Reference

Ransomware families: who they are and what they do

The names below appear in ransom notes and file extensions across the UAE and worldwide. Each entry explains the group, how it operates, what it targets and what the laboratory view on recovery is. Names are public threat-intelligence identifiers, not endorsements.

Quick reference

Check the extension on your encrypted files against this table. Extensions vary by affiliate and build, so send us samples to confirm.

FamilyFirst seenTypical extensionModelPrimary targetsStatus 2026
Karma2026.karmaUnder analysisUnder analysisNew in 2026
Peter2026.peterUnder analysisUnder analysisNew in 2026
Leila2026.LeilaUnder analysisUnder analysisNew in 2026
Qilin2022.qilin / randomRaaS, double extortionHealthcare, manufacturing, finance, ESXiMost active
Akira2023.akira .powerrangesRaaS, double extortionSMEs, VPN appliances, ESXiVery active
LockBit2019.lockbit / randomRaaSAll sectorsResurfaced (v5)
DragonForce2023.dragonforceRaaS "cartel"Retail, servicesActive
Play (PlayCrypt)2022.PLAYClosed groupGovernment, enterprisesActive
Medusa2021.MEDUSARaaSEducation, healthcare, ESXiActive
INC Ransom2023.INCClosed groupHealthcare, public sectorActive
Clop (Cl0p)2019.clop .Cl0pMass exploitationFile-transfer platformsCampaign-driven
Phobos / 8Base2018.id[...].[mail].extRaaS, SME-focusedSmall business via RDPCommon in UAE SMEs
Dharma / CrySIS2016.id-XXXX.[mail].extRaaS, RDP brute forceSmall businessPersistent
Makop2020.[id].[mail].makopRDP-basedSmall business, Asia and Middle EastPersistent
Mallox (TargetCompany)2021.mallox .xollamRaaS, SQL-server focusExposed MS SQL serversActive
STOP / Djvu20184-letter, e.g. .qazxConsumer, cracked softwareHome users, small officesVery common
BlackCat / ALPHV2021randomRaaS (Rust)Enterprises, healthcareDefunct 2024
RansomHub2024randomRaaSAll sectorsCollapsed 2025

How Ransomware-as-a-Service works

Most of the families below are businesses. A core team develops the encryptor, the leak site and the negotiation portal. Independent "affiliates" rent the platform, break into victims and deploy it. Affiliates keep 70 to 85 percent of any ransom. This is why the same family appears in wildly different attacks: the tooling is shared, the intruders are not.

In 2026 four operations, Qilin, Akira, The Gentlemen and LockBit, accounted for roughly four in ten publicly listed victims worldwide. Several groups have also announced "cartel" arrangements to share infrastructure. For the victim, the practical point is that the encryptor is a product with versions, bugs and known behaviours, and those can be studied.

Karma

New in 2026
First seen
2026
Extensions
.karma
Status
Under analysis

Karma is one of the new families recorded in 2026. Encrypted files are renamed with the .karma extension. Details of its operators, targets and encryption scheme are still being established, so each case is examined individually from the ransom note and file samples.

Laboratory view. Do not rename or delete the encrypted files. Send the ransom note and two or three .karma files so the exact variant can be confirmed and the recovery options assessed.

Peter

New in 2026
First seen
2026
Extensions
.peter
Status
Under analysis

Peter is a newly observed family in 2026. Affected files carry the .peter extension. Public information on this family is still limited, which makes sample-based identification the essential first step.

Laboratory view. Preserve the ransom note and the encrypted files exactly as found. Samples of .peter files allow the laboratory to compare the build against known encryptors.

Leila

New in 2026
First seen
2026
Extensions
.Leila
Status
Under analysis

Leila appeared in 2026 and appends the .Leila extension, with a capital L, to encrypted files. Its technical profile is still under analysis.

Laboratory view. New families often reuse code from older encryptors. Comparing .Leila samples with known builds is how the laboratory establishes whether a recovery method already exists.

Qilin

Most active in 2026RaaS
First seen
2022, as "Agenda"; rebranded Qilin
Extensions
.qilin, or a per-victim random string; note named README-RECOVER-[id].txt
Platforms
Windows, Linux, VMware ESXi (dedicated encryptor)
Encryption
AES-256 or ChaCha20 for files, RSA-4096 for keys; configurable partial encryption for speed

Qilin posts more new victims to its leak site each week than any other operation. It is written in Rust and Go, targets hypervisors directly and offers affiliates one of the highest revenue shares in the ecosystem, which explains its rapid growth. Attacks commonly start with stolen VPN credentials and end with encryption of ESXi datastores, which takes every virtual machine offline at once.

Laboratory view. Qilin's partial-encryption modes leave large sections of big files untouched. For databases and virtual disks this often allows structural reconstruction even when the encrypted blocks cannot be decrypted. Send samples of the largest affected files, not only small documents.

Akira

Very activeRaaS
First seen
March 2023
Extensions
.akira; Linux/ESXi variant .powerranges; note akira_readme.txt
Platforms
Windows, Linux, ESXi, Nutanix AHV
Encryption
ChaCha20 with RSA-wrapped keys; encrypts a percentage of each file depending on size

Akira is known for exploiting VPN appliances without multi-factor authentication and for its retro, green-on-black leak site. It collected an estimated 150 million US dollars in 2025 and remains one of the two most active operations. It targets mid-sized companies heavily, including in the Gulf.

Laboratory view. Earlier Akira Linux builds contained cryptographic weaknesses that allowed key recovery under specific conditions. Current builds are stronger, but the size-based partial encryption still makes database and VM reconstruction viable in many cases.

LockBit

ResurfacedRaaS
First seen
2019 ("ABCD"), LockBit 2.0 (2021), 3.0 "Black" (2022), 5.0 (late 2025)
Extensions
.lockbit, or a random 9-character string per build
Platforms
Windows, Linux, ESXi, macOS proof-of-concept
Encryption
AES with RSA-2048/4096 key wrapping; extremely fast encryptor

LockBit was the world's most prolific ransomware until its infrastructure was seized by law enforcement in February 2024. The leaked LockBit 3.0 builder has since been reused by dozens of unrelated criminals, and the original group returned with version 5 in late 2025. A "LockBit" ransom note today can come from almost anyone.

Laboratory view. Because so many amateur groups use the leaked builder with default or poorly configured settings, LockBit-family cases have an above-average recovery rate. Identifying the exact build is the first step.

DragonForce

ActiveRaaS "cartel"
First seen
2023
Extensions
.dragonforce; note readme.txt
Platforms
Windows, Linux, ESXi
Encryption
Derived from the leaked LockBit 3.0 and Conti code bases

DragonForce operates a white-label model in which affiliates can run their own "brand" on its infrastructure. It was behind the high-profile 2025 attacks on UK retailers and in September 2025 publicly proposed a coalition with LockBit and Qilin.

Laboratory view. The shared Conti/LockBit lineage means known analysis techniques apply. Recovery depends on the affiliate's configuration choices.

Play (PlayCrypt)

ActiveClosed group
First seen
June 2022
Extensions
.PLAY; note ReadMe.txt with only an email address
Platforms
Windows, ESXi
Encryption
AES-RSA hybrid, intermittent encryption

Play does not use affiliates and does not publish an initial ransom amount; victims must email the group. It had compromised roughly 900 organisations by mid-2025, exploiting Fortinet and Exchange vulnerabilities and using custom tools to steal data before encryption.

Laboratory view. Play's intermittent encryption pattern is well characterised. Large files such as SQL data files and VMDKs frequently retain enough intact structure for repair.

Medusa

ActiveRaaS
First seen
2021 (not related to MedusaLocker)
Extensions
.MEDUSA; note !!!READ_ME_MEDUSA!!!.txt
Platforms
Windows, and since 2025 custom ESXi payloads
Encryption
AES-256 with RSA

Medusa runs a public "Medusa Blog" leak site and has been the subject of a joint CISA/FBI advisory. It aggressively targets virtualised environments and applies a triple-extortion twist: victims have reported being contacted by a second actor claiming the first negotiator stole the payment.

Laboratory view. A clear example of why paying provides no certainty. Technical recovery of ESXi datastores is the reliable route.

INC Ransom

Active
First seen
July 2023
Extensions
.INC; note INC-README.txt / .html
Platforms
Windows, Linux, ESXi
Encryption
AES-128 CTR with Curve25519 key exchange, multiple speed modes

INC focuses on healthcare, education and public bodies and is known for careful, manual intrusions using legitimate administration tools. Its source code was offered for sale in 2024, and derivative "Lynx" builds have appeared.

Clop (Cl0p)

Campaign-driven
First seen
2019, from the CryptoMix family
Extensions
.clop, .Cl0p, .C_L_O_P
Model
Mass exploitation of file-transfer software (Accellion, GoAnywhere, MOVEit, Cleo)

Clop is unusual: in its largest campaigns it did not encrypt anything. It exploited zero-day vulnerabilities in file-transfer products, stole data from hundreds of organisations at once and extorted them with the threat of publication. It shows that "ransomware" today is often a data-theft problem first.

Phobos / 8Base

Common in UAE SMEsRaaS
First seen
2018 (Phobos); 8Base 2022
Extensions
.id[XXXXXXXX-1234].[email].phobos and variants .eking, .faust, .elbie, .8base
Entry
Brute-forced or purchased Remote Desktop credentials
Encryption
AES-256 per file, RSA-1024 wrapped keys

Phobos is a low-cost kit aimed at small and medium businesses with exposed RDP. 8Base is its most organised franchise. Both are extremely common in the Gulf region because of the number of small networks with remote desktop open to the internet.

Laboratory view. Phobos encrypts only the first part of large files, so databases, backups and virtual disks are often substantially repairable. Recovery rates in this family are high.

Dharma / CrySIS

Persistent
First seen
2016
Extensions
.id-XXXXXXXX.[email].ext, hundreds of variants (.dharma, .wallet, .arena, .cezar)
Entry
RDP brute force, manual deployment

The ancestor of Phobos. Dharma has been sold and resold as a kit for a decade and still appears weekly in small-business incidents. Attacks are hands-on: the intruder logs in over RDP, disables antivirus and runs the encryptor manually.

Laboratory view. Partial encryption of large files and known implementation errors in several builds make Dharma cases frequently recoverable.

Makop

Persistent
First seen
2020, from the Phobos lineage
Extensions
.[ID].[email].makop, also .mkp, .hinduism, .zbw
Entry
RDP brute force, phishing

Makop is widespread across the Middle East and Asia. It typically deletes shadow copies, disables recovery options and appends the operator's contact email to every file name.

Mallox (TargetCompany, Fargo)

Active
First seen
2021
Extensions
.mallox, .xollam, .FARGO3, .avast
Entry
Brute-forced Microsoft SQL Server accounts exposed to the internet

Mallox is the family most directly associated with database servers. It attacks weak SQL Server passwords, installs itself through the database engine and encrypts the data files of the very system it entered through.

Laboratory view. Because the attack starts inside SQL Server, transaction logs and page-level structures often survive. Database reconstruction is a core A-Lab capability for this family.

STOP / Djvu

Very common
First seen
2018
Extensions
Four random lowercase letters, e.g. .qazx, .wwza, .ttza; note _readme.txt
Entry
Cracked software, key generators, fake downloads

The most common ransomware for individuals and very small offices. It spreads through pirated software bundles and encrypts the first 150 KB of each file. When the malware cannot reach its server it uses an "offline key" shared across many victims.

Laboratory view. Offline-key cases are frequently fully recoverable. Even online-key cases benefit from the 150 KB limit: large media, archives and databases are mostly intact.

BlackCat / ALPHV

Defunct 2024
Active
November 2021 to March 2024
Extensions
Random 7-character string per victim
Notable
First major ransomware written in Rust; attacked healthcare at scale, then disappeared with an affiliate's 22 million dollar payment

BlackCat's exit is a lesson in itself. After a US healthcare provider reportedly paid, the operators kept the money, cheated their own affiliate and shut down. Many former affiliates moved to RansomHub and then to Qilin and DragonForce.

RansomHub

Collapsed 2025
Active
February 2024 to April 2025
Notable
Grew to over 700 victims in a year by recruiting former BlackCat, Conti and Scattered Spider members, then went offline abruptly

RansomHub's rise and fall shows how quickly the names change while the underlying people and code persist. A ransom note is a brand, not a fixed technical reality. The encryptor version in front of you is what determines your recovery options.