Ransomware Intelligence

killsec3

Ransomware group profile

232Victims
RussiaSource country
72Impact score
Also Known As
KillSecurity

Description

KillSec is a notorious ransomware group that has gained prominence for its aggressive attacks on critical infrastructure across various sectors. Known for employing advanced tactics, including double extortion methods, they encrypt data and threaten to leak sensitive information if ransom demands are not met. Their operations have increasingly targeted industries with less robust cybersecurity defenses, causing widespread disruption and financial damage.

Key insights

  • Targets critical infrastructure, particularly in healthcare and finance sectors.
  • Utilizes advanced obfuscation techniques to avoid detection.
  • Employed double extortion tactics, encrypting data and threatening leaks.
  • Gains access through spearphishing and exploiting software vulnerabilities.
  • Recent campaigns have increasingly used sophisticated ransomware variants.
  • Emerging trend involves leveraging zero-day vulnerabilities for attacks.

Threat Level & Status Breakdown

For killsec3 · Based on incidents in selected period

2.8threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality3.4/ 10

Status Breakdown

Data Leaked0.4%1
Negotiating0.9%2
Claimed15.1%35
First seenAug 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 25, 2026

Recent activity

Monthly attack count for killsec3 in the selected period

232Total attacks
168peak in Oct
23.2avg / month
AugSepOctNovDecJanFebMarMayJun04590135180

Intelligence

IOCs, YARA/Sigma rules, and related families for killsec3

  1. 7b3f4d34b8d3518c092d81506df05103
  2. de88ae471d8b95e5e10264aea5eb040fedb9bb71428385e7cff6c77a6ae47d97
  3. 4896cfff334f846079174d3ea2d541eec72690a0
  4. 5d0509f68a9b7c415a726be75a078180e3f02e59866f193b0a99eee8e39c874f
  5. f0220f5d1f935f09d58e869247cfdb5d
  6. a88f34c0b3a6df683bb89058f8e7a7d534698069
  7. e8c56706296175195a03348b9cd5064e60c36fdeaa6e5fd7b5614ca6bca1c3f8
  8. 106248206f1c995a76058999ccd6a6d0f420461e
  9. 977054802de7b583a38e0524feefa7356c47c53dd49de8c3d533e7689095f9ac
  10. cbe82e23f8920512b1cf56f3b5b0bca61ec137b9
  11. 8684e74d35baab30e8f8af7db486c2a339d3063feb2074109b8c96c1fea8313e
  12. 508a20f25a9e0797b3dea4b5055b16af
  13. f52e18b7c8417c7573125c0047adb32d8d813529
  14. 785b52e144577375abe4d1c785c451f60c423788
  15. c6d6c64d12cf9dd4474aa492697720af
  16. 0a3b0cd349210c4488ef71e8b331ba47
  17. c5fa7fd1ff45c5cfaec851795f4c2e15326046f3022778bdf6f37b7b1dd75f5c
  18. e9ea1026cf176f4d497a27d0c856bedf
  19. 3cfcb57b94e69372cd2815dc63d66ab4b4ac4fec48b3b092f76ae5c9beaa353f
  20. 311ec9208f5fe3f22733fca1e6388ea9c0327be0836c955d2cf6a22317d4bdca
  21. c3ecbc6023bfa170c31eaf7033b68495798e305111ca9f2f203f58b9ec942384
  22. afcccd45bc700a75e46297bfdae0c47048dc14fc
  23. 4d0663cff0c5c3f29c81e9aefd37f16a318ff638986ecc60e9bce6c90b72606b
  24. ce02802067934e0eb072f69bf6427bf6
  25. a0b47c781e70877ad4e721ba49f64fc0bc469e38750f070a232d12f03d9990bc
  26. cb2d18fb91f0cd88e82cb36b614cfedf3e4ae49b
  27. 264e801035f64163ffa7cf05086ce4c7d1396956
  28. 4d590a9640093bbda21597233b400b037278366660ba2c3128795bc85d35be72
  29. ceaec46f7d65706ffc639e75c515d0a35a21338d
  30. 2798bf4fd8e2bc591f656fa107bd871451574d543882ddec3020417964d2faa9
  31. 636d4f1e3dcf0332a815ce3f526a02df3c4ef2890a74521d05d6050917596748
  32. f8c80bbecbfb38f252943ee6beec98edc93cd734ec70ccd2565ab1c4db5f072f
  33. cab1c4c675f1d996b659bab1ddb38af365190e450dec3d195461e4e4ccf1c286
  34. 13265c0e32312a0763f3f8fed0f017a606355987ac9398bfb38f47c760ad32b0
  35. 95ae81de52655fac3f1b226f1896690566090640
  36. 62242df8c7db337e46f44c4323ac9738adba89f095deb8e5d873ee8b35fa5079
  37. 49c720758b8a87e42829ffb38a0d7fe2a8c36dc3007abfabbea76155185d2902
  38. 0e71728e5e6a762923fc0372e2047e0d969bcc5efbf4f3010df2ff6576cab725
  39. 4aeb65e3c9a2ca3177f3525686d3b9f4a39ca2b749acd8431589ee28fa528bb9
  40. 2f3d67740bb7587ff70cc7319e9fe5c517c0e55345bf53e01b3019e415ff098b
  41. 0a93c86ef96d81c90485df71a3b90961
  42. d4757f035c3447c33c2347101d08c1e798f1a044
  43. 94b3250879e3600b24318e47620ae5aab15d8640
  44. b64d3d38de70cade9b423e87c571a65c
  45. c30a14b595fa334084cd32fa60b3c827
  46. 194d739fa93970d63dade70aae7c3b9ac8a6938be9f0e2d470d3adf8c106bfad
  47. 6e426247c1fdaaa09091b5ab4bb5a76b
  48. 4e1ed311021ce99a7556af05ca520a5569853eed
  49. f194b0bc35b74f6ed410d8a35e471c57
  50. c43b0006b3f7cd88d31aded8579830168a44ba79
  51. 5492947d2b85a57f40201cd7d1351c3d4b92ae88
  52. 470f0db6a56a879985c62cd71c5a98a4
  53. 1f38a9e17e5096bca84b6ec87eb5470b2ce4450a6a03b3e41b38dbd91ab281da
  54. 8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d
  55. b0fd9705e8f83129f97f9111b03642fe
  56. 2af2841bf925ed1875faadcbb0ef316c641e1dcdb61d1fbf80c3443c2fc9454f
  57. abd4263c97ab33b22f67e581ebb09ec7b98e4084dd32a7eca6502d3737715769
  58. d8edd46220059541ff397f74bfd271336dda702c6b1869e8a081c71f595a9e68
  59. aa6a9c25aff0e773d4189480171afcf7d0f69ad9
  60. a5fd7e67d46f4d2239c43101666dd0582367bd8d
  61. f08676eeb489087bc0e47bd08a3f7c4b57ef5941698bc09d30857c650763859c
  62. 4c917d92ded082bd8623d5e148d4b65ed02447bad3157cad8b66194b93150262
  63. 710e80fb64e08f20ab58c20ccdbc966f6e3b54511775e8ed99ff0bcf51690227
  64. 49a58ddf3bedc37b61a8205bb3805413
  65. 401c5d2157d303df1ca465ff4097ee4474574c39f614cbb5734193a3917354c0
  66. e345d793477abbecc2c455c8c76a925c0dfe99ec4c65b7c353e8a8c8b14da2b6
  67. 8b6afbf73a9b98eec01d8510815a044cd036743b64fef955385cbca80ae94f15
  68. f10bd5443148d47fbf7c6a6998651eb9bda4c7c9213f9e5a65a76e98637cb748
  69. 7ae31f517fc172a4924f9ee0321c2b013cd3836c97166dac4bcfc5c108d30596
  70. de998bd26ea326e610cc70654499cebfd594cc973438ac421e4c7e1f3b887617
  71. a31642046471ec138bb66271e365a01569ff8d7f
  72. 68320761a01f9df5f1bdc71c94326311
  73. 5303183d82b8c4d2a47fab4167868a8cfbf8d56d3397701ab890e88c99105ae4
  74. af34b30695539f108741648a1fce012bdf81cc75
  75. 0df13fd42fb4a4374981474ea87895a3830eddcc7f3bd494e76acd604c4004f7
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for killsec3

Other

T1486

T1486

T1490

T1490

T1566.002

T1566.002

T1059.001

T1059.001

T1047

T1047

T1078

T1078

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1071.001

T1071.001

Victims(200)

CompanyDomainCountryIndustryStatusDiscovered
csinsurance.mxMX MexicoFinancial Services
Unknown
24 days ago
acehospital.inIN IndiaHealthcare
Unknown
24 days ago
dsdlawfirm.comProfessional Services
Unknown
about 1 month ago
mrs holdingsProfessional Services
Unknown
about 2 months ago
Medical PAYFinancial Services
Unknown
about 2 months ago
hospitalvetdiadema24h.com.brBR BrazilHealthcare
Unknown
3 months ago
palram.comIL IsraelManufacturing
Unknown
3 months ago
shlomo bit
Unknown
4 months ago
MyFair
Unknown
4 months ago
MedicalGPTHealthcare
Unknown
4 months ago
yurdriversnetworkTransportation
Unknown
4 months ago
primaria ungheniRO RomaniaGovernment & Defense
Unknown
4 months ago
Onlinedivorcetexasonlinedivorcetexas.comUS United StatesRetail & E-Commerce
Unknown
4 months ago
Orainorain.ioUS United StatesFinancial Services
Unknown
4 months ago
Getly
Unknown
5 months ago
brooklyn groupRetail & E-Commerce
Unknown
5 months ago
X-CD TechnologiesTechnology
Unknown
5 months ago
NextCapitalTrustFinancial Services
Unknown
6 months ago
publicsafety.ohio.govUS United StatesGovernment & Defense
Unknown
6 months ago
grade resultsEducation
Unknown
6 months ago

Page 1 of 10