Ransomware Intelligence

killsec3

Ransomware group profile

232Victims
RussiaSource country
70Impact score
Also Known As
KillSecurity

Description

KillSec is a notorious ransomware group that has gained prominence for its aggressive attacks on critical infrastructure across various sectors. Known for employing advanced tactics, including double extortion methods, they encrypt data and threaten to leak sensitive information if ransom demands are not met. Their operations have increasingly targeted industries with less robust cybersecurity defenses, causing widespread disruption and financial damage.

Key insights

  • Targets critical infrastructure, particularly in healthcare and finance sectors.
  • Utilizes advanced obfuscation techniques to avoid detection.
  • Employed double extortion tactics, encrypting data and threatening leaks.
  • Gains access through spearphishing and exploiting software vulnerabilities.
  • Recent campaigns have increasingly used sophisticated ransomware variants.
  • Emerging trend involves leveraging zero-day vulnerabilities for attacks.

Threat Level & Status Breakdown

For killsec3 · Based on incidents in selected period

2.8threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality3.4/ 10

Status Breakdown

Data Leaked0.4%1
Negotiating0.9%2
Claimed15.1%35
First seenAug 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 20, 2026

Recent activity

Monthly attack count for killsec3 in the selected period

232Total attacks
168peak in Oct
23.2avg / month
AugSepOctNovDecJanFebMarMayJun04590135180

Intelligence

IOCs, YARA/Sigma rules, and related families for killsec3

  1. 7b3f4d34b8d3518c092d81506df05103
  2. de88ae471d8b95e5e10264aea5eb040fedb9bb71428385e7cff6c77a6ae47d97
  3. f0220f5d1f935f09d58e869247cfdb5d
  4. 8684e74d35baab30e8f8af7db486c2a339d3063feb2074109b8c96c1fea8313e
  5. 785b52e144577375abe4d1c785c451f60c423788
  6. c6d6c64d12cf9dd4474aa492697720af
  7. afcccd45bc700a75e46297bfdae0c47048dc14fc
  8. 4d0663cff0c5c3f29c81e9aefd37f16a318ff638986ecc60e9bce6c90b72606b
  9. ce02802067934e0eb072f69bf6427bf6
  10. 264e801035f64163ffa7cf05086ce4c7d1396956
  11. 2798bf4fd8e2bc591f656fa107bd871451574d543882ddec3020417964d2faa9
  12. 13265c0e32312a0763f3f8fed0f017a606355987ac9398bfb38f47c760ad32b0
  13. 95ae81de52655fac3f1b226f1896690566090640
  14. 49c720758b8a87e42829ffb38a0d7fe2a8c36dc3007abfabbea76155185d2902
  15. 0e71728e5e6a762923fc0372e2047e0d969bcc5efbf4f3010df2ff6576cab725
  16. d4757f035c3447c33c2347101d08c1e798f1a044
  17. 94b3250879e3600b24318e47620ae5aab15d8640
  18. b64d3d38de70cade9b423e87c571a65c
  19. 8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d
  20. d8edd46220059541ff397f74bfd271336dda702c6b1869e8a081c71f595a9e68
  21. 401c5d2157d303df1ca465ff4097ee4474574c39f614cbb5734193a3917354c0
  22. e345d793477abbecc2c455c8c76a925c0dfe99ec4c65b7c353e8a8c8b14da2b6
  23. f10bd5443148d47fbf7c6a6998651eb9bda4c7c9213f9e5a65a76e98637cb748
  24. 5303183d82b8c4d2a47fab4167868a8cfbf8d56d3397701ab890e88c99105ae4
  25. 0df13fd42fb4a4374981474ea87895a3830eddcc7f3bd494e76acd604c4004f7
  26. f001329114937fbc439f251c803ba825
  27. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  28. 8ad67a1b7a5f2428c93f7a13a398e39c
  29. f49c5ca09e04cfb0e5e8532946d183e9cce6595ce364a59b0c9423a828be8415
  30. 4f88d3977a24fb160fc3ba69821287a197ae9b04493d705dc2fe939442ba6461
  31. 1d5ef46357eb2298b1c3c4faccbaafa729137613
  32. a5febb4b5ba6572594de87d2a9de6df65d49da755385bf3d3d4d054772ce493c
  33. 0303f89829763e734b1f9d4f46671e59bfaa1be5d8ec84d35a203efbfcb9bb15
  34. f9db8601d94df9c026331066a2ba9ae1
  35. 011fdaa3a7d7f7badc6088eda2a21fa808bcefe2c0cd24b21a89271102c5be60
  36. 501e5cc4cb65d55cff934e7447528fef5243578d
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for killsec3

Other

T1486

T1486

T1490

T1490

T1566.002

T1566.002

T1059.001

T1059.001

T1047

T1047

T1078

T1078

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1071.001

T1071.001

Victims(200)

CompanyDomainCountryIndustryStatusDiscovered
csinsurance.mxMX MexicoFinancial Services
Unknown
18 days ago
acehospital.inIN IndiaHealthcare
Unknown
18 days ago
dsdlawfirm.comProfessional Services
Unknown
about 1 month ago
mrs holdingsProfessional Services
Unknown
about 1 month ago
Medical PAYFinancial Services
Unknown
about 2 months ago
hospitalvetdiadema24h.com.brBR BrazilHealthcare
Unknown
3 months ago
palram.comIL IsraelManufacturing
Unknown
3 months ago
shlomo bit
Unknown
3 months ago
MyFair
Unknown
4 months ago
MedicalGPTHealthcare
Unknown
4 months ago
yurdriversnetworkTransportation
Unknown
4 months ago
primaria ungheniRO RomaniaGovernment & Defense
Unknown
4 months ago
Onlinedivorcetexasonlinedivorcetexas.comUS United StatesRetail & E-Commerce
Unknown
4 months ago
Orainorain.ioUS United StatesFinancial Services
Unknown
4 months ago
Getly
Unknown
4 months ago
brooklyn groupRetail & E-Commerce
Unknown
5 months ago
X-CD TechnologiesTechnology
Unknown
5 months ago
NextCapitalTrustFinancial Services
Unknown
5 months ago
publicsafety.ohio.govUS United StatesGovernment & Defense
Unknown
5 months ago
grade resultsEducation
Unknown
6 months ago

Page 1 of 10