cyclops
- First seen
- 2023-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:52:24
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications manufacturing retail-and-hospitality professional-services
Context
Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023. It operates as a Ransomware-as-a-Service (RaaS), targeting multiple platforms including Windows, macOS, Linux, and ESXi systems. Crafted in Go, it uses strong encryption algorithms like ChaCha20 and Curve25519. Knight includes both a full and "lite" encryptor, supports batch attacks, hosts a Tor leak site, and offers a web portal for affiliates—positioning itself as a scalable and partner-friendly ransomware operation. Affiliates can manage deployments, track payments, and negotiate with victims through a sophisticated RaaS platform.
Reports & references
- ransomlook.io — Cyclops (report)
- sentinelone.com — Knight (report)
- kelacyber.com — Cyclops Ransomware Gang Unveils Knight Raas (report)
- wwwmicrosoft.com — Malware Encyclopedia Description (report)
- cloudsek.com — Understanding Knight Ransomware Advisory Analysis (report)
- quorumcyber.com — Knight Ransomware Report (report)
- harfanglab.io — Cyclops Replacement Bellaciao (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cyclops (report)