knight logo

knight

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Cyclops
Ver en IntelTracker → APTTrail →
Knight is a ransomware-as-a-service (RaaS) operation that emerged in July 2023, representing a rebrand and evolution of the earlier Cyclops ransomware, also known as Cyclops 2.0. The group operates with a clear financial motivation, employing multi-extortion tactics to pressure victims into paying ransoms. A distinguishing feature of Knight is its offering of both normal and 'lite' versions of its payloads, designed to cater to various attack scales. The RaaS program provides affiliates with a builder, expanded toolsets, and panel access to create payloads and manage campaigns, often incorporating unique features like personalized support and distinct TOR domains for each target. The group's alleged origin is Russia and Europe, though this is based on their own claims of being a team of four individuals. Knight is commonly referred to by its former alias, Cyclops, and its source code was later sold in February 2024, leading to the emergence of the RansomHub ransomware, which is believe
Tecnicas MITRE
T1090, T1543, T1547, T1036, T1195, T1566

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

ArgentinaAmerican SamoaAustraliaBrazilCanadaChileChinaColombiaGermanySpain

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesSoftware PublishersEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationAdministrative &Waste Management

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com