Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
KillSec is a ransomware and data-extortion operation that began as an Anonymous-aligned hacktivist collective (DDoS and website defacement) and pivoted to ransomware in late 2023, formally launching a Ransomware-as-a-Service (RaaS) platform branded 'KillSec3' in June 2024. It runs a Tor-based affiliate panel and a data-leak site, offers an affiliate-friendly ~88% revenue split, and blends criminal ransomware with advertised 'security services' (illicit penetration testing / OSINT). It is a high-volume, opportunistic actor with heavy impact on healthcare, professional services, and technology across the US, India, Latin America, and Asia.
KillSec emerged around 2023 as a hacktivist collective aligned with the Anonymous movement, conducting DDoS attacks and website defacements. It pivoted to ransomware operations in October 2023 and, on 25 June 2024, formalized a Ransomware-as-a-Service model advertised as 'KillSec3.' The RaaS offering included a C++ Windows locker, a builder tool for affiliates to customize configurations, a Tor-accessible control/affiliate panel providing real-time victim statistics and integrated chat, and later expansion into VMware ESXi targeting. Affiliates reportedly paid a low entry fee (~$250) and retained roughly 88% of ransom proceeds, one of the more generous splits in the ecosystem. The group also blends criminality with 'security services,' advertising penetration testing and OSINT-for-hire that in practice function as illicit access operations. KillSec operates a dedicated data-leak site and pursues double-extortion (exfiltration plus encryption, sometimes pure data-leak extortion). Aggregators (ransomware.live) document ~285 victims across ~49 countries, with the US (88) and India (50) most affected, followed by the UK, Brazil, and Belgium, and heavy concentration in professional services, technology, healthcare, and financial services. In September 2025 Resecurity documented a record spree against healthcare providers and software vendors across Brazil, Peru, Colombia, and the US (e.g., MedicSolution, Archer Health, Suiza Lab), including exposed cloud storage with tens of GB of medical records. The group remained active into 2026 (leak-site activity observed through August 2026). MENA relevance: The RaqibCTI Saudi Arabia / UAE / Egypt tags correspond to real KillSec data-leak-site posts (e.g., Saudi Arabia: Royal Saudi Air Force, OxyHealth; UAE: Nathan and Nathan, AX Capital, Mixfame, HappyTenant, Dardoc; Egypt: Shaghalni), but these are unverified adversary/aggregator leak-site claims that have NOT been independently confirmed by victim disclosure, incident-response reporting, or a second primary source. MENA is not a deliberate strategic focus for KillSec; these appear to be opportunistic victims within a global, high-volume campaign. Verdict: MIXED — the country tags are grounded in genuine leak-site claims and should be retained, but every MENA victim listing should be labeled 'unverified leak-site claim' until corroborated.
+18 more relationships — see the relationships browser.