Lesser-Known Ransomware Groups Still Targeting Businesses in 2026

Groups like Monti, Vice Society, Royal (now rebranded as BlackSuit), Cuba, Nokoyawa, Yanluowang, and Lorenz rarely make national headlines like LockBit or Qilin, but they’re still actively compromising businesses in 2026. Many of them keep a low profile on purpose, reusing leaked code, exploiting overlooked entry points like VoIP phone systems, and running double-extortion campaigns against mid-size organizations that never attract the same scrutiny as a Fortune 100 breach.
Why “Lesser-Known” Ransomware Groups Still Matter
A ransomware group doesn’t need to be famous to do serious damage; it just needs enough targets willing to pay quietly, and enough distance from law enforcement to keep operating. Several of the groups below trace their code, tooling, or personnel directly back to larger operations that were publicly shut down, which means a headline about a gang “disappearing” often means it fragmented into something smaller and harder to track.
Rebrands, Splinters, and the Conti Legacy
The Conti ransomware group shut down in 2022 after an internal leak, reportedly by a member angered by the gang’s public support for Russia’s invasion of Ukraine, exposed its chat logs and, eventually, its source code. That leak didn’t end the threat; it multiplied it. Royal’s founding members are widely believed to include former Conti operators, and Monti built its earliest ransomware payloads almost entirely on Conti’s leaked code. This pattern, a well-known group dissolving under pressure and reseeding two or three smaller successors, is one of the main reasons “lesser-known” groups keep appearing on breach notifications years after the operations they descended from officially ended.
Why Smaller Groups Fly Under the Radar
Staying obscure is a deliberate strategy, not an accident. Security researchers have described Vice Society as a second- or third-tier group in technical sophistication. Yet, it still listed 33 different schools on its leak site in a single year by focusing on regional school districts and hospitals that get far less media and law enforcement attention than a major hospital chain or airline. Lower ransom demands, smaller victim organizations, and a preference for negotiation over publicity all help these groups extend their operational lifespan well past what a more prominent gang could expect.
Monti Ransomware
Who Is Monti?
Monti surfaced in June 2022, within weeks of Conti’s public shutdown, and its name is widely read as a deliberate nod to (or mockery of) its predecessor. Early Monti attacks relied almost entirely on Conti’s leaked source code, tooling, and tactics, which led researchers to debate for months whether it was a genuine Conti offshoot or simply a new crew capitalizing on leaked material. Monti runs both Windows and Linux ransomware variants. He has consistently targeted legal, government, and healthcare organizations, publishing non-paying victims to a leak site it calls its “Wall of Shame.”
Attack Methods and Targets
Monti’s most documented intrusion exploited the Log4Shell vulnerability against an internet-facing VMware Horizon system, encrypting dozens of hosts and servers before defenders could respond. After a roughly two-month gap in activity in 2023, the group returned with a Linux-based encryptor that diverged sharply from its original Conti-based code, adding Custom behavior specifically designed to evade the detection signatures researchers had built around the earlier variant. That shift, from copying someone else’s playbook to writing original evasion logic, is a useful signal that a “minor” group is investing in longevity rather than a quick payday.
Vice Society Ransomware
Group Overview and Origins
Vice Society first appeared in mid-2021 and stands out for what it doesn’t do: build its own ransomware. Instead of developing a proprietary encryptor, the group has relied on existing strains such as HelloKitty and Zeppelin, later moving to a custom-branded payload called PolyVice. In September 2022, a joint advisory from the FBI, CISA, and the Multi-State Information Sharing and Analysis Center warned that Vice Society was disproportionately targeting K-12 schools and higher education institutions, a pattern the group has sustained ever since alongside regional healthcare providers.
Notable Victims (including CommScope)
In April 2023, North Carolina-based network infrastructure company CommScope confirmed a ransomware incident after Vice Society published employee data, including Social Security numbers and bank account details for thousands of staff, on its leak site following a failed ransom negotiation. CommScope’s scale (more than 30,000 employees and customers spanning hospitals, schools, and federal agencies) made it one of Vice Society’s largest confirmed victims, alongside earlier hits on San Francisco’s BART transit system, Puerto Rico’s water utility, and multiple universities and school districts across the US, UK, Canada, and Germany.
Royal Ransomware (Now BlackSuit)
What Is Royal Ransomware?
Royal emerged around September 2022 as a human-operated ransomware operation that skipped the affiliate/ransomware-as-a-service model most large groups use, instead running attacks with a smaller, tighter core team believed to include former Conti members. Like most groups on this list, Royal relies on double extortion, exfiltrating data before encrypting it and threatening to publish it if the ransom isn’t paid.
The Conti-to-Royal-to-BlackSuit Timeline
Royal was one of the most active ransomware operations through mid-2023, with the June 2023 attack on the City of Dallas, Texas, marking a turning point. Shortly after, the group began deploying a new encryptor called BlackSuit. In August 2024, an updated joint CISA and FBI advisory formally confirmed what researchers had suspected for months: BlackSuit is a rebrand of Royal, based on shared coding characteristics between the two ransomware families.
How Royal Ransomware Works
Initial access typically comes through phishing emails, exposed Remote Desktop Protocol, or vulnerable public-facing applications, sometimes purchased outright from initial access brokers rather than obtained directly. Once inside, the group turns off antivirus tooling, establishes command-and-control communication, and exfiltrates data before encrypting systems, a sequence built to maximize extortion leverage even if a victim can restore from backup.
CISA Advisory and Known IOCs
The joint #StopRansomware advisory covering Royal and BlackSuit, first published in March 2023 and updated in November 2023 and again in August 2024, documents tactics, techniques, and procedures mapped to the MITRE ATT&CK framework along with indicators of compromise for network defenders. The advisory notes BlackSuit activity spanning commercial facilities, healthcare, government facilities, and critical manufacturing sectors.
Notable Victims: City of Dallas and Others
Beyond the City of Dallas attack, which disrupted municipal IT systems including police-related operations, BlackSuit was later linked to an attack on the Henry County School System in Georgia that exposed data belonging to more than 40,000 students and staff and took the district offline for several days. Ransom demands from the group have typically ranged from $1 million to $10 million, with one reported demand as high as $60 million, and total demands attributed to the BlackSuit brand are estimated to have exceeded $500 million within its first year of operation.
Is There a Royal Ransomware Decryptor?
No publicly available, reliable free decryptor currently exists for Royal or BlackSuit. As with most active ransomware families, paying the ransom doesn’t guarantee full data recovery, which is why CISA’s guidance for this group centers on maintaining segmented, offline backups and strong password policies rather than relying on a recovery tool after the fact.
Royal Ransomware Leak Site
Both Royal and BlackSuit operate a Tor-hosted leak site where non-paying victims are listed publicly, with stolen data posted in stages to pressure continued negotiation, the same double-extortion leak-site model used by nearly every group covered in this article.
Cuba Ransomware
What Is Cuba Ransomware?
Cuba is a Windows-based ransomware family that’s been active since at least December 2019, targeting financial institutions, technology firms, and logistics companies across North America, South America, and Europe. Despite the name, CISA has explicitly stated there’s no indication the group has any connection or affiliation with the Republic of Cuba; it’s a branding choice, not an attribution. In threat intelligence circles, actors behind it are also tracked as Tropical Scorpius.
Technical Deep Dive: GetKeyState and VkKeyScan Keylogging (MITRE ATT&CK)
One of Cuba’s more distinctive capabilities is built-in keylogging using the Windows API calls GetKeyState and VkKeyScan, mapped to MITRE ATT&CK’s Input Capture: Keylogging technique (T1056.001), which the group uses to harvest credentials for lateral movement once inside a network. Cuba actors have also exploited CVE-2022-24521, a privilege-escalation flaw in the Windows Common Log File System, and abused Microsoft Exchange vulnerabilities like ProxyShell and ProxyLogon for initial access, typically delivering the ransomware itself through a loader known as Hancitor.
Cuba Ransomware Associated Threat Groups
Security researchers track the operators behind Cuba ransomware as Tropical Scorpius, and the group has shown tooling overlap with other financially motivated actors that use the Hancitor loader. However, researchers haven’t established a formal affiliation between the crews.
Known Victims and IOCs
CISA’s joint advisory on Cuba ransomware, first published in December 2022, catalogs file hashes, ransom note language, cryptocurrency wallet addresses, and Jabber and email contacts used by the group, alongside confirmed victims spanning the financial, government, healthcare, and IT sectors.
Nokoyawa Ransomware
Group Profile and Attack Pattern
Nokoyawa first appeared in February 2022. Researchers initially suspected a connection to Hive ransomware before determining it was more closely related to the Karma and Nemty families, with some code reused from the leaked Babuk source. Technically, Nokoyawa stands out for combining Salsa20 symmetric encryption with a rarely used elliptic curve algorithm (ECC-SECT233R1) rather than the more common encryption choices seen across the ransomware landscape. In May 2023, Kaspersky researchers found Nokoyawa affiliates exploiting a genuine Windows zero-day vulnerability in the Common Log File System to escalate privileges, a notable move, since most financially motivated ransomware crews rely on known, already-patched vulnerabilities rather than burning a zero-day. Public tracking currently attributes 36 known victims to the group across the US, Brazil, Romania, Singapore, and other countries.
Yanluowang Ransomware
Group Profile and Notable Incidents
Symantec first identified Yanluowang in October 2021. Its name, borrowed from a deity in Chinese mythology, was meant to suggest Chinese origin, but the group’s internal Matrix chat server was hacked on Halloween 2022. Roughly 2,700 messages spanning January to September of that year were leaked; researchers found the communications were entirely in Russian, exposing the “Chinese” branding as misdirection. The group runs tightly targeted, human-operated attacks rather than broad opportunistic campaigns, and its confirmed victim list includes major Western enterprises Cisco and Walmart. Public tracking currently shows only a handful of confirmed victims, consistent with a group that prioritizes precision over volume.
Lorenz Ransomware
Group Profile and IOCs
Lorenz has been active since at least February 2021, and researchers believe it is a rebrand of an earlier strain known as “.sZ40,” with code similarities also linking it to the older ThunderCrypt ransomware. Like most groups here, it runs a double-extortion model, typically using FileZilla to exfiltrate data before encrypting systems with Microsoft’s BitLocker, occasionally extending to VMware ESXi hosts, rather than a fully Custom encryptor. Its most distinctive trait is an initial-access method most ransomware crews ignore: exploiting CVE-2022-29499, a remote code execution flaw in Mitel MiVoice Connect VoIP appliances, to obtain a reverse shell through an organization’s office phone system before tunneling further into the network using a tool called Chisel. Lorenz has primarily targeted small and mid-size US businesses, with secondary activity in China and Mexico, and has been linked to an attack on EDI provider Commport Communications.
How to Detect and Defend Against These Groups
None of the seven groups above relies on a single exploit or entry point, which is exactly why defense against them has to combine the fundamentals CISA repeats across nearly every #StopRansomware advisory- patch known vulnerabilities quickly, enforce phishing-resistant multifactor authentication, and maintain offline backups- with visibility into where these groups actually operate: the dark web leak sites and forums where stolen data first surfaces.
Dark Web Monitoring for Early Warning
Every group covered here runs a leak site. It typically gives victims a negotiation window before publishing stolen data, which means the first sign of a breach often surfaces on the dark web well before it becomes public knowledge. Continuous dark web monitoring can catch a company’s name, employee credentials, or stolen files circulating in that window, turning what would otherwise be a surprise leak-site listing into an early warning an incident response team can act on.
IOC and Leak-Site Tracking
Cross-referencing the file hashes, ransom-note language, and infrastructure indicators published in CISA’s #StopRansomware advisories against internal network logs is a practical way to catch these specific families before encryption completes. It’s also worth monitoring leak sites for vendor and supply-chain partner names, not just your own organization. Vice Society and Royal have both used third-party breaches to reach downstream victims, so a partner’s listing can be an early signal of your own exposure.
Frequently Asked Questions (FAQ)
Is Royal ransomware the same as BlackSuit?
Yes. CISA and the FBI confirmed in August 2024 that BlackSuit is a rebrand of Royal ransomware, based on coding similarities identified between the two variants.
Is Cuba ransomware connected to the country of Cuba?
No. CISA has stated there’s no indication the group has any connection or affiliation with the Republic of Cuba; the name is simply a branding choice.
Which of these groups has hit the most victims?
Among the groups covered here, Nokoyawa currently has the highest confirmed victim count at 36, while Yanluowang’s more targeted approach has kept its confirmed victim list much smaller.
Is there a free decryptor for any of these ransomware families?
Not currently. None of the seven groups covered here has a reliable, publicly available free decryption tool, which is part of why maintaining backups and catching a breach early matters more than hoping for a fix after encryption.


