Skip to content

Knight

Knight is a ransomware family and ransomware-as-a-service operation active by 2023 and notable for code reuse relationships with later ransomware strains.

Profile source: Mallory opens in a new tab

Knight

Family profile

Knight is a ransomware family and ransomware-as-a-service operation active by 2023 and notable for code reuse relationships with later ransomware strains. It has been referenced in connection with broader ransomware ecosystem shifts in 2024, particularly because its source code was reportedly sold in February 2024 and subsequently repurposed by other actors. Security reporting has identified significant code overlap between Knight and RansomHub, including similarities in encryptor logic, help-menu structure, and string-obfuscation techniques, making Knight relevant to attribution discussions around successor or derivative ransomware operations.

Knight primarily targeted enterprise environments and is associated with multi-platform ransomware activity through its code lineage and reuse by later families that support Windows, Linux, and ESXi systems. Its role in the criminal ecosystem appears especially important as a precursor whose codebase enabled follow-on ransomware development rather than solely as an isolated campaign. Knight has also been discussed alongside other contemporary extortion groups in analyses of the fragmented post-ALPHV and post-LockBit ransomware landscape.

High-confidence public reporting in the supplied material supports Knight’s classification as ransomware, but does not provide sufficiently detailed, direct evidence on its own delivery vectors, victim sectors, or a fuller standalone capability profile beyond file-encrypting extortion activity typical of ransomware operations.

Capabilities

  • Extortion

Operational record

1
YARA rules
2
Ransom notes
1
Leak sites
0 available

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.