Research page reference
Knight ransomware lineage Knight ransomware

Actor lineage

Global lineage directory
Cyclops

Overview

Knight/Cyclops resources share substantial lineage with RansomHub. Available reporting does not establish that the same operators continued under RansomHub.

Documentary media

Known aliases

Evidence-backed names associated with this lineage record
AliasTypeFirst observedLast observedConfidenceSources
CyclopsGovernment and MITRE reporting identify Knight as formerly Cyclops; exact dates are not established in this snapshot. Former name Date not established Date not established High confidence FBI, CISA, MS-ISAC, and HHS · MITRE ATT&CK

Historical timeline

Lineage and relationships

Relationships shown from this actor's perspective
Related actor or familyRelationshipPeriodConfidenceEvidence summarySources
RansomHuboperation Code overlapsuspected · directed From February 2024 Moderate confidence

MITRE reports that RansomHub operators may have purchased and rebranded Knight resources and notes code, feature, and infrastructure overlaps. The same source does not establish that Knight's operators became RansomHub.

  • MITRE uses conditional language—“may have purchased and rebranded resources”—while documenting multiple technical overlaps.
  • The joint RansomHub advisory records the Cyclops/Knight lineage but does not independently prove operator continuity.
FBI, CISA, MS-ISAC, and HHS · MITRE ATT&CK

Predecessors

None established.

Successors

None established.

Splits and mergers

None established.

Suspected affiliate relationships

None established.

MITRE ATT&CK integration

No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.

External intelligence references

  1. #StopRansomware: RansomHub RansomwareFBI, CISA, MS-ISAC, and HHS · government advisory · primary authoritative
  2. RansomHub, Software S1212MITRE ATT&CK · MITRE ATTACK · authoritative secondary

Confidence and evidence notes

Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.