Knight ransomware
From extortion.wiki, the actor-lineage evidence directory
This evidence entity has no standalone negotiation-actor collection in the current Ransomchats snapshot. It exists to document a sourced relationship without rewriting or inventing a threat-actor URL.
Actor lineage
Global lineage directoryOverview
Knight/Cyclops resources share substantial lineage with RansomHub. Available reporting does not establish that the same operators continued under RansomHub.
Documentary media

Known aliases
| Alias | Type | First observed | Last observed | Confidence | Sources |
|---|---|---|---|---|---|
| CyclopsGovernment and MITRE reporting identify Knight as formerly Cyclops; exact dates are not established in this snapshot. | Former name | Date not established | Date not established | High confidence | FBI, CISA, MS-ISAC, and HHS · MITRE ATT&CK |
Historical timeline
-
Knight ransomware disputed event
Knight resources linked to RansomHub reporting
The joint RansomHub advisory and MITRE reporting connect RansomHub resources to Knight/Cyclops. MITRE frames purchase and rebranding as possible, so this event documents code or resource lineage rather than confirmed operator continuity.
Evidence status: officially confirmed Moderate confidenceRelated: RansomHub
Lineage and relationships
| Related actor or family | Relationship | Period | Confidence | Evidence summary | Sources |
|---|---|---|---|---|---|
| RansomHuboperation | Code overlapsuspected · directed | From February 2024 | Moderate confidence | MITRE reports that RansomHub operators may have purchased and rebranded Knight resources and notes code, feature, and infrastructure overlaps. The same source does not establish that Knight's operators became RansomHub.
| FBI, CISA, MS-ISAC, and HHS · MITRE ATT&CK |
Predecessors
None established.
Successors
None established.
Splits and mergers
None established.
Suspected affiliate relationships
None established.
MITRE ATT&CK integration
No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.
External intelligence references
- #StopRansomware: RansomHub RansomwareFBI, CISA, MS-ISAC, and HHS · government advisory · primary authoritative
- RansomHub, Software S1212MITRE ATT&CK · MITRE ATTACK · authoritative secondary
Confidence and evidence notes
Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.