Research page reference

Shared malware, language, infrastructure style, negotiation behavior, or affiliates do not establish common operators. Empty sections are deliberate: the archive does not fill evidence gaps with inference.

Documented timeline

25 source-linked events

Major observations, enforcement actions, disruptions, and qualified lineage reports. Documentary thumbnails are local archival derivatives; the universal neutral silhouette is labeled and never presented as historical evidence.

Alphabetical actor index

26 archive actors · 13 curated evidence entities
Current negotiation actors, evidence-only entities, and their lineage coverage
Source actorCanonical lineageAliasesRelationshipsNegotiationsRansomware notesEvidence status
ABCD ransomwareEvidence-only entity ABCD ransomware 0 1 Sources attached
Akira Akira 0 0 60 3 Sources attached
Avaddon Not curated 0 0 7 1 No lineage claims published
Avos AvosLocker 1 0 1 1 Sources attached
Babuk Not curated 0 0 2 0 No lineage claims published
BlackBasta Black Basta 0 1 5 5 Sources attached
BlackMatter BlackMatter 0 1 2 1 Sources attached
Cloak Not curated 0 0 2 3 No lineage claims published
Conti Conti 0 2 32 4 Sources attached
Darkside DarkSide 0 1 5 1 Sources attached
Dragonforce Not curated 0 0 14 2 No lineage claims published
fog Not curated 0 0 6 2 No lineage claims published
Hive Hive 0 0 8 2 Sources attached
Hunters International Not curated 0 0 1 3 No lineage claims published
kairos Not curated 0 0 1 1 No lineage claims published
Knight ransomwareEvidence-only entity Knight ransomware 1 1 Sources attached
lockbit3.0 LockBit 5 2 42 5 Sources attached
Mallox Not curated 0 0 3 2 No lineage claims published
mount-locker Not curated 0 0 1 0 No lineage claims published
Nightspire Not curated 0 0 7 4 No lineage claims published
NoEscape Not curated 0 0 2 3 No lineage claims published
Pear Not curated 0 0 1 0 No lineage claims published
Qilin Qilin 1 0 2 3 Sources attached
RansomHub RansomHub 0 1 1 4 Sources attached
Ranzy Not curated 0 0 2 1 No lineage claims published
REvil REvil 2 0 20 3 Sources attached
RunSomeWares Not curated 0 0 1 0 No lineage claims published
trinity Not curated 0 0 14 1 No lineage claims published

Actors with known predecessors or successors

  • ABCD ransomware → LockBit Predecessor · Confirmed

    The joint LockBit advisory explicitly calls ABCD ransomware the predecessor to LockBit. This describes ransomware lineage and does not by itself prove uninterrupted operator identity.

    CISA, FBI, MS-ISAC, and international partners

Known and reported rebrands

Known splits

No split relationship currently meets the evidence threshold.

Known mergers

No merger relationship currently meets the evidence threshold.

Disputed relationships

No relationship in this snapshot is marked disputed. Suspected and moderate-confidence records remain visibly separate from confirmed records.

Recently updated lineage records

  1. ABCD ransomware
  2. Akira
  3. AvosLocker
  4. Black Basta
  5. BlackMatter
  6. Conti
  7. DarkSide
  8. Hive
  9. Knight ransomware
  10. LockBit

Relationship directory

5 relationships shown

Evidence-backed actor, operation, and ransomware-family relationships
SourceRelationshipTargetPeriodConfidenceEvidence summarySources
Conti Code overlapsupported · undirected LockBit From January 2023 High confidence

The joint LockBit advisory reports that LockBit Green incorporated Conti ransomware source code. Code reuse is not evidence that the operations shared leadership.

  • CISA's LockBit evolution table records the January 2023 arrival of LockBit Green incorporating Conti source code.
CISA, FBI, MS-ISAC, and international partners
Knight ransomware Code overlapsuspected · directed RansomHub From February 2024 Moderate confidence

MITRE reports that RansomHub operators may have purchased and rebranded Knight resources and notes code, feature, and infrastructure overlaps. The same source does not establish that Knight's operators became RansomHub.

  • MITRE uses conditional language—“may have purchased and rebranded resources”—while documenting multiple technical overlaps.
  • The joint RansomHub advisory records the Cyclops/Knight lineage but does not independently prove operator continuity.
FBI, CISA, MS-ISAC, and HHS · MITRE ATT&CK
ABCD ransomware Predecessorconfirmed · directed LockBit From September 2019 Confirmed

The joint LockBit advisory explicitly calls ABCD ransomware the predecessor to LockBit. This describes ransomware lineage and does not by itself prove uninterrupted operator identity.

  • CISA's LockBit evolution table records ABCD activity in September 2019 and identifies it as the predecessor to LockBit.
CISA, FBI, MS-ISAC, and international partners
DarkSide Rebrandsuspected · directed BlackMatter From July 2021 Moderate confidence

CISA, FBI, and NSA describe BlackMatter as a possible DarkSide rebrand. The source does not confirm complete operator continuity.

  • The joint advisory says BlackMatter is a possible rebrand of DarkSide and dates the two operations on either side of May–July 2021.
CISA, FBI, and NSA
Conti Shared operatorssuspected · undirected Black Basta From April 2022 Moderate confidence

MITRE records researchers' assessment that Black Basta operators could include current or former Conti members. “Could include” is not treated as confirmed membership or succession.

  • MITRE's Black Basta software entry summarizes similarities in tactics, leak sites, payment sites, and negotiations and preserves the researchers' conditional assessment.
MITRE ATT&CK

Confidence model

Confirmed
Explicit authoritative attribution or multiple strong independent sources.
High confidence
Strong technical or operational evidence with broad agreement, short of full confirmation.
Moderate confidence
Credible reporting or partial technical evidence supports the relationship.
Low confidence
Limited, indirect, or preliminary evidence.
Disputed
Credible sources disagree.
Unknown
Evidence is currently insufficient.

See lineage source attribution for source tiers, MITRE separation, and media-review boundaries.