Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Changelog

Show changes for
2026-09-21
Website

Updated: /ttps ATT&CK Tactics Matrix

2026-09-21
Website

Improved: PGP Key Info on IoCs

  • The PGP key info popup on the IoCs page is now a proper modal, matching the X/Twitter account info popup, and the same "i" button/modal is now also available for PGP IoCs on group pages.
  • The modal now shows when the key was added, and flags any primary key or subkey whose expiration date has passed with a red Expired tag.
  • Fixed parsing for PGP keys stored with their armor newlines flattened to spaces, which previously made the info modal fail with "no valid OpenPGP data found".
2026-09-20
Website

New: Disclosures menu — SEC 8-K and UK ICO trackers

  • New Disclosures menu grouping regulator-published records related to ransomware, separate from leak-site data.
  • SEC 8-K (Item 1.05) — Material Cybersecurity Incident filings sourced from EDGAR, each with a stock price trend sparkline covering the 6 months following the filing date.
  • UK ICO — enforcement actions (reprimands, monetary penalties, enforcement notices, prosecutions) related to ransomware, live-queried from the ICO's enforcement action register.
2026-09-20
Website

Update Sources & Credits information

  • In the /about page, we have updated the Sources used by Ransomware.live
2026-09-19
Website Scraper/Parser

New: favicon hash fingerprinting for leak-site locations

  • The scraper now computes a Shodan-compatible favicon hash (mmh3 of the base64-encoded icon) for every leak-site location, useful for spotting shared hosting/infrastructure and clearnet mirrors reused across groups.
  • Shown as http favicon mmhash in the Fingerprint section of each location's info modal on group pages.
  • Backfilled for all favicons already on disk; new locations pick it up automatically on their next scrape.
2026-09-19
Website

New: Data Exfiltrated stat on group pages

  • Group detail pages now show the total amount of data reported as exfiltrated across that group's victims.
2026-09-19
Website

Navigation menu reorganized

  • YARA Rules, TTPs Matrix, KQL Queries, IoCs and Vulnerabilities are now grouped under a new Arsenal dropdown menu instead of separate top-level links.
  • Search moved to the second navigation row.
2026-09-19
Website

New: dedicated CVE record pages

  • Every CVE mentioned on the site now links to its own record page with the NVD description, CVSS score/vector (with a radar chart breakdown for both CVSS v3.x and v4.0), EPSS exploitation probability, CISA KEV / known-ransomware-use status, affected vendor(s)/product(s), and which ransomware groups are known to have exploited it.
2026-09-19
Website

New Vulnerabilities page

  • Vulnerabilities used by Threat Actors are available at /vulns with two views: Applications (grouped by vendor) and Threat Actors (grouped by ransomware group).
2026-09-18
Website

Follow Ransomware.live on WhatsApp

2026-09-10
Website

Search IOCs directly with +ioc:

  • Added a new +ioc: keyword to /search — searches only the IOC database and returns the group(s) an indicator belongs to. The value can be a literal indicator (hash, email, wallet, IP, domain, ...) or a group's slug. Requested by Ellis.
2026-09-06
Website

Trace where a ransom payment went

  • Added the option to trace a ransom payment's on-chain flow — follow the money hop by hop.
2026-09-06
Website

Cryptomoney section redesign on group pages

  • The Cryptomoney section on group pages now shows BTC wallets in a compact two-column layout with a one-click copy button, instead of a table with a date column.
  • Fixed a bug where the section's expand/collapse toggle could silently stop working.
2026-09-06
Website

Bitcoin wallets added to the IoCs page

  • /ioc now also lists ransom-note BTC wallets as "Bitcoin Wallet" indicators alongside the existing curated IOCs, with wallet-trace and OFAC-screening links.
2026-09-06
Website

MX record check for email IOCs

  • Email IOCs on /ioc now show whether their domain has a valid MX (mail) record — a green "MX found" or red "No MX" badge next to each address.
2026-09-05
API-Pro

Bug in API-PRO for IOCs

  • We have corrected a bug in the API-PRO which did not return the IOCs for some groups. It's now corrected.
2026-08-30
Website

VirusTotal lookup for domain IOCs

  • Domain IOCs on /ioc now link out to a VirusTotal lookup — detection stats, reputation, categories, registrar and creation date — the same way hash IOCs already link to VirusTotal.
  • The domain lookup also shows the domain's last known DNS records (A, MX, NS, TXT, etc.).
2026-08-23
Scraper/Parser

New parser for KillSec

  • The KillSec DSL has been redesigned. The parser has been rewritten.
2026-08-23
Scraper/Parser

Rewrite Scraper/Parser

2026-08-22
Website

Open a support ticket by email

  • You can now open a support ticket just by emailing us at supportransomware.live — no need to log in or visit the site first.
2026-08-22
Website API-Pro

Captcha & law-enforcement seizure detection for leak-site locations

  • Added captcha and seized fields to locations, tracking whether a monitored leak-site location is currently gated behind a captcha/bot-challenge or has been seized by law enforcement.
  • Group detail pages now show a status icon in the Known Locations table (puzzle piece for captcha, handcuffs for seizure), with both explained in the page legend.
2026-08-21
Website

New /support ticket portal

  • Launched /support, a customer-facing portal to manage support questions as tickets, with victim/case search and file attachments.
  • Passwordless magic-link login by email — no password to manage, just a one-time login link sent to the requester's inbox.
  • Migrated all historical tickets from Freshdesk, our previous support solution, into the new internal ticket system.

No changes match the selected filters.