Uptime Hamster: 11d 11h 50mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza knight

knight

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Cyclops, APT ICEFOG, APT REDBALDKNIGHT, DNSep, ironhusky, nccTrojan, phantomnet, piratepanda, portdoor, smanager, darknights, dknife, spellbinder, wizardnet
Ver en IntelTracker → APTTrail →
Knight is a ransomware-as-a-service (RaaS) operation that emerged in July 2023, representing a rebrand and evolution of the earlier Cyclops ransomware, also known as Cyclops 2.0. The group operates with a clear financial motivation, employing multi-extortion tactics to pressure victims into paying ransoms. A distinguishing feature of Knight is its offering of both normal and 'lite' versions of its payloads, designed to cater to various attack scales. The RaaS program provides affiliates with a builder, expanded toolsets, and panel access to create payloads and manage campaigns, often incorporating unique features like personalized support and distinct TOR domains for each target. The group's alleged origin is Russia and Europe, though this is based on their own claims of being a team of four individuals. Knight is commonly referred to by its former alias, Cyclops, and its source code was later sold in February 2024, leading to the emergence of the RansomHub ransomware, which is believe

Aliases del actor

CyclopsAPT ICEFOGAPT REDBALDKNIGHTDNSepironhuskynccTrojanphantomnetpiratepandaportdoorsmanagerdarknightsdknifespellbinderwizardnet

Actores similares

apt-redbaldknightactor · 1apt-icefogactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownblog.talosintelligence.comAPT REDBALDKNIGHT indicators and references
Repositoriounknowngithub.comdarknights indicators and references
DLS / leak siteunknownraw.githubusercontent.comdarknights indicators and references
DLS / leak siteunknownblog.talosintelligence.comdarknights indicators and references
Repositoriounknowngithub.comdarknights indicators and references
Repositoriounknowngithub.comdarknights indicators and references
DLS / leak siteunknownwww.virustotal.comdarknights indicators and references
DLS / leak siteunknownwww.welivesecurity.comdarknights indicators and references
X/Twitterunknownx.comdarknights indicators and references
X/Twitterunknown110.92.64.117APTTrailURLhttpdarknights indicators and references
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: knight
Tecnicas MITRE
T1090, T1543, T1547, T1036, T1195, T1566
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAmerican SamoaAustraliaBrazilCanadaChileChinaColombiaGermanySpain

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesSoftware PublishersEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationAdministrative &Waste Management

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com