HackerFeeds
Back to ransomware overview

YARA Detection Rules

340 groups with published YARA rules · 340 rules · 290.8 KB total. Mirrored from ransomware.live.

Groups with detection rules

#GroupRulesTotal size
10apt
1
0.4 KBDownload JSON
20mega
1
0.4 KBDownload JSON
38base
1
0.8 KBDownload JSON
4abrahams_ax
1
0.5 KBDownload JSON
5abyss
1
0.4 KBDownload JSON
6adminlocker
1
0.5 KBDownload JSON
7againstthewest
1
0.5 KBDownload JSON
8agl0bgvycg
1
0.5 KBDownload JSON
9ailock
1
1.1 KBDownload JSON
10akira
1
2.1 KBDownload JSON
11ako
1
0.4 KBDownload JSON
12alp-001
1
0.4 KBDownload JSON
13alphalocker
1
0.5 KBDownload JSON
14alphv
1
1.1 KBDownload JSON
15anubis
1
0.4 KBDownload JSON
16apos
1
0.4 KBDownload JSON
17apt73
1
0.4 KBDownload JSON
18arcusmedia
1
0.5 KBDownload JSON
19argonauts
1
0.5 KBDownload JSON
20arkana
1
0.4 KBDownload JSON
21arvinclub
1
0.5 KBDownload JSON
22atomsilo
1
0.4 KBDownload JSON
23auditteam
1
0.5 KBDownload JSON
24aurora
1
0.4 KBDownload JSON
25avaddon
1
0.9 KBDownload JSON
26avos
1
0.4 KBDownload JSON
27avoslocker
1
0.9 KBDownload JSON
28aware
1
0.4 KBDownload JSON
29aztroteam
1
0.5 KBDownload JSON
30babuk
1
3.7 KBDownload JSON
31babuk2
1
0.4 KBDownload JSON
32babyduck
1
0.4 KBDownload JSON
33beast
1
0.9 KBDownload JSON
34benzona
1
0.4 KBDownload JSON
35bert
1
0.4 KBDownload JSON
36bianlian
1
0.8 KBDownload JSON
37blackbasta
1
7.3 KBDownload JSON
38blackbyte
1
1.5 KBDownload JSON
39blacklock
1
0.5 KBDownload JSON
40blackmatter
1
0.5 KBDownload JSON
41blacknevas
1
0.5 KBDownload JSON
42blackout
1
0.4 KBDownload JSON
43blackshadow
1
0.5 KBDownload JSON
44blackshrantac
1
0.5 KBDownload JSON
45blacksuit
1
2.1 KBDownload JSON
46blacktor
1
0.4 KBDownload JSON
47blackwater
1
0.5 KBDownload JSON
48bluebox
1
0.4 KBDownload JSON
49bluelocker
1
1.0 KBDownload JSON
50bluesky
1
0.4 KBDownload JSON
51bonacigroup
1
0.5 KBDownload JSON
52bqtlock
1
0.4 KBDownload JSON
53braincipher
1
0.5 KBDownload JSON
54bravox
1
0.4 KBDownload JSON
55brotherhood
1
0.5 KBDownload JSON
56cactus
1
1.0 KBDownload JSON
57cephalus
1
0.4 KBDownload JSON
58chaos
1
1.4 KBDownload JSON
59cheers
1
0.4 KBDownload JSON
60chilelocker
1
0.5 KBDownload JSON
61chort
1
0.4 KBDownload JSON
62cicada3301
1
0.9 KBDownload JSON
63ciphbit
1
0.4 KBDownload JSON
64cipherforce
1
0.5 KBDownload JSON
65cloak
1
0.5 KBDownload JSON
66clop
1
9.9 KBDownload JSON
67cmdorganization
1
0.5 KBDownload JSON
68coinbasecartel
1
0.5 KBDownload JSON
69contfr
1
0.4 KBDownload JSON
70conti
1
0.9 KBDownload JSON
71cooming
1
0.4 KBDownload JSON
72crazyhunter
1
0.4 KBDownload JSON
73crosslock
1
0.5 KBDownload JSON
74cry0
1
0.4 KBDownload JSON
75crylock
1
0.4 KBDownload JSON
76cryp70n1c0d3
1
0.5 KBDownload JSON
77cryptbb
1
0.4 KBDownload JSON
78cryptnet
1
0.4 KBDownload JSON
79crypto24
1
0.4 KBDownload JSON
80cuba
1
0.9 KBDownload JSON
81cyclops
1
0.4 KBDownload JSON
82d4rk4rmy
1
0.4 KBDownload JSON
83dagonlocker
1
0.5 KBDownload JSON
84daixin
1
0.4 KBDownload JSON
85dan0n
1
0.4 KBDownload JSON
86darkangels
1
0.5 KBDownload JSON
87darkbit
1
0.4 KBDownload JSON
88darkleakmarket
1
0.5 KBDownload JSON
89darkpower
1
0.4 KBDownload JSON
90darkrace
1
0.4 KBDownload JSON
91darkside
1
0.4 KBDownload JSON
92darkvault
1
0.5 KBDownload JSON
93datacarry
1
0.5 KBDownload JSON
94datakeeper
1
0.5 KBDownload JSON
95dataleak
1
0.4 KBDownload JSON
96desolator
1
0.5 KBDownload JSON
97devman
1
0.4 KBDownload JSON
98diavol
1
0.8 KBDownload JSON
99direwolf
1
0.4 KBDownload JSON
100dispossessor
1
0.4 KBDownload JSON
101donex
1
0.5 KBDownload JSON
102donutleaks
1
0.4 KBDownload JSON
103doppelpaymer
1
0.9 KBDownload JSON
104dragonforce
1
0.5 KBDownload JSON
105dragonransomware
1
0.5 KBDownload JSON
106dread
1
0.4 KBDownload JSON
107dunghill
1
0.4 KBDownload JSON
108ech0raix
1
0.4 KBDownload JSON
109eldorado
1
0.5 KBDownload JSON
110embargo
1
0.5 KBDownload JSON
111entropy
1
0.5 KBDownload JSON
112ep918
1
0.4 KBDownload JSON
113esxiargs
1
0.4 KBDownload JSON
114everest
1
0.5 KBDownload JSON
115exitium
1
0.4 KBDownload JSON
116exorcist
1
0.4 KBDownload JSON
117fletchen
1
0.4 KBDownload JSON
118flocker
1
0.4 KBDownload JSON
119fog
1
0.8 KBDownload JSON
120frag
1
0.4 KBDownload JSON
121freecivilian
1
0.5 KBDownload JSON
122fsteam
1
0.4 KBDownload JSON
123fulcrumsec
1
0.5 KBDownload JSON
124funksec
1
0.5 KBDownload JSON
125gdlockersec
1
0.5 KBDownload JSON
126genesis
1
0.4 KBDownload JSON
127global
1
0.4 KBDownload JSON
128grief
1
9.0 KBDownload JSON
129groove
1
0.4 KBDownload JSON
130gunra
1
0.4 KBDownload JSON
131hades
1
0.9 KBDownload JSON
132handala
1
0.4 KBDownload JSON
133haron
1
0.4 KBDownload JSON
134hellcat
1
0.4 KBDownload JSON
135helldown
1
0.5 KBDownload JSON
136hellogookie
1
0.5 KBDownload JSON
137hellokitty
1
1.3 KBDownload JSON
138hive
1
3.0 KBDownload JSON
139holyghost
1
0.5 KBDownload JSON
140hotarus
1
0.4 KBDownload JSON
141hunters
1
1.0 KBDownload JSON
142icefire
1
0.5 KBDownload JSON
143imncrew
1
0.4 KBDownload JSON
144incransom
1
1.8 KBDownload JSON
145insane
1
0.4 KBDownload JSON
146insomnia
1
0.4 KBDownload JSON
147interlock
1
0.5 KBDownload JSON
148j
1
0.4 KBDownload JSON
149kairos
1
0.4 KBDownload JSON
150karakurt
1
0.4 KBDownload JSON
151karma
1
0.5 KBDownload JSON
152kawa4096
1
0.4 KBDownload JSON
153kazu
1
0.4 KBDownload JSON
154kelvinsecurity
1
0.5 KBDownload JSON
155killsec
1
0.4 KBDownload JSON
156kittykatkrew
1
0.5 KBDownload JSON
157knight
1
0.5 KBDownload JSON
158kraken
1
0.4 KBDownload JSON
159krybit
1
0.4 KBDownload JSON
160kryptos
1
0.4 KBDownload JSON
161kyber
1
0.4 KBDownload JSON
162la_piovra
1
0.5 KBDownload JSON
163lamashtu
1
0.4 KBDownload JSON
164lapsus$
1
0.4 KBDownload JSON
165leaktheanalyst
1
0.5 KBDownload JSON
166lilith
1
0.4 KBDownload JSON
167linkc
1
0.4 KBDownload JSON
168lockbit
1
0.9 KBDownload JSON
169lockbit2
1
0.9 KBDownload JSON
170lockbit3
1
0.9 KBDownload JSON
171lockbit3_fs
1
0.5 KBDownload JSON
172lockbit5
1
0.4 KBDownload JSON
173lockdata
1
0.4 KBDownload JSON
174loki
1
0.4 KBDownload JSON
175lolnek
1
0.4 KBDownload JSON
176lorenz
1
1.1 KBDownload JSON
177losttrust
1
0.6 KBDownload JSON
178lunalock
1
0.4 KBDownload JSON
179lv
1
0.5 KBDownload JSON
180lynx
1
0.4 KBDownload JSON
181m3rx
1
0.4 KBDownload JSON
182madcat
1
0.4 KBDownload JSON
183madliberator
1
0.5 KBDownload JSON
184malas
1
0.4 KBDownload JSON
185malekteam
1
0.5 KBDownload JSON
186mallox
1
2.5 KBDownload JSON
187mamona
1
0.4 KBDownload JSON
188marketo
1
0.4 KBDownload JSON
189maze
1
1.2 KBDownload JSON
190mbc
1
0.4 KBDownload JSON
191medusa
1
8.8 KBDownload JSON
192medusalocker
1
6.9 KBDownload JSON
193meow
1
0.4 KBDownload JSON
194metaencryptor
1
0.5 KBDownload JSON
195midas
1
0.4 KBDownload JSON
196mindware
1
0.4 KBDownload JSON
197minteye
1
0.4 KBDownload JSON
198mnt6
1
0.4 KBDownload JSON
199mogilevich
1
0.5 KBDownload JSON
200moneymessage
1
0.5 KBDownload JSON
201monti
1
0.8 KBDownload JSON
202morpheus
1
0.5 KBDownload JSON
203mosesstaff
1
0.5 KBDownload JSON
204mountlocker
1
0.5 KBDownload JSON
205ms13089
1
0.4 KBDownload JSON
206mydecryptor
1
0.5 KBDownload JSON
207n3tworm
1
0.4 KBDownload JSON
208nasirsecurity
1
0.5 KBDownload JSON
209nefilim
1
0.8 KBDownload JSON
210nemty
1
0.4 KBDownload JSON
211netrunner
1
0.5 KBDownload JSON
212netwalker
1
30.6 KBDownload JSON
213nevada
1
1.6 KBDownload JSON
214nightsky
1
0.5 KBDownload JSON
215nightspire
1
0.5 KBDownload JSON
216nitrogen
1
0.5 KBDownload JSON
217noescape
1
0.7 KBDownload JSON
218nokoyawa
1
0.9 KBDownload JSON
219noname
1
0.4 KBDownload JSON
220nova
1
0.4 KBDownload JSON
221obscura
1
0.4 KBDownload JSON
222onepercent
1
0.5 KBDownload JSON
223onyx
1
0.4 KBDownload JSON
224orca
1
0.4 KBDownload JSON
225orion
1
0.4 KBDownload JSON
226osiris
1
0.4 KBDownload JSON
227pandora
1
0.4 KBDownload JSON
228pay2key
1
0.4 KBDownload JSON
229payload
1
0.4 KBDownload JSON
230payloadbin
1
0.5 KBDownload JSON
231payoutsking
1
0.5 KBDownload JSON
232pear
1
0.4 KBDownload JSON
233play
1
7.6 KBDownload JSON
234playboy
1
0.4 KBDownload JSON
235projectrelic
1
0.5 KBDownload JSON
236prolock
1
0.5 KBDownload JSON
237prometheus
1
0.5 KBDownload JSON
238promptlock
1
0.5 KBDownload JSON
239pysa
1
0.9 KBDownload JSON
240qilin
1
1.6 KBDownload JSON
241qiulong
1
0.4 KBDownload JSON
242qlocker
1
0.4 KBDownload JSON
243quantum
1
9.3 KBDownload JSON
244rabbithole
1
0.5 KBDownload JSON
245radar
1
0.4 KBDownload JSON
246radiant
1
0.4 KBDownload JSON
247ragnarlocker
1
1.6 KBDownload JSON
248ragnarok
1
0.5 KBDownload JSON
249ralord
1
0.4 KBDownload JSON
250ramp
1
0.4 KBDownload JSON
251rancoz
1
0.4 KBDownload JSON
252ranion
1
0.4 KBDownload JSON
253ransombay
1
0.5 KBDownload JSON
254ransomcartel
1
0.5 KBDownload JSON
255ransomcortex
1
0.5 KBDownload JSON
256ransomed
1
0.4 KBDownload JSON
257ransomexx
1
0.9 KBDownload JSON
258ransomhouse
1
0.5 KBDownload JSON
259ransomhub
1
0.9 KBDownload JSON
260ranstreet
1
0.5 KBDownload JSON
261ranzy
1
0.4 KBDownload JSON
262raworld
1
0.7 KBDownload JSON
263raznatovic
1
0.5 KBDownload JSON
264rebornvc
1
0.4 KBDownload JSON
265redalert
1
0.5 KBDownload JSON
266redransomware
1
0.5 KBDownload JSON
267revil
1
1.4 KBDownload JSON
268reynolds
1
0.4 KBDownload JSON
269rhysida
1
6.6 KBDownload JSON
270robinhood
1
0.9 KBDownload JSON
271rook
1
0.4 KBDownload JSON
272royal
1
7.3 KBDownload JSON
273rransom
1
0.4 KBDownload JSON
274runsomewares
1
0.5 KBDownload JSON
275sabbath
1
0.5 KBDownload JSON
276safepay
1
0.4 KBDownload JSON
277sarcoma
1
0.4 KBDownload JSON
278satanlockv2
1
0.5 KBDownload JSON
279secp0
1
0.4 KBDownload JSON
280securotrop
1
0.5 KBDownload JSON
281sensayq
1
0.4 KBDownload JSON
282shadow
1
0.4 KBDownload JSON
283shadowbyt3$
1
0.5 KBDownload JSON
284shaoleaks
1
0.5 KBDownload JSON
285shinyhunters
1
0.5 KBDownload JSON
286shinysp1d3r
1
0.5 KBDownload JSON
287sicarii
1
0.4 KBDownload JSON
288siegedsec
1
0.5 KBDownload JSON
289silent
1
0.4 KBDownload JSON
290silentransomgroup
1
0.5 KBDownload JSON
291sinobi
1
0.4 KBDownload JSON
292skira
1
0.4 KBDownload JSON
293slug
1
0.4 KBDownload JSON
294snatch
1
2.6 KBDownload JSON
295solidbit
1
0.4 KBDownload JSON
296spacebears
1
0.4 KBDownload JSON
297sparta
1
0.4 KBDownload JSON
298spook
1
0.4 KBDownload JSON
299stormous
1
0.4 KBDownload JSON
300sugar
1
0.5 KBDownload JSON
301suncrypt
1
1.4 KBDownload JSON
302synack
1
0.4 KBDownload JSON
303teamxxx
1
0.4 KBDownload JSON
304tengu
1
0.4 KBDownload JSON
305termite
1
0.5 KBDownload JSON
306thegentlemen
1
0.5 KBDownload JSON
307thegreenbloodgroup
1
0.5 KBDownload JSON
308threeam
1
0.9 KBDownload JSON
309timc
1
0.4 KBDownload JSON
310toufan
1
0.4 KBDownload JSON
311tridentlocker
1
0.5 KBDownload JSON
312trigona
1
0.9 KBDownload JSON
313trinity
1
1.3 KBDownload JSON
314trisec
1
0.4 KBDownload JSON
315u-bomb
1
0.4 KBDownload JSON
316underground
1
0.4 KBDownload JSON
317unknown
1
0.4 KBDownload JSON
318unsafe
1
0.4 KBDownload JSON
319valencialeaks
1
0.5 KBDownload JSON
320vanhelsing
1
0.5 KBDownload JSON
321vanirgroup
1
0.5 KBDownload JSON
322vect
1
0.4 KBDownload JSON
323vendetta
1
0.4 KBDownload JSON
324vfokx
1
0.4 KBDownload JSON
325vicesociety
1
0.4 KBDownload JSON
326walocker
1
0.4 KBDownload JSON
327wannacry
1
1.3 KBDownload JSON
328warlock
1
0.4 KBDownload JSON
329werewolves
1
0.5 KBDownload JSON
330weyhro
1
0.4 KBDownload JSON
331worldleaks
1
0.5 KBDownload JSON
332x001xs
1
0.4 KBDownload JSON
333xinglocker
1
0.5 KBDownload JSON
334xinof
1
0.4 KBDownload JSON
335xp95
1
0.4 KBDownload JSON
336yanluowang
1
0.9 KBDownload JSON
337yurei
1
0.4 KBDownload JSON
338zeon
1
0.4 KBDownload JSON
339zerolockersec
1
0.5 KBDownload JSON
340zerotolerance
1
0.5 KBDownload JSON

Rule text is available at https://hackersfeeds-api.secaware.workers.dev/api/rl/yara/<group> — usable as input to Loki, YARA-X, or any compatible scanner.