KillSec
KillSec is a ransomware operation that emerged from an Anonymous-aligned hacktivist background and later evolved into a financially motivated ransomware and ransomware-as-a-service actor.
Profile source: Mallory opens in a new tabKillSec
Family profile
KillSec is a ransomware operation that emerged from an Anonymous-aligned hacktivist background and later evolved into a financially motivated ransomware and ransomware-as-a-service actor. By 2025 it had gained traction as an active extortion threat and was repeatedly observed among ransomware strains affecting healthcare-related organizations. Victim reporting also linked the operation to attacks outside healthcare, including organizations in South Korea and Brazil, indicating opportunistic multi-sector targeting rather than a narrowly specialized victim profile.
KillSec is associated with ransomware-based extortion and has been characterized as a hybrid actor blending hacktivist origins with profit-driven criminal activity. Reporting also indicates that it offered affiliates additional offensive tooling, including distributed denial-of-service and data-stealing capabilities, consistent with broader multi-extortion tradecraft in the ransomware ecosystem. Its activity has been discussed alongside other prominent 2025 ransomware groups, reflecting its rise within a fragmented threat landscape shaped by affiliate migration and the proliferation of smaller brands.
High-confidence reporting supports classifying KillSec as ransomware targeting enterprise environments, but the available information here does not establish a specific initial access vector, operating system focus, or distinctive technical implementation with sufficient certainty. Its known impact is most clearly tied to extortion operations against organizations, including healthcare businesses.
Capabilities
- Ddos
- Exfiltration
- Extortion
Operational record
Recent claims
MITRE ATT&CK