Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors killsec

Description

KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split, primarily targeting healthcare, financial services, and government sectors with over 250 documented victims as of late 2025. Known victims: 277

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

KillSec, originating from a hacktivist group linked with Anonymous, has transitioned into a sophisticated ransomware operation. Launching their Ransomware-as-a-Service (RaaS) platform in June 2024, they primarily target healthcare, financial, and government sectors. With over 250 documented victims by late 2025, KillSec poses a significant threat to these industries with their affiliate-friendly revenue model.

Goals & Targeting

KillSec's strategic objectives center on generating substantial financial returns through ransomware campaigns. Targeting sectors with high recovery costs and potential for quick payouts, such as healthcare and financial services, aligns with their goal of maximizing profit. Their selection of victims reflects a calculated approach to exploit critical infrastructure while avoiding prolonged operational exposure.

Enhanced Description

KillSec emerged from hacktivist roots within the Anonymous movement before shifting focus to ransomware in October 2023. By June 2024, they had established a RaaS platform offering an attractive 88% revenue split for affiliates, facilitating rapid growth and widespread campaigns across multiple sectors. Primarily targeting healthcare, financial services, and government entities, KillSec has demonstrated both technical proficiency and strategic focus in their operations. Their activities highlight a clear shift from hacktivism to criminal enterprise driven by financial gain.

Key Capabilities

  • Ransomware development
  • Ransomware-as-a-Service (RaaS) operations
  • High-volume campaign orchestration
  • Sophisticated targeting strategy

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1046
T1078.001
T1284
T1566.001
T1003.001

Software / Tooling

KillSec ransomware (hypothetical)
Third-party encryption tools
Phishing payloads

Campaigns & Victims

KillSec's affiliate program has significantly amplified their operational reach, enabling a high volume of attacks across various industries. Campaigns often involve large-scale data encryption and demands for substantial ransoms. Notable victims include healthcare providers such as MedicalGPT and MyFair, demonstrating their focus on sectors with critical data vulnerabilities. KillSec's campaigns have shown adaptability in delivery methods but remain less sophisticated than state-sponsored actors.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Encrypted files with '.killsec' extension
  • Lateral movement across networks

Recommended Actions

  • Implement anti-phishing training for employees
  • Deploy advanced threat detection solutions focusing on anomaly detection
  • Regularly back up critical data offline
  • Enforce multi-factor authentication (MFA) across all systems
  • Monitor for KillSec campaign patterns using threat intelligence feeds
  • Segment network access to limit lateral movement

Suggested Tags

Ransomware
Financial gain
Healthcare sector
Government sector
RaaS
Criminal group

Confidence Assessment

High confidence in KillSec's operational patterns and goals, supported by their extensive victim list and RaaS activities. Limited visibility into specific technical tools or infrastructure complicates detailed analysis, suggesting areas for further investigation.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

16

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting
Hacktivism
Financial gain
Healthcare sector
Government sector
RaaS
Criminal group

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 21, 2024
Last Seen
Jul 23, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.