Dragonforce

DragonForce is a Ransomware-as-a-Service (RaaS) and ransomware cartel that emerged in late 2023, primarily focused on financial extortion through double-extortion tactics.

Handala

Handala is an Iran-affiliated cyber threat group that presents itself as a pro-Palestinian “hacktivist” collective. Emerging in December 2023, the group has become known for disruptive, destructive cyber operations primarily targeting Israeli and Western organizations, often acting as a front for Iran’s Ministry of Intelligence and Security (MOIS).

Kawa4096

Kawa4096 is an organized ransomware threat actor that emerged in mid-2025, notable for double extortion tactics, data leak sites on Tor, partial encryption methods to maximize impact, and psychological coercion via branding mimicry, and it has already been linked to multiple international incidents.

Silent Crow

Silent Crow is a pro‑Ukraine hacktivist group that became publicly active in late 2024 and has conducted multiple politically motivated cyberattacks against Russian state and corporate infrastructure. Operating in the context of the Russia–Ukraine conflict, the group’s actions are primarily intended to apply political pressure and disrupt adversary capabilities rather than for financial gain.

Belarusian Cyberpartisans

Belarusian Cyberpartisans is a self-styled hacktivist group that opposes president Alexander Lukashenko and says it wants to liberate Belarus from dictatorship.