Ransomcortex is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 4 public victims claimed by this operator between July 12, 2024. Ransomcortex is an emerging ransomware group that first appeared in July 2024, operating with apparent financial motivation based on their targeting patterns and ransom demands. Given the group's recent emergence and limited public documentation, details about their country of origin and organizational structure remain unclear, though their primary focus on Brazilian targets suggests potential regional connections or familiarity with local business environments. The group has demonstrated a preference for targeting critical infrastructure and service sectors, specifically healthcare, manufacturing, and hospitality organizations, though specific details about their initial access methods, encryption techniques, and whether they employ data exfiltration tactics have not been extensively documented by major security firms. With only four confirmed victims since their emergence six months ago, Ransomcortex appears to operate on a smaller scale compared to established ransomware families, and no major high-profile attacks or significant law enforcement actions have been publicly reported against this group. As of early 2024, the group appears to remain active but maintains a relatively low profile in the ransomware landscape.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.