THREAT‑WATCH logo

THREAT‑WATCH

Threat Actors

Ransomware & Financially Motivated Groups

These are the groups a Greek mid-market company is realistically going to meet. They are businesses: they pick targets on expected return, not ideology, which means downtime cost and ability to pay matter more to them than your sector's strategic importance. Most operate an affiliate model, where the group builds the ransomware and rents it to independent operators who do the actual intrusion. That structure is why takedowns rarely end anything permanently: disrupting the brand leaves the affiliates, who reappear under a new name within months. It also means the intrusion tradecraft you face is whatever the affiliate happens to be good at, rather than a single consistent playbook. The profiles below describe how each group operates and what its activity implies for defence.

Attribution in this field is rarely a matter of courtroom-level proof; the summaries below reflect what has been publicly attributed by government agencies, law enforcement, and established security researchers, not independent claims by THREAT‑WATCH. Status (active/disrupted/defunct) reflects the most recent public reporting available and can change.

LockBit

Disrupted

LockBit Black, LockBit 3.0

Ransomware-as-a-Service (financially motivated)

A ransomware-as-a-service operation that was, by volume, the most active ransomware group globally before an international law enforcement takedown in February 2024.

LockBit ran an affiliate model that let independent criminal groups use its ransomware in exchange for a cut of ransom payments, which let it scale to claim over 2,000 victims and extort more than $120 million. In February 2024, the FBI, UK's National Crime Agency, Europol, and international partners executed Operation Cronos, seizing LockBit's servers, leak site, and source code, and deliberately eroding trust between LockBit and its roughly 200 affiliates. Attacks attributed to LockBit dropped sharply afterward, though the ransomware-as-a-service model it popularized continues through successor groups.

Target SectorsManufacturing, healthcare, financial services, public sector, and professional services, largely indiscriminate by industry.

Ransomware Detection & Response

BlackCat / ALPHV

Defunct

ALPHV, Noberus

Ransomware-as-a-Service (financially motivated)

A ransomware-as-a-service operation active from late 2021 that collapsed in an apparent exit scam in March 2024, stealing an affiliate's ransom payment instead of paying out.

BlackCat was known for being written in the Rust programming language, unusual for ransomware at the time, and for aggressive double-extortion tactics. By September 2023, the FBI estimated it had compromised over 1,000 victims and collected close to $300 million in ransom payments, second only to LockBit. After a US law enforcement disruption of its infrastructure in December 2023, the operation exit-scammed in March 2024, taking roughly $22 million meant for an affiliate rather than paying out. The original service has not resumed; many of its estimated 90+ affiliates are believed to have moved to successor operations such as RansomHub and Embargo.

Target SectorsHealthcare, financial services, and other sectors handling high-value data, targeted opportunistically.

Ransomware Detection & Response

Akira

Active

Ransomware-as-a-Service (financially motivated)

A closed ransomware-as-a-service operation active since April 2023 that became one of the most prolific ransomware groups globally by ransom proceeds in 2025.

Akira uses the standard double-extortion model, encrypting systems while also stealing data to pressure payment. The group generated an estimated $150 million in 2025 alone and has shown a consistent ability to adapt its targeting and tooling in response to law enforcement pressure. Activity has continued to accelerate into 2026, with monthly victim counts posted on its leak site more than doubling between February and March 2026.

Target SectorsManufacturing, professional services, healthcare, and education, with a pattern of exploiting VPN and remote-access vulnerabilities for initial access.

Ransomware Detection & Response

Cl0p

Active

Clop, TA505

Data extortion (financially motivated)

A group known for mass-exploiting vulnerabilities in file-transfer and enterprise software to steal data at scale, often without deploying encryption at all.

Cl0p's signature approach is exploiting a single vulnerability in widely used enterprise software to compromise dozens or hundreds of organizations in one campaign, then extorting them over stolen data rather than encrypting systems. Its 2023 mass-exploitation of a MOVEit Transfer vulnerability affected thousands of downstream organizations. In 2026, Cl0p ran a comparable campaign exploiting a vulnerability in PTC's Windchill and FlexPLM product lifecycle management software, naming over 40 organizations including major manufacturers. As of mid-2026, Cl0p remained highly active, with over 1,300 victims claimed on its leak site.

Target SectorsAny organization using the specific enterprise software being mass-exploited in a given campaign, span across manufacturing, finance, and professional services.

24/7 SOC Monitoring & MDR

FIN7

Active

Carbon Spider, Sangria Tempest

Financially motivated

A financially motivated group active since around 2013, historically known for targeting point-of-sale systems and, more recently, for links to multiple ransomware affiliate operations.

FIN7 originally focused on stealing payment card data from retail and hospitality point-of-sale systems using spear-phishing to gain initial access. Over its long operational history it has repeatedly reorganized under different front-company identities and has been linked by researchers to ransomware deployment through affiliations with multiple ransomware-as-a-service brands over the years. Its longevity and repeated reinvention make it one of the most persistent financially motivated threat groups tracked by the security industry.

Target SectorsRetail, hospitality, restaurants, and increasingly a broader range of sectors as it has diversified beyond point-of-sale theft.

Phishing Training

Scattered Spider

Active

UNC3944, Octo Tempest, Muddled Libra

Financially motivated / extortion

A financially motivated group known for sophisticated social engineering, particularly help-desk impersonation and SIM swapping, that has evolved into deploying ransomware directly.

Unlike most ransomware operators, Scattered Spider's core skill is manipulating people, not exploiting software: calling IT help desks impersonating employees to reset credentials and bypass MFA, or SIM-swapping a target's phone number to intercept authentication codes. A joint FBI/CISA advisory (updated July 2025) documented the group's shift toward deploying DragonForce ransomware and targeting VMware ESXi environments directly. Despite multiple arrests of alleged members through 2024 and 2025, its decentralized structure has kept it operationally resilient, with activity continuing into 2026.

Target SectorsTechnology, telecommunications, financial services, and increasingly critical infrastructure and retail.

Phishing Training