KillSec — Ransomware Profile

KillSec (aka Kill Security) surfaced around 2021 as an Anonymous-aligned hacktivist crew running DDoS attacks and website defacements, and pivoted to ransomware in October 2023 with its KillSecurity 2.0 and 3.0 lockers, according to Rapid7's June 2025 analysis of the group. It formalised a ransomware-as-a-service programme in June 2024 with a C++ Windows locker, affiliate dashboard and builder, added an ESXi locker in November 2024, and now operates as a financially motivated double-extortion outfit that also sells stolen data and pentest, OSINT and DDoS services from its leak site. Recent activity is dominated by opportunistic theft from exposed cloud storage rather than novel exploitation, including the September 2025 compromise of Brazilian healthcare software vendor MedicSolution, where Resecurity documented more than 34GB of patient records taken from insecure S3 buckets. Attribution remains unresolved: Rapid7 describes the group as Russia-aligned and Halcyon infers an Eastern Europe/Russia nexus from Moscow-hours activity and CIS avoidance, while noting its Asia and Latin America targeting diverges from typical Russian criminal patterns, so no country of origin is asserted here.

Also tracked as

Kill Security

IntelFusions coverage (4)

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions