cyclops

First seen
2023-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:52:24

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications manufacturing retail-and-hospitality professional-services

Context

Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023. It operates as a Ransomware-as-a-Service (RaaS), targeting multiple platforms including Windows, macOS, Linux, and ESXi systems. Crafted in Go, it uses strong encryption algorithms like ChaCha20 and Curve25519. Knight includes both a full and "lite" encryptor, supports batch attacks, hosts a Tor leak site, and offers a web portal for affiliates—positioning itself as a scalable and partner-friendly ransomware operation. Affiliates can manage deployments, track payments, and negotiate with victims through a sophisticated RaaS platform.

Reports & references

  • ransomlook.io — Cyclops (report)
  • sentinelone.com — Knight (report)
  • kelacyber.com — Cyclops Ransomware Gang Unveils Knight Raas (report)
  • wwwmicrosoft.com — Malware Encyclopedia Description (report)
  • cloudsek.com — Understanding Knight Ransomware Advisory Analysis (report)
  • quorumcyber.com — Knight Ransomware Report (report)
  • harfanglab.io — Cyclops Replacement Bellaciao (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cyclops (report)

External references