Skip to main content

Operator dossier

Scarlettgroup is a ransomware operator currently active on public leak sites. Darkfield has indexed 1 public victims claimed by this operator between October 8, 2026.

Recent disclosures by Scarlettgroup

All 1 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Scarlettgroup →

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status changes from active to dormant when no new disclosure appears for 60 days. Without a disclosure date, activity is unknown. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

← All groups

Scarlettgroup

1 victims indexed · first seen 60 minutes ago · last activity 3 hours ago

1
Victims indexed
#361 of 410 tracked operators
<1m
Active period
Oct 2026 → Oct 2026
—
Countries hit

At a glance

Status
active
First seen
60 minutes ago
Last activity
3 hours ago

Recent victims

  • Loading recent victims

Source

Updated 3 hours ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Scarlettgroup posts a victim.

Add Scarlettgroup to your watchlist — Pro pings you within 5 minutes of any new Scarlettgroup leak-site post, Telegram callout, or affiliate-rebrand inference.