New & Emerging Ransomware Groups 2025-2026 | How to Respond

Emerging Ransomware Groups

Newer/emerging ransomware groups are ransomware-as-a-service operations that surfaced in 2025 and 2026; among them are Interlock, BlackSuit, SafePay, Fog, Cactus, Lynx, 8Base, El Dorado, and Cicada3301, and they have already claimed confirmed corporate victims despite lacking the name recognition of established brands like LockBit or Qilin. The pace of new entrants is unusually fast: 61 new ransomware groups entered the market between April 2025 and March 2026, an average of more than one new group per week, pushing the total number of active threat groups to 146 by June 2026. For security teams, that speed is the real risk; a group with no track record today can be running double-extortion campaigns against your vendors within weeks. This guide profiles each of these newer groups individually, who they are, who they’ve hit, and how they operate, so you can recognize a name the moment it appears on a leak site or in an incident report, plus what to do if your organization turns up in one.

What Counts as an “Emerging” Ransomware Group in 2025-2026

An emerging ransomware group is a threat actor that has appeared on a public data leak site within the past 12 to 18 months, claimed at least one confirmed victim, and has not yet built the sustained volume or name recognition of an established operator like LockBit, Qilin, or Akira. Every group covered in this guide, Interlock, BlackSuit, SafePay, Fog, Cactus, Lynx, 8Base, El Dorado, and Cicada3301, fits that window, and most are still building their victim count and public profile rather than running at full operational scale.

Why New Groups Keep Appearing (rebrands, affiliate splits, RaaS kits)

New ransomware brands surface constantly because the barrier to launching one keeps dropping. A law enforcement takedown or infrastructure seizure rarely eliminates the people behind a group; it scatters their affiliates, who regroup under a new name within weeks using the same tooling and negotiation playbooks. Ransomware-as-a-service kits accelerate this further: an operator no longer needs to write their own encryptor; they can license one and recruit affiliates to run the intrusions. IBM’s X-Force Threat Intelligence Index recorded 109 distinct extortion groups active in 2025, up from 73 the year before, a 49% jump driven largely by this lower barrier to entry rather than by any single new technique. BlackSuit itself illustrates the pattern: researchers link it to the earlier Royal ransomware operation, which itself traces back to the Conti collapse.

How We Track and Verify New Threat Actors

DeXpose treats a group as active and worth tracking once it maintains a working leak site, has functioning negotiation infrastructure, and has posted at least one verifiable victim; dormant sites and unconfirmed claims don’t qualify. Each profile in this guide is built from that same verification standard: leak-site postings, CISA and FBI advisories where available, and corroborating incident reports, rather than a group’s own claims taken at face value. That distinction matters in a landscape this crowded, since not every name that appears on a forum or leak-site listing turns out to be a real, independently operating group.

Interlock Ransomware

Interlock is a ransomware group that first surfaced in September 2024 and has become one of the most active newer threat actors targeting healthcare, critical infrastructure, and business networks across North America and Europe. Unlike most modern ransomware operations, Interlock doesn’t run a typical ransomware-as-a-service affiliate program; it operates as a closed group with its own infrastructure and a leak site it calls “Worldwide Secrets Blog,” using double extortion to pressure victims into paying.

Ransomware

Who Is Interlock and What Do They Target

Interlock is financially motivated and opportunistic rather than selective, meaning it doesn’t appear to pre-select victims by industry so much as exploit whatever access it can get. Its entry point sets it apart from most ransomware crews. Instead of buying stolen credentials or brute-forcing exposed RDP, Interlock lures victims through compromised legitimate websites, fake browser-update prompts, and, since May 2025, the ClickFix technique, which tricks users into running a malicious command themselves. The group builds encryptors for both Windows and Linux, including variants aimed specifically at virtual machines, which lets a single successful intrusion take down an entire hypervisor’s worth of servers at once.

Notable Attacks (DaVita and Other Confirmed Victims)

Interlock’s highest-profile attack to date hit DaVita, a major U.S. kidney dialysis provider, in April 2025. The group claimed it stole roughly 1.5 terabytes of data and later leaked it after negotiations failed; DaVita ultimately confirmed 2.7 million patients were affected and agreed to a $15 million class-action settlement over the breach. Kettering Health, an Ohio health system, and Texas Tech University Health Sciences Center were also hit in attacks believed to be Interlock’s work, reinforcing healthcare as a recurring target for the group.

TTPs, CVEs Exploited, and FBI/CISA Advisories

On July 22, 2025, CISA, the FBI, HHS, and MS-ISAC issued a joint #StopRansomware advisory (AA25-203A) detailing Interlock’s indicators of compromise and tactics, drawn from FBI investigations through June 2025. The advisory flagged Interlock’s use of PowerShell-based payload delivery, persistence via the Windows Startup folder, and credential-stealing tools deployed after initial access; by mid-2025, it also noted a PHP-based variant tied to the wider KongTuke FileFix campaign. Organizations are advised to focus on DNS filtering, web access controls, and user training against social-engineering lures, since Interlock’s initial access relies on tricking a person rather than exploiting a specific unpatched vulnerability.

BlackSuit Ransomware

BlackSuit is a ransomware group whose infrastructure U.S. and international law enforcement seized in July 2025. However, the operation had already extorted more than $370 million from victims by the time it was taken down. It’s one of the more consequential “newer” groups on this list only in name; its lineage traces back through two earlier ransomware brands, and its July 2025 takedown, not its debut, is what makes it worth tracking now.

Ransomware

Origins and Link to Royal Ransomware

BlackSuit isn’t so much a new group as a rebrand. It emerged in mid-2023 as the successor to Royal ransomware, which itself grew out of Quantum ransomware, a lineage that traces back to members of the Conti cartel after that group disbanded in 2022. Royal was active from January to July 2023, claiming roughly 123 victims before its activity dropped off and the BlackSuit name took over. By the end of 2023, CISA reported BlackSuit had extorted more than $275 million from at least 350 known victims, and its ransom demands have reportedly ranged from roughly $1 million to figures well above that for larger targets.

Notable Attacks (CDK Global and Others)

BlackSuit’s most disruptive attack hit CDK Global in June 2024, a software provider used by thousands of U.S. car dealerships; the outage forced dealers back onto paper records for days and reportedly ended after CDK paid a $25 million ransom. The group also forced plasma-collection company Octapharma to shut down nearly 200 donation centers temporarily, and its victim list spans healthcare, education, public safety, energy, and government organizations, sectors where operational downtime creates maximum pressure to pay.

2025 Takedown and $370 Million Seizure

On July 24, 2025, the Justice Department, Homeland Security Investigations, IRS Criminal Investigation, the FBI, the Secret Service, and law enforcement partners across seven countries executed Operation Checkmate, seizing four servers, nine domains, and roughly $1.09 million in cryptocurrency tied to BlackSuit. Investigators found that Royal and BlackSuit combined had compromised more than 450 known U.S. victims and collected over $370 million in ransom payments since 2022. The takedown disrupted BlackSuit’s extortion infrastructure, but researchers at Cisco Talos assess with moderate confidence that former BlackSuit members have already regrouped under a new name, Chaos ransomware, a reminder that a law enforcement seizure rarely ends a group’s activity so much as it forces a rebrand.

SafePay Ransomware

SafePay is a ransomware group that surfaced in late 2024 and became one of the world’s most active ransomware operations within a year, best known for the July 2025 attack that knocked global IT distributor Ingram Micro offline for days. Unlike most fast-scaling ransomware brands, SafePay isn’t a ransomware-as-a-service operation with affiliates; it’s an independent group that keeps full operational control and 100% of ransom payments.

Ransomware

Who Is SafePay and Their Attack Pattern

SafePay typically gains initial access through valid credentials obtained via a compromised VPN gateway or portal, rather than exploiting a specific software vulnerability, and it deliberately avoids common persistence techniques like enabling RDP or creating new user accounts to stay under the radar. Once inside, the group moves fast: it exfiltrates data first, then encrypts, compressing the gap between initial access and full network encryption to roughly 24 hours, a speed that leaves defenders a narrow window to respond. NCC Group identified SafePay as the most active ransomware group in May 2025, responsible for 18% of all tracked attacks that month, and its code checks system language settings and halts if it detects Russian, Ukrainian, or several neighboring languages, suggesting its operators avoid targets in that region.

Ingram Micro and Other Confirmed Victims

SafePay’s highest-profile attack hit Ingram Micro, a $48 billion technology distributor, on July 2–3, 2025, taking down its ordering systems and AI-powered Xvantage distribution platform and disrupting operations across the U.S., Europe, and Asia for roughly a week. Ingram Micro later quantified the damage at 1% to 1.5% of its third-quarter net sales, an estimated $126 million to $189 million. He separately disclosed that the personal data of 42,521 employees and job applicants had been taken, a breach it settled for $350,000 in January 2026. Despite that headline attack, SafePay’s typical victim looks nothing like Ingram Micro: an analysis of 500 of its leak-site listings found more than 90% were small and medium-sized businesses, with multinationals making up only about 8%. The group has claimed over 220 victims since emerging, concentrated in the U.S., Germany, the U.K., Australia, and Canada.

File Extensions, Variants, and IOCs

SafePay encrypts files with a distinctive .safepay extension and drops a ransom note titled readme_safepay.txt that opens with the line “Your corporate network was attacked by SafePay team.” Key indicators of compromise include victim-specific mutexes created to prevent multiple encryption runs on the same device, deleted shadow copies, disabled security services, and the use of common but telling tools, PsExec, WinRAR, FileZilla, and the reconnaissance script ShareFinder.ps1, to move data before encryption begins. Security teams monitoring for SafePay should watch for DLLHost.exe invoking CMSTPLUA COM objects, a known UAC-bypass technique, alongside unusual outbound transfers via WinRAR or FileZilla that signal exfiltration already in progress.

Fog Ransomware

Fog is a ransomware group that emerged in spring 2024 and has become notable less for its size than its speed; in one documented case, it moved from initial network access to complete file encryption in under two hours. It stands out among newer groups for a target list skewed toward education and business services rather than the healthcare and critical-infrastructure sectors most ransomware crews chase. However, it expanded into financial services by mid-2024.

Ransomware

What Is Fog Ransomware

Fog gains initial access almost exclusively through compromised VPN credentials, most notably by exploiting a SonicWall SSL VPN vulnerability (CVE-2024-40766). It has also been observed exploiting a critical Veeam Backup & Replication flaw (CVE-2024-40711) to compromise backup infrastructure directly. Once inside, it uses pass-the-hash techniques to escalate to administrative privileges, maps network shares with tools like SharpShares.exe, and pulls saved credentials from browser profiles using the legitimate Windows utility esentutl.exe before exfiltrating data with Rclone. Fog encrypts files with a “.FOG” or “.FLOCKED” extension, specifically targeting virtual machine disk files and deleting backups to remove any recovery option short of paying.

CISA Advisory Details and Technical Analysis

Fog hasn’t received its own dedicated #StopRansomware joint advisory like groups such as Interlock or Akira have. Instead, it shows up in CISA and vendor advisories about the two vulnerabilities it exploits most, the SonicWall SSL VPN flaw and the Veeam RCE bug, both of which Fog and Akira were observed weaponizing within days of each other in 2024. Most detailed technical analysis has come from incident responders who caught Fog in the act: Adlumin documented a thwarted attack on a financial services company down to the specific command-line tools used, and Darktrace’s telemetry captured the sub-two-hour attack that first demonstrated the group’s speed.

Fog vs. Akira, Shared Infrastructure

Fog and Akira aren’t just similar; researchers believe they’re operationally connected. Arctic Wolf tracked 30 ransomware intrusions via compromised SonicWall VPN accounts in late 2024 and found 75% were linked to Akira and the remaining 25% to Fog, concluding the two groups were collaborating rather than competing for the same targets. On-chain analysis from TRM Labs reinforces that link: Fog used the same cryptocurrency laundering infrastructure as Akira during one operational phase, and both groups’ malware carries code and wallet overlaps tracing back to the defunct Conti ransomware operation. For defenders, the practical takeaway is that an intrusion showing Fog’s fingerprints likely shares infrastructure, tooling, or even personnel with Akira, meaning a mitigation built for one group’s TTPs is likely to catch the other.

Cactus Ransomware

Cactus is a ransomware group active since March 2023 that built its reputation on a distinctive technical trait: it encrypts its own ransomware binary, a self-protective step most ransomware strains don’t bother with, making it harder for antivirus tools to detect before execution. It’s best known publicly for its January 2024 attack on French energy giant Schneider Electric, but the group has quietly listed more than 100 victims on its leak site since launching.

Ransomware

Origins and Leak Site Activity

Cactus first appeared in March 2023 as a multipoint extortion operation, and researchers at Kroll flagged its self-encrypting binary as an unusual feature that sets it apart from typical ransomware tooling. The group runs a standard double-extortion model, stealing data before encrypting systems and threatening to leak it if the ransom goes unpaid, and had crossed the 80-victim mark on its Tor-based leak site within its first year. This pace put it among the more prolific newer operators rather than a slow-building niche threat.

Schneider Electric and Other Notable Victims

Cactus’s highest-profile attack hit Schneider Electric on January 17, 2024, breaching the company’s Sustainability Business division and its Resource Advisor cloud platform, which manages energy and sustainability data for more than 2,000 client companies including Walmart, Hilton, and PepsiCo. The group claimed to have exfiltrated 1.5 terabytes of data and later published passport scans and signed confidential agreements as proof. However, network segmentation kept the breach contained to that one division. Other confirmed victims include Marfrig Global Foods, one of the world’s largest beef producers, and MINEMAN Systems, a mining-industry software provider, showing Cactus isn’t concentrated in one sector so much as opportunistic across industrial and consumer-facing targets alike.

TTPs and IOCs

Cactus most commonly gains initial access through vulnerable VPN gateways, particularly older Fortinet VPN instances, as well as purchased credentials, phishing, and partnerships with initial-access brokers. Once inside a network, it uses the SoftPerfect Network Scanner (netscan) and PowerShell commands to enumerate connected systems and identify user accounts before moving laterally, then relies on well-documented, publicly available tooling rather than custom-built malware for most of the intrusion. That reliance on commodity tools is itself a useful detection signal: unusual netscan activity or PowerShell enumeration commands combined with VPN gateway logins from unfamiliar geographies are among the earliest indicators defenders can catch before Cactus reaches the encryption stage.

Lynx Ransomware

Lynx is a ransomware-as-a-service operation that emerged in July 2024 as a rebrand of the earlier INC ransomware, and it has scaled unusually fast: from roughly 96 confirmed victims in January 2025 to nearly 300 by August 2025, and 393 by March 2026. Despite publicly claiming an “ethical” policy against targeting hospitals and government institutions, the group has repeatedly hit healthcare-adjacent organizations and critical infrastructure, including an April 2026 attack on ACN Healthcare.

Ransomware

Who Is Lynx and 2025 Activity Timeline

Lynx’s malware shares a significant portion of its codebase with INC ransomware; researchers have found roughly 70% overlap in key functions, strongly suggesting Lynx’s operators bought or repurposed INC’s source code rather than building from scratch. The group runs a standard RaaS model with affiliates, uses double extortion, and primarily targets manufacturing, legal services, retail, and energy organizations across North America and Europe. Its activity accelerated steadily through 2025: a December 2024 attack disrupted energy supplier Electrica, a January 2025 breach hit U.S. law firm Hunter Taubman Fischer & Li, and by early 2026 Lynx was running high-volume campaigns, including a single day in January 2026 when 20 separate organizations were added to its leak site at once, a pattern consistent with automated scanning or the simultaneous use of previously purchased network access.

Healthcare Sector Targeting (ACN Healthcare, April 2026)

On April 8, 2026, Lynx claimed responsibility for breaching ACN Healthcare, a Delaware-based revenue cycle management and healthcare business process outsourcing provider, with the listing appearing on Lynx’s leak site two days later. As of mid-April 2026, the full scope of the breach, including how many patients or providers were affected and what data was exposed, had not been publicly disclosed. The attack is notable given Lynx’s stated policy of avoiding “hospitals” and organizations that “play vital roles in society”: ACN Healthcare processes billing and revenue data for healthcare providers rather than delivering care directly, a distinction that appears to place it outside the group’s self-declared boundaries even as the attack lands squarely within the healthcare sector’s supply chain, the same indirect-targeting pattern seen in other major healthcare breaches where a vendor, not a hospital, is the entry point.

8Base Ransomware

8Base is a ransomware group that surfaced in its current form in early 2023, built on a modified version of the leaked Phobos ransomware, and was largely dismantled by law enforcement in February 2025, making it more of a cautionary case study than an active threat today. Its leak site campaigns are traceable back to smaller 2022 operations, but it didn’t become a recognized name until a sharp activity spike in mid-2023.

Ransomware

Group Background and Activity

8Base never built its own ransomware from scratch. Instead, it customized the leaked Phobos builder, appending a “.8base” extension to encrypted files and embedding the ransomware payload inside SmokeLoader, a commodity backdoor trojan, to help it evade detection during delivery. Operating a double-extortion model aimed primarily at small and medium-sized businesses, the group claimed victims across finance, manufacturing, IT, and healthcare, including, according to DOJ charges, a children’s hospital, mostly concentrated in the United States and Brazil. In February 2025, an international law enforcement action dubbed Operation PHOBOS AETOR seized the group’s leak site and 27 servers, arrested four suspected 8Base leaders in Thailand, and warned more than 400 organizations that had been targeted or were under active threat. Authorities estimated the group had stolen roughly $16 million from over 1,000 victims before the takedown. With the infrastructure dismantled, current search activity around 8Base largely comes from past victims still dealing with the aftermath, recovery, data exposure, and legal questions, rather than organizations facing an active, ongoing threat from the group itself.

El Dorado Ransomware

El Dorado (also tracked as Eldorado) is a ransomware-as-a-service operation that emerged in March 2024 and rebranded as BlackLock in late 2024, so most of its 2025-2026 activity shows up under the newer name rather than the original. It’s a useful example of how fast this space turns over: a group can go from unknown to rebranded within a single year, which is part of why tracking newer ransomware groups by name alone quickly becomes outdated.

Ransomware

Group Background

El Dorado first surfaced in March 2024 as a RaaS platform built in Go, using ChaCha20 for file encryption and RSA-OAEP for key encryption, with variants capable of hitting both Windows and Linux/VMware ESXi environments. It targeted real estate, education, professional services, healthcare, and manufacturing organizations. By late 2024, researchers had confirmed that the same operator behind El Dorado, using the online alias “$$$”, had transitioned the operation into a new brand, BlackLock, with the two groups’ leak sites sharing an almost identical victim list and confirmed code and ransom-note overlap. BlackLock’s activity then surged dramatically, with one report finding a 1,425% quarter-over-quarter increase in data leak site posts in the final quarter of 2024 alone.

2025-2026 Attacks (Arkansas and Beyond)

El Dorado’s confirmed 2024 victims, before the BlackLock rebrand fully took hold, included New River Electrical in Ohio, the College of Veterinary Medicine at Kansas State University, and the City of Pensacola, Florida. Separately, El Dorado, Arkansas, a municipal government, confirmed a ransomware-related cyber incident as part of the broader wave of attacks on U.S. city and county governments in 2025-2026. However, public reporting on that incident hasn’t attributed it specifically to the El Dorado ransomware brand. The naming overlap between the city and the ransomware group appears to be coincidental rather than connected. That distinction matters for anyone researching this topic: a search for “El Dorado ransomware” could reasonably return either the RaaS operation or news about the Arkansas city’s breach, and conflating the two risks misattributing an incident to a threat actor that may have had nothing to do with it.

Cicada3301 Ransomware

Cicada3301 is a ransomware-as-a-service operation that emerged in June 2024 and is widely believed to be a rebrand or close collaborator of the now-defunct BlackCat/ALPHV group, based on near-identical code and ransom note formatting. It borrows its name from the well-known 2012-2014 internet cryptography puzzle. However, the ransomware operation has no actual connection to it; the original puzzle’s organizers have publicly denounced the criminal group for using the name.

Group Background and Current Status

Cicada3301 began recruiting affiliates on the RAMP cybercrime forum in June 2024, offering a Rust-based locker capable of hitting Windows, Linux, VMware ESXi, NAS devices, and even PowerPC systems, an unusually broad platform range for a group this new. Security researchers at Truesec found the ransomware shared significant code similarities with ALPHV/BlackCat, including matching encryption methods and VM-shutdown techniques, strengthening the theory that former ALPHV developers or affiliates are behind the operation. The group gains initial access primarily through stolen or brute-forced VPN credentials on Cisco, Fortinet, Palo Alto, and SonicWall devices, then uses tools like PsExec to escalate privileges and deletes shadow copies to block recovery. Cicada3301 claimed roughly 30 victims across more than 15 countries within its first year, concentrated in the U.S. and U.K. with additional activity in Switzerland and Norway, and remains an active RaaS operation as of the most recent tracking, making it one of the smaller but more technically capable groups on this list, worth watching given its apparent lineage from one of the more disruptive ransomware brands to precede it.

Common TTPs Across These Emerging Groups

Despite operating independently, the nine groups profiled here, Interlock, BlackSuit, SafePay, Fog, Cactus, Lynx, 8Base, El Dorado, and Cicada3301, share a remarkably consistent playbook: steal data before encrypting it, then use the threat of public exposure as the primary lever to force payment. That convergence isn’t coincidence; it reflects a criminal ecosystem where tooling, source code, and even affiliates move freely between groups, so new brands rarely need to innovate from scratch.

Ransomware

Double-Extortion and Leak Site Tactics

Every group covered here runs some form of double extortion, exfiltrating sensitive data prior to encryption and maintaining a Tor-based leak site to publish stolen files if a victim refuses to pay. The specifics vary: SafePay compresses the entire intrusion-to-encryption window to roughly 24 hours, while Lynx and Cactus tend to negotiate longer before publishing, but the underlying pressure mechanism is identical across all nine: encryption disrupts operations today, and the leak site threatens reputational and legal damage tomorrow. This model has become so standardized that groups reuse code and infrastructure wholesale; Lynx’s malware shares roughly 70% of its functions with the earlier INC ransomware, and 8Base built its entire operation on a modified version of the leaked Phobos builder rather than developing original ransomware.

Initial Access Patterns (RDP, phishing, exploited CVEs)

Compromised VPN credentials are the single most common entry point across this group of nine, appearing in Cactus’s Fortinet VPN exploitation, SafePay’s and Cicada3301’s brute-forced or stolen VPN logins, and Fog’s and Akira’s shared exploitation of a SonicWall SSL VPN flaw (CVE-2024-40766). Social engineering is the second major pattern; Interlock relies on compromised legitimate websites and the ClickFix technique to trick users into running malicious commands themselves, a method that sidesteps traditional phishing filters entirely. A smaller number of groups exploit specific software vulnerabilities directly, such as Fog’s use of a critical Veeam Backup & Replication RCE flaw (CVE-2024-40711) to compromise backup infrastructure before attackers ever touch the production network. The practical takeaway for defenders is that patching alone won’t close the gap: enforcing multifactor authentication on every VPN and remote-access account would have blocked the initial access vector in most of the intrusions described across these nine groups.

How to Tell If Your Organization Was Named by One of These Groups

The most reliable way to find out if a ransomware group has named your organization is to check that group’s Tor-based leak site directly or use a dark web monitoring service that tracks leak site postings automatically; waiting for a ransom note to appear on your own systems means you’re already several stages into an active intrusion. Since most of the groups profiled here publish victims only after negotiations stall, a name can appear on a leak site days or weeks after the breach.

Ransomware

Checking Leak Sites and Dark Web Mentions

Each of these nine groups maintains its own Tor-hosted leak site where it lists victim organizations, often with sample stolen files as proof before a ransom deadline expires. Manually checking each site is possible but impractical for most security teams; leak sites go up, get seized, and reappear under new names constantly, as seen with BlackSuit’s infrastructure seizure in 2025 and El Dorado’s rebrand to BlackLock. A dark web monitoring platform that continuously tracks these leak sites, along with broader mentions of your domain, employee credentials, or brand across dark web forums and marketplaces, catches a listing far faster than manual checks. DeXpose’s Free Darkweb Report and Email Data Breach Scan tools are built for exactly this kind of continuous exposure check. NCC Group’s finding that SafePay alone accounted for 18% of all tracked ransomware attacks in a single month underscores how much leak-site activity any manual monitoring process would need to keep up with.

What to Do Immediately If You’re Listed

If your organization appears on a ransomware leak site, the priority is verification, not negotiation: confirm the listing is genuine and determine what data the group actually claims to have, since some groups pad or falsify claims to increase pressure. From there, isolate affected systems immediately to stop lateral movement, engage a forensic incident response team to determine the actual scope of access and exfiltration, and notify legal counsel before making any public statement or contacting the threat actor directly. Loop in law enforcement, the FBI’s IC3, or CISA for U.S. organizations early; agencies have disrupted several of the groups covered here, including BlackSuit and 8Base, and current reports can sometimes reveal whether decryption keys or negotiation intelligence already exist from prior takedowns. Paying the ransom should be a last resort weighed with legal and executive input, not a default response, since payment doesn’t guarantee data won’t be leaked anyway and can mark an organization as a repeat target.

Frequently Asked Questions

How do new ransomware groups form?

Most form when affiliates from a disrupted or dismantled operation regroup under a new name, often reusing the same tooling, leak-site infrastructure, and negotiation playbooks within weeks of a law enforcement takedown. Ransomware-as-a-service kits have also lowered the barrier further, letting an operator license an existing encryptor and recruit affiliates rather than building malware from scratch, a big part of why the number of active ransomware groups tracked industry-wide has grown by double digits year over year.

Are these groups rebrands of older gangs?

Several of them, yes. BlackSuit is a direct rebrand of Royal, which itself traces back through Quantum to the disbanded Conti cartel; El Dorado rebranded as BlackLock in late 2024; Lynx reuses a large share of INC ransomware’s source code; and 8Base built its operation on a modified version of the leaked Phobos builder rather than original malware. Others, like Interlock, SafePay, and Cactus, appear to be genuinely new operations, though even these show tooling and tactical overlap with earlier groups, a reminder that “new” in ransomware usually means a new name, not a new set of techniques.

What industries are they targeting most in 2025-2026?

Healthcare and critical infrastructure show up disproportionately across this group of nine; Interlock’s DaVita attack, Lynx’s ACN Healthcare breach, and BlackSuit’s history with hospitals and public safety organizations all fit that pattern, alongside manufacturing, education, and business services, which several groups including Fog and Cactus favor for their weaker security postures relative to potential payout size. No single industry is off-limits: SafePay’s victim profile skews heavily toward small and medium-sized businesses across almost any sector, while a smaller number of these groups have shown willingness to hit large multinationals when the opportunity presents itself, as SafePay did with Ingram Micro.

More from the knowledge hub

All guides