Bonacigroup is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 3 public victims claimed by this operator between October 4, 2021 and December 6, 2021. Bonacigroup is a relatively minor ransomware operation that emerged in October 2021 with an apparent focus on financially motivated cybercrime activities. Based on available public documentation, the group has maintained a limited operational scope with only three documented victims to date. The group appears to specifically target the legal sector, with their known activities concentrated primarily in the United Kingdom, suggesting either a regional focus or specialized knowledge of legal industry vulnerabilities. Due to the limited number of documented attacks and the group's relatively recent emergence, there is insufficient public reporting from major cybersecurity firms or law enforcement agencies to establish definitive details about their attack methodology, initial access vectors, or specific tools and techniques employed. No major high-profile campaigns or significant ransoms have been publicly attributed to Bonacigroup, and there are no documented law enforcement actions specifically targeting this operation. The current operational status of Bonacigroup remains unclear given the sparse public documentation, though the limited victim count and narrow targeting focus suggest they operate as a smaller-scale ransomware group rather than a major threat actor.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.