public research to Phobos/Faust affiliates. Its encryptors carry Phobos hallmarks - info.hta notes and long id[...] extensions - and its victims are mostly small and mid-sized firms in the US and Europe.
Actively operatingRecent activityCMD Organization
No public decryptorCMD Organization is a new extortion crew tracked publicly since May 2026. It styles itself a corporate security and vulnerability company while stealing data and deleting victims' file storage, then auctioning the data on its Tor leak site. Public technical detail is limited and no encryptor sample has been analysed.
Newly emergedRecent activityM3RX
No public decryptor.8hmlsewu
M3RX is an emerging double-extortion crew that began naming victims on its Tor leak site in April 2026. Its Go-based Windows encryptor renames files to random characters plus .8hmlsewu, drops RECOVERY_NOTES.TXT and negotiates only through a Tor chat portal and Tox. No free decryptor exists.
Newly emergedRecent activity
Data theft only, no encryption5
Groups that steal data and threaten to publish it without encrypting anything. The files themselves may be intact; the risk is disclosure and compliance, so response focuses on attribution and scoping the exposure.
PEAR
No public decryptorPEAR (Pure Extraction And Ransom) is a data-theft-only extortion crew that surfaced in mid-2025. It openly states that it does not encrypt systems, relying entirely on stolen data and a Tor leak site for leverage; roughly 90% of its victims are US-based, concentrated in business services, healthcare, legal and education.
Actively operatingRecent activitySilent Ransom Group
No public decryptorSilent Ransom Group (Luna Moth, Chatty Spider, UNC3753) is a Conti-lineage crew that extorts without encrypting anything. Operators impersonate an internal IT helpdesk by phone, walk staff into a remote-access session, take documents out, then press with a clearnet leak site and calls to employees. The FBI flagged in-person intrusions with USB storage in both May 2025 and May 2026.
Actively operatingRecent activityShinyHunters
No public decryptorShinyHunters (ShinyCorp, UNC6240, Bling Libra; MITRE ATT&CK G1057) has run data-theft extortion since 2019 without ever encrypting a file. Operators use voice phishing and stolen SaaS OAuth tokens to pull data out of Salesforce, Snowflake and Databricks, then press with a Tor leak site and a 72-hour bitcoin deadline. Victim postings continued through 2026.
Actively operatingRecent activityScattered LAPSUS$ Hunters
No public decryptor.[8位随机字符]
Scattered LAPSUS$ Hunters (SLSH) is a data-theft extortion alliance that formed on Telegram in August 2025 from ShinyHunters, Scattered Spider and LAPSUS$ members. It breaches Salesforce, Okta and Snowflake tenants at scale through vishing, insider recruitment and OAuth token abuse. Its own encryptor, ShinySp1d3r, was announced in November 2025 and samples have been analysed, but no deployment at scale has been confirmed as of September 2026.
Actively operatingRecent activityWorld Leaks
No public decryptorWorld Leaks is the extortion-only brand Hunters International adopted in January 2025: no encryptor, no renamed files, just data theft backed by a Tor leak site. No new victims have been posted since late July 2026 and the leak site has been unreachable, so the operation currently looks dormant.
Currently dormantRecent activity
Mobile2
Screen-locking and extortion malware targeting Android and iOS, usually spread through third-party app stores, repackaged installers and SMS links.
Mantax Otax
No public decryptor.enc
Mantax Otax is an Android ransomware family disclosed in September 2026 that bundles file encryption, screen locking and spyware into one APK. It appends .enc to encrypted files while stealing OTPs, contacts, photos and chat histories, then pressures victims with exposure and harassment. No public decryptor exists.
Newly emergedRecent activityGoldFactory
No public decryptorGoldFactory is a Chinese-speaking mobile financial-crime group whose Android and iOS trojans - Gigabud, GoldPickaxe and GoldDigger - steal facial biometrics, ID photos and banking credentials to carry out fraudulent transfers. It encrypts nothing and drops no ransom note, so it is a fundamentally different threat from encryption ransomware.
Actively operatingRecent activity
Older families that still shape the ecosystem8
Operations that have disbanded, been disrupted by law enforcement or rebranded, yet whose leaked builders and source code are still reused. Historical samples keep causing infections today.
BlackCat
No public decryptor.[7位随机字符]
BlackCat (ALPHV) was the first major Rust-based ransomware-as-a-service operation, active from November 2021. It seized accounts through help-desk social engineering, encrypted ESXi and Windows estates under double extortion, and shut down in a March 2024 exit scam after keeping the Change Healthcare ransom — its key infrastructure no longer exists.
Recent activityRansomHub
No public decryptor.[6位随机字符]
RansomHub launched in February 2024 as a rebrand of Knight/Cyclops and rapidly absorbed affiliates from ALPHV and LockBit with a 90% revenue share, accumulating hundreds of victims within a year. Its infrastructure went offline in early April 2025 and the operation has been dormant since, with affiliates largely migrating to Qilin and DragonForce.
Operation shut downRecent activityBlack Basta
Some versions decryptable.basta .[随机字符]
Black Basta was a Conti-derived RaaS operation that emerged in April 2022 and affected more than 500 organisations, known for QakBot delivery and Microsoft Teams IT-impersonation social engineering. It disbanded in February 2025 after its internal chat logs leaked, though its tradecraft carried over to successors such as Cactus.
Operation shut downRecent activityBabuk
Some versions decryptable.babuk .babyk .babuk2
Babuk (Babyk) was an early double-extortion family from 2021 whose Windows, ESXi and NAS source code and builder leaked, seeding a large share of today's ESXi lockers. Original variants are partly recoverable with a free decryptor; derivatives usually are not.
Recent activity8Base
Free decryptor available.8base .id[8位ID-4位].[联系邮箱].8base
8Base was a Phobos-based double-extortion crew marked by the .8base extension, info.txt / info.hta notes and an ID-plus-email filename pattern, focused on small and mid-size firms. Its infrastructure was seized in February 2025 and Japan's NPA released a free decryptor in July 2025.
Operation shut downRecent activityREvil
Free decryptor available.[5-10位随机字符]
REvil (Sodinokibi) was the most damaging RaaS operation of 2019-2021, known for random per-victim extensions, [ext]-HOW-TO-DECRYPT.txt notes and the Happy Blog leak site, and for the JBS and Kaseya supply-chain incidents. Its infrastructure went dark in July 2021 and the crew collapsed after Russian arrests in early 2022; files encrypted before 13 July 2021 can be recovered with Bitdefender's free decryptor.
Operation shut downRecent activityConti
Some versions decryptable.CONTI .[5位随机大写字母] .[5位随机大小写字母数字]
Conti was one of the most destructive ransomware-as-a-service operations of 2020-2022, run by Wizard Spider (the TrickBot crew), with over 1,000 victims and more than USD 150 million collected. The brand dissolved in 2022 after its internal chats and source code leaked, and its members dispersed into Black Basta, Royal, Akira and other successors.
Operation shut downRecent activityHunters International
No public decryptor.locked
Hunters International was a RaaS operation built on Hive's source code from October 2023, marked early on by the .locked extension and a Contact Us.txt note. From v6 it encrypted silently without renaming files or dropping notes. The crew shut down in July 2025 and rebranded as the data-theft-only brand World Leaks.
RebrandedRecent activity
Decryptor status explained
- Free decryptor available
A free decryptor has been published by a security vendor or law enforcement. Matching samples can be decrypted directly, but the exact version still has to be confirmed.
- Some versions decryptable
Only certain versions or key batches can be decrypted, or unencrypted fragments left by intermittent encryption can be recovered. Each sample needs its own assessment.
- No public decryptor
No public decryptor exists today. Recovery relies on backups, snapshots, database repair and fragment reconstruction.
Identification & lookup tools
Ransomware identification tool
Enter an encrypted file extension, a ransom note filename or part of a contact address and we will match it against our family profiles.
Encrypted extension index
An alphabetical index of extensions, from .locked and .mallox to .beijing, mapped back to the ransomware family behind them.