The biggest ransomware brands still dominate the extortion leak sites, but the past few days show how crowded the field beneath them has become. Alongside the usual high-volume operators, a cluster of smaller and newer crews has been posting fresh victims across Asia, Europe, Latin America and North America, including a brand new name that surfaced this weekend.
These are claims, not confirmations. Everything below comes from the gangs' own leak sites, where crews name organisations they say they have hacked in order to pressure them into paying. IntelFusions tracks these posts as unverified extortion claims. A listing is not proof that data was stolen, and some entries turn out to be exaggerated, recycled or simply false.
A new name called Blackout
The standout newcomer is Blackout, a brand that first appeared on 19 July and immediately listed three victims on the same day: an electronics maker in Japan, a technology firm in the United States and a group in the United Kingdom. Debuting with several victims at once is a common pattern for operations that quietly build up access before going public, though it can also be a smaller crew reposting older intrusions under a fresh banner. Either way, Blackout is worth watching.
The long tail keeps growing
Blackout is not alone. Over the past two weeks several lower-profile crews have kept a steady drumbeat of claims: Krybit with around nine listings, Nova with eight, Doommageddon with seven, M3rx with five and Payload with three. Nova stands out for the targets it picks, having recently listed an entry tied to Indonesia's transport ministry among victims in Brazil and Turkey. If accurate, a national government body would be a notable catch for a crew of this size, but that claim remains unverified.
The pattern matters more than any single name. Ransomware has become a low barrier to entry business: affiliates move between brands, tooling is rented or leaked, and a crew can rebrand overnight to shed a tarnished reputation or dodge law enforcement attention. That churn is why the leak sites now carry a long tail of names most defenders have never heard of, sitting beneath established operators such as Qilin and INC Ransom, whose recent sprees we covered in our roundup of Qilin's US victims and INC Ransom's Asia-Pacific surge.
What defenders should do
The technique behind most of these intrusions is unglamorous and consistent: stolen or weak credentials, exposed remote-access and VPN gateways, and unpatched internet-facing software. Practical priorities do not change with the brand name. Enforce multi-factor authentication on every remote-access and email account, keep internet-facing systems patched, segment networks so a single foothold cannot reach everything, and keep offline, tested backups. Organisations in Indonesia and the wider region can review our Indonesia threat profile for local context.
If your organisation appears on one of these sites, treat it as a credible signal to launch incident response and preserve evidence, even before you can confirm what was taken. Early containment and legal or regulatory notification usually matter more than the specific gang doing the extorting.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.