knight

Aliases: Cyclops

First seen
2021-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:13:33

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

Knight, also known as Cyclops, is a ransomware family that targets critical infrastructure and various industries. It is known for encrypting data and demanding cryptocurrency payments for decryption keys.

Detection coverage

  • 3 YARA rules

Detection rules

  • MALPEDIA_Win_Knight_Auto (yara-rule)
  • MALPEDIA_Win_Disk_Knight_Auto (yara-rule)
  • HARFANGLAB_Charmingkitten_Cyclops (yara-rule)

Reports & references

  • Broadcom/Symantec — Ransomhub Knight Ransomware (report)
  • ransomlook.io — Knight (report)
  • bleepingcomputer.com — Knight Ransomware Rebrands From Cyclops Targets Windows Linux Esxi (report)
  • Trend Micro — Knight Ransomware Raas (report)
  • sentinelone.com — Knight Ransomware Raas Targets Multiple Platforms (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Knight (report)

External references