The names below appear in ransom notes and file extensions across the UAE and worldwide. Each entry explains the group, how it operates, what it targets and what the laboratory view on recovery is. Names are public threat-intelligence identifiers, not endorsements.
Check the extension on your encrypted files against this table. Extensions vary by affiliate and build, so send us samples to confirm.
| Family | First seen | Typical extension | Model | Primary targets | Status 2026 |
|---|---|---|---|---|---|
| Karma | 2026 | .karma | Under analysis | Under analysis | New in 2026 |
| Peter | 2026 | .peter | Under analysis | Under analysis | New in 2026 |
| Leila | 2026 | .Leila | Under analysis | Under analysis | New in 2026 |
| Qilin | 2022 | .qilin / random | RaaS, double extortion | Healthcare, manufacturing, finance, ESXi | Most active |
| Akira | 2023 | .akira .powerranges | RaaS, double extortion | SMEs, VPN appliances, ESXi | Very active |
| LockBit | 2019 | .lockbit / random | RaaS | All sectors | Resurfaced (v5) |
| DragonForce | 2023 | .dragonforce | RaaS "cartel" | Retail, services | Active |
| Play (PlayCrypt) | 2022 | .PLAY | Closed group | Government, enterprises | Active |
| Medusa | 2021 | .MEDUSA | RaaS | Education, healthcare, ESXi | Active |
| INC Ransom | 2023 | .INC | Closed group | Healthcare, public sector | Active |
| Clop (Cl0p) | 2019 | .clop .Cl0p | Mass exploitation | File-transfer platforms | Campaign-driven |
| Phobos / 8Base | 2018 | .id[...].[mail].ext | RaaS, SME-focused | Small business via RDP | Common in UAE SMEs |
| Dharma / CrySIS | 2016 | .id-XXXX.[mail].ext | RaaS, RDP brute force | Small business | Persistent |
| Makop | 2020 | .[id].[mail].makop | RDP-based | Small business, Asia and Middle East | Persistent |
| Mallox (TargetCompany) | 2021 | .mallox .xollam | RaaS, SQL-server focus | Exposed MS SQL servers | Active |
| STOP / Djvu | 2018 | 4-letter, e.g. .qazx | Consumer, cracked software | Home users, small offices | Very common |
| BlackCat / ALPHV | 2021 | random | RaaS (Rust) | Enterprises, healthcare | Defunct 2024 |
| RansomHub | 2024 | random | RaaS | All sectors | Collapsed 2025 |
Most of the families below are businesses. A core team develops the encryptor, the leak site and the negotiation portal. Independent "affiliates" rent the platform, break into victims and deploy it. Affiliates keep 70 to 85 percent of any ransom. This is why the same family appears in wildly different attacks: the tooling is shared, the intruders are not.
In 2026 four operations, Qilin, Akira, The Gentlemen and LockBit, accounted for roughly four in ten publicly listed victims worldwide. Several groups have also announced "cartel" arrangements to share infrastructure. For the victim, the practical point is that the encryptor is a product with versions, bugs and known behaviours, and those can be studied.
Karma is one of the new families recorded in 2026. Encrypted files are renamed with the .karma extension. Details of its operators, targets and encryption scheme are still being established, so each case is examined individually from the ransom note and file samples.
Peter is a newly observed family in 2026. Affected files carry the .peter extension. Public information on this family is still limited, which makes sample-based identification the essential first step.
Leila appeared in 2026 and appends the .Leila extension, with a capital L, to encrypted files. Its technical profile is still under analysis.
Qilin posts more new victims to its leak site each week than any other operation. It is written in Rust and Go, targets hypervisors directly and offers affiliates one of the highest revenue shares in the ecosystem, which explains its rapid growth. Attacks commonly start with stolen VPN credentials and end with encryption of ESXi datastores, which takes every virtual machine offline at once.
Akira is known for exploiting VPN appliances without multi-factor authentication and for its retro, green-on-black leak site. It collected an estimated 150 million US dollars in 2025 and remains one of the two most active operations. It targets mid-sized companies heavily, including in the Gulf.
LockBit was the world's most prolific ransomware until its infrastructure was seized by law enforcement in February 2024. The leaked LockBit 3.0 builder has since been reused by dozens of unrelated criminals, and the original group returned with version 5 in late 2025. A "LockBit" ransom note today can come from almost anyone.
DragonForce operates a white-label model in which affiliates can run their own "brand" on its infrastructure. It was behind the high-profile 2025 attacks on UK retailers and in September 2025 publicly proposed a coalition with LockBit and Qilin.
Play does not use affiliates and does not publish an initial ransom amount; victims must email the group. It had compromised roughly 900 organisations by mid-2025, exploiting Fortinet and Exchange vulnerabilities and using custom tools to steal data before encryption.
Medusa runs a public "Medusa Blog" leak site and has been the subject of a joint CISA/FBI advisory. It aggressively targets virtualised environments and applies a triple-extortion twist: victims have reported being contacted by a second actor claiming the first negotiator stole the payment.
INC focuses on healthcare, education and public bodies and is known for careful, manual intrusions using legitimate administration tools. Its source code was offered for sale in 2024, and derivative "Lynx" builds have appeared.
Clop is unusual: in its largest campaigns it did not encrypt anything. It exploited zero-day vulnerabilities in file-transfer products, stole data from hundreds of organisations at once and extorted them with the threat of publication. It shows that "ransomware" today is often a data-theft problem first.
Phobos is a low-cost kit aimed at small and medium businesses with exposed RDP. 8Base is its most organised franchise. Both are extremely common in the Gulf region because of the number of small networks with remote desktop open to the internet.
The ancestor of Phobos. Dharma has been sold and resold as a kit for a decade and still appears weekly in small-business incidents. Attacks are hands-on: the intruder logs in over RDP, disables antivirus and runs the encryptor manually.
Makop is widespread across the Middle East and Asia. It typically deletes shadow copies, disables recovery options and appends the operator's contact email to every file name.
Mallox is the family most directly associated with database servers. It attacks weak SQL Server passwords, installs itself through the database engine and encrypts the data files of the very system it entered through.
The most common ransomware for individuals and very small offices. It spreads through pirated software bundles and encrypts the first 150 KB of each file. When the malware cannot reach its server it uses an "offline key" shared across many victims.
BlackCat's exit is a lesson in itself. After a US healthcare provider reportedly paid, the operators kept the money, cheated their own affiliate and shut down. Many former affiliates moved to RansomHub and then to Qilin and DragonForce.
RansomHub's rise and fall shows how quickly the names change while the underlying people and code persist. A ransom note is a brand, not a fixed technical reality. The encryptor version in front of you is what determines your recovery options.