FulcrumSec

FulcrumSec is a financially motivated cloud extortion group—also known as The Threat Thespians—that has been active since late 2025. Operating primarily via a “steal and squeeze” model, they gain entry into enterprise environments and steal sensitive corporate and user data to demand multi-million-dollar ransoms.

Payload

Payload ransomware group is a highly active, financially motivated threat actor that first emerged in February 2026. Operating primarily on a double-extortion model, they encrypt enterprise data and exfiltrate sensitive files, threatening to publish them on their dedicated Tor leak sites if the ransom is not paid.

Nitrogen

Nitrogen is a highly capable double-extortion ransomware and initial-access group active since late 2024. Operating primarily in the USA, Canada, and UK, they target high-value targets across manufacturing, technology, and finance. Their malware uses advanced evasion and carries a bug that renders decryption mathematically impossible.

Cicada3301 ransomware group

Cicada3301 is a sophisticated, highly active Ransomware-as-a-Service (RaaS) operation that emerged in mid-2024.

Gunra

Gunra is a financially motivated, double-extortion ransomware group that emerged in 2025. Operating primarily as a Ransomware-as-a-Service (RaaS), the group actively attacks Windows and Linux systems across global sectors like manufacturing, healthcare, and IT, while deliberately avoiding targets in the United States.