Ransomware groups - Sos Ransomware

Ransomware groups are cybercriminal organizations specialized in deploying malware that encrypts victims’ data, making this information inaccessible. Once the data has been encrypted, these groups typically demand a ransom, often paid in cryptocurrency, in exchange for the decryption key enabling victims to recover their data. These attacks can target individuals, businesses, government institutions or critical infrastructures, causing major disruption and considerable financial loss.

Over the years, several ransomware groups have emerged and gained notoriety for their large-scale attacks and exorbitant ransom demands. These groups use sophisticated techniques, exploit vulnerabilities and constantly adapt their methods to evade detection and maximize their profits. In addition to encrypting data, some also threaten to divulge sensitive information if they don’t receive payment, adding an extra dimension of blackmail to their operations.

The most active Ransomware groups in France in 2024

For security reasons, we voluntarily limit the disclosure of detailed information about our specific tools. Our cyber watch unit constantly monitors the activity of ransomware groups.

LockBIT 2.0 & 3.0

LockBit made its debut in 2019. It primarily targets large organizations and uses military-grade encryption technology to hold organizations' IT systems hostage.

BlackCat ransomware

The digital enemy to watch closely in 2023... BlackCat ransomware, also known as Alphv ransomware, is considered to be one of the most sophisticated types of malware.

PYSA ransomware

Pysa ransomware has emerged as a major threat in the cyberthreat landscape. It was first reported by the Federal Bureau of Investigation (FBI) due to its increased activity and high impact.

Monti ransomware

The Monti ransomware stands out for its targeted cyberattacks and sophisticated infiltration strategy. Although still relatively new, it has already inflicted considerable damage on several organizations.

Hive ransomware

The Hive ransomware was a ransomware-as-a-service (RaaS) operation run by the eponymous cybercriminal organization between June 2021 and January 2023. Its main target was public institutions.

And many more...

Browse our knowledge base. We have compiled the available data on the following Ransomware strains

Top 10 ransomware groups january 2025
Cybersecurity

Top 10 ransomware groups for January 2025

January 2025 saw a dynamic shift in ransomware activity, characterized by the resurgence of established ransomware groups, the emergence of new players and increasingly sophisticated

Space Bears ransomware
Ransomware

Understanding Space Bears and Lexus ransomware

Cybersecurity is a constantly evolving field, and ransomware threats continue to diversify. Among the most recent and worrying are Space Bears and Lexus, two variants

monti conti ransomware
Ransomware groups

Monti Ransomware: the new threat to systems

The Monti ransomware has been in the news for some months now, thanks to targeted cyberattacks and a sophisticated infiltration strategy. Although relatively new to

ryuk ransomware
Ransomware groups

Understanding the Ryuk ransomware to protect your data

Cyber attacks are becoming increasingly sophisticated and dangerous, with serious consequences for businesses and governments. One of the most widespread and feared forms of attack

Cl0p ransomware
Ransomware groups

Clop ransomware: a growing threat

Clop ransomware has become a hot topic in the world of cybersecurity. Emerging as a major threat, it has targeted various institutions, particularly in the