Mogilevich is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 9 public victims claimed by this operator between February 20, 2024 and March 2, 2024. Mogilevich is a recently emerged ransomware group that first appeared in February 2024, operating with apparent financial motivations based on their targeting patterns and operational behavior. Due to the group's recent emergence and relatively limited public documentation, specific details about their country of origin, affiliations, or operational model remain unclear to major threat intelligence firms and law enforcement agencies. The group has demonstrated a preference for targeting technology, government, business services, and transportation/logistics sectors, suggesting they may employ initial access vectors commonly effective against these industries, though their specific attack methodologies, encryption techniques, and data exfiltration practices have not been extensively documented by major security researchers. With only nine known victims identified to date, Mogilevich has maintained a relatively low profile compared to established ransomware operations, with no widely reported major campaigns or high-profile incidents documented by CISA, FBI, or prominent security firms like Mandiant. The group appears to remain active as of current reporting, though their limited operational footprint and recent emergence make comprehensive threat profiling challenging based on available public intelligence.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.