MONTI

Monti was first discovered in June 2022, Monti ransomware appeared as a clone of Conti, as it used most of its code following a leak from a Ukrainian researcher. In September 2022, an Intel471 report highlighted the increased likelihood of Monti being a rebrand of Conti based on their identical initial network access methods.

Members of the gang do not consider themselves cybercriminals or their software malicious. They refer to the tools they use as utilities that reveal security problems in corporate networks, and call their attacks penetration testing, for which they want to get paid. If the victim company does not pay, they publish the name of their victims on their data leak site, under a section called “Wall of Shame.”

Despite the terms used to describe their activity, the Monti group behaves like any other ransomware gang, breaching company network, stealing data, and asking for a ransom.

Hellcat ransomware gang

Hellcat ransomware gang emerged in mid-2024 and employs a ransomware-as-a-service (RaaS) model, offering ransomware tools and infrastructure to affiliates in exchange for a share of the profits. The group has so far focused on high-value targets, such as government and critical sectors like energy and education.

Hellcat’s double extortion tactics indicate a deeper psychological element aimed at humiliation and public pressure.

Ukrainian Cyber Alliance

The Ukrainian Cyber Alliance (UCA, Ukrainian Language Український кіберальянс, УКА) is a community of Ukrainian cyber activists from Ukraine and around the world. The UCA was formed in spring of 2016 by a merger of two cyber activist groups, FalconsFlame and Trinity. It was joined later by group RUH8 and individual activists from the CyberHunta group. These hacktivists have united to counter Russian aggression in Ukraine.

Lynx Ransomware Group

The Lynx Ransomware-as-a-Service (RaaS) group has been found operating a highly organized platform, complete with a structured affiliate program and robust encryption methods. The group actively recruits experienced penetration testing teams through underground forums.

The group provides its affiliates with an “All-in-One Archive” that contains binaries for Windows, Linux, and ESXi environments.Affiliates receive an 80% share of ransom proceeds, handle all negotiations and maintain control over the ransom wallet. Lynx also offers additional services, such as a call center to harass victims and advanced storage solutions for high-performing affiliates.

Blackjack group

The Blackjack hacking group is believed to be affiliated with Ukrainian intelligence services.