SafePay Ransomware Group

SafePay is a relatively new but highly active ransomware operation known for using a “double extortion” tactic—encrypting victims’ files while also stealing their data and threatening to leak it. The group gains initial access to corporate networks using compromised credentials for VPN gateways.

Scattered Lapsus$ Hunters

The Scattered Lapsus$ Hunters group claims to consist of cybercriminals associated with the Scattered Spider, Lapsus$, and ShinyHunters extortion groups.

Scattered Lapsus$ Hunters also claimed responsibility for recent Salesforce data theft attacks.

Everest Ransomware Group

The Russian linked Everest group has been responsible for multiple ransomware attacks and data breaches since 2020. Since it surfaced in 2020, the Everest ransomware operation has switched tactics from data theft-only corporate extortion to including ransomware in its attacks to encrypt victims’ compromised systems.

Notable victims of Everest ransomware attacks include the Brazilian Government, Coca-Cola, the U.S. space agency, NASA, and the cannabis retail chain, Stiiizy.

ShinyHunters

ShinyHunters first emerged in 2020 and claims to have successfully attacked 91 victims so far. The group is primarily after money, but has also been willing to cause reputational damage to their victims.

ShinyHunters posted on Telegram they have been working with known threat actors Scattered Spider and Lapsus$ to target companies such as Salesforce and Allianz Life. Scattered Lapsus$ Hunters, the newly rebranded group, recently advertised they had started providing ransomware as a service. They claim their service is better than other cyber crime groups offer, such as LockBit and Dragonforce. Rather than negotiating directly with victims, the group often publishes public extortion messages.

The 2025 Coca Cola salesforce databreach suggests possible link with hacker group Gehenna.

Interlock

Interlock ransomware operation launched in late September 2024. The group cannot be classified as a “Ransomware-as-a-Service” (RaaS) group, as no advertisements for recruiting affiliates or information about affiliates have been found as of March 2025.

The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices.

Interlock has a Data Leak Site (DLS) called “Worldwide Secrets Blog” exposing victim’s data, and providing a way to negotiate the ransom price to the victims.