The Mamba ransomware group is a relatively obscure threat actor that emerged in May 2020 with apparent financial motivations, though limited public documentation exists about their operations. Based on available intelligence, the group has maintained a low profile with minimal documented activity, suggesting either independent operations or a small-scale affiliate model rather than a major ransomware-as-a-service operation. The group appears to primarily target the healthcare and public health sector within the United States, though specific attack methodologies, initial access vectors, and encryption techniques remain largely undocumented by major security researchers and government agencies. With only one publicly documented victim, Mamba has not conducted any notable high-profile campaigns or attracted significant law enforcement attention compared to more prominent ransomware operations. The current operational status of the Mamba ransomware group remains unclear due to limited threat intelligence reporting and their low-volume targeting approach. The group has been linked to 1 public disclosures across our corpus. First observed on a leak site on May 7, 2020. The operation is currently inactive.
Also tracked as: HDDCryptor.
Sector and geography
This disclosure adds to ransomware activity in the Healthcare and Public Health sector, which has 52 disclosures indexed across all operators we track. Geographically, Unnamed health care company is reported in United States, a country with 7,392 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.