1. Security verification failed. Please try again.
Skip to main content

DarkWebSonar Blog

In-depth analysis of dark web activity, ransomware trends, and cyber threat intelligence. Explore expert research, case studies, and insights that help you stay ahead of evolving threats.

16 posts(Page 1 of 2)
+1

Dark Web Most Wanted: Miyako

Miyako is an Initial Access Broker specialist with 221 DarkWebSonar-tracked listings since November 2024, 95% Initial Access, and 42% US targeting. Telemetry shows debut and 2026-W27 batch spikes of firewall root/RCE sales.

DarkWebSonar Research Team
July 24, 2026
9 min read
Read more
+1

Dark Web Most Wanted: Nova

Nova ransomware has logged 129 victim postings across 45 countries since April 2025, with only 13% of victims in the United States. DarkWebSonar telemetry shows a May–June 2026 surge and a RaaS operation rebranded from RALord.

DarkWebSonar Research Team
June 15, 2026
8 min read
Read more
+1

Dark Web Most Wanted: DimasHxR

DimasHxR ranks second among all threat actors tracked by DarkWebSonar in the last 90 days with 508 incidents — yet carries zero open-source footprint. Weekly telemetry shows a surge peak of 150 incidents in April 2026 followed by a 61% decline, revealing a campaign lifecycle that makes continuous monitoring essential.

DarkWebSonar Research Team
May 2, 2026
10 min read
Read more
+1

Dark Web Most Wanted: Keymous+

Keymous+ is a DDoS-specialist hacktivist group with over 1,400 incidents tracked by DarkWebSonar, heavily targeting Morocco, France, India, Egypt, and Israel. Government, technology, and financial sectors bear the brunt of their Telegram-driven operations.

DarkWebSonar Research Team
February 24, 2026
8 min read
Read more
+1

Dark Web Most Wanted: NoName057(16)

NoName057(16) is the most active threat actor tracked by DarkWebSonar, with 894 incidents in the last 90 days and 5,500+ total incidents. Their campaigns are heavily concentrated in Europe, making them a sustained, high-tempo disruption threat for European organizations.

DarkWebSonar Research Team
January 16, 2026
8 min read
Read more
+1

Dark Web Most Wanted: MEDUSA

MEDUSA has established itself as one of the most persistent ransomware groups of 2025, with 201 confirmed victim postings tracked by DarkWebSonar. With 61.7% of victims in the United States and strong targeting of construction, healthcare, and education sectors, MEDUSA represents a critical threat.

DarkWebSonar Research Team
December 2, 2025
8 min read
Read more
+1

Dark Web Most Wanted: CL0P

CL0P remains one of the most dangerous ransomware groups tracked by DarkWebSonar, with 635 victim postings since October 2024 and a sustained January–February 2026 campaign wave. With 68.5% of victims in the United States and heavy targeting of manufacturing, technology, and retail, CL0P represents a critical threat to organizations worldwide.

DarkWebSonar Research Team
November 20, 2025
8 min read
Read more
+1

Dark Web Most Wanted: HEZI RASH

HEZI RASH has rapidly emerged as one of the most prolific hacktivist groups of 2025, with 856 incidents tracked by DarkWebSonar in just over three months. Dominated by DDoS attacks, the group targets 38 countries across government, media, and education sectors.

DarkWebSonar Research Team
November 4, 2025
8 min read
Read more
+1

Dark Web Most Wanted: Sinobi Ransomware

Sinobi has logged 277 leak-site postings since July 2025, with 80% of victims in the United States and manufacturing leading industry targets. After a March 2026 pause, six new victims appeared on May 5, 2026. DarkWebSonar telemetry tracks the Lynx-lineage RaaS operator through burst publication cycles and its current dormant status.

DarkWebSonar Research Team
October 25, 2025
8 min read
Read more

We use cookies to improve your experience

Help us understand how visitors interact with our website by collecting anonymous information (Google Analytics, Ahrefs, PostHog).