Skip to content

KillSec

KillSec is a ransomware operation that emerged from an Anonymous-aligned hacktivist background and later evolved into a financially motivated ransomware and ransomware-as-a-service actor.

Profile source: Mallory opens in a new tab

KillSec

Family profile

KillSec is a ransomware operation that emerged from an Anonymous-aligned hacktivist background and later evolved into a financially motivated ransomware and ransomware-as-a-service actor. By 2025 it had gained traction as an active extortion threat and was repeatedly observed among ransomware strains affecting healthcare-related organizations. Victim reporting also linked the operation to attacks outside healthcare, including organizations in South Korea and Brazil, indicating opportunistic multi-sector targeting rather than a narrowly specialized victim profile.

KillSec is associated with ransomware-based extortion and has been characterized as a hybrid actor blending hacktivist origins with profit-driven criminal activity. Reporting also indicates that it offered affiliates additional offensive tooling, including distributed denial-of-service and data-stealing capabilities, consistent with broader multi-extortion tradecraft in the ransomware ecosystem. Its activity has been discussed alongside other prominent 2025 ransomware groups, reflecting its rise within a fragmented threat landscape shaped by affiliate migration and the proliferation of smaller brands.

High-confidence reporting supports classifying KillSec as ransomware targeting enterprise environments, but the available information here does not establish a specific initial access vector, operating system focus, or distinctive technical implementation with sufficient certainty. Its known impact is most clearly tied to extortion operations against organizations, including healthcare businesses.

Capabilities

  • Ddos
  • Exfiltration
  • Extortion

Operational record

1
YARA rules
2
Leak sites
0 available

Recent claims

MITRE ATT&CK

KillSec in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.