Loki
Loki is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Loki is an active ransomware group known for double-extortion tactics.
Loki is an active ransomware/extortion group that lists its victims on a public leak site. They target a range of organizations, using encryption and data publication as leverage for extortion. Key TTPs include ransomware deployment, data exfiltration, and double-extortion tactics. Defenders should monitor for exposed infrastructure, enforce network segmentation, and maintain regular offline backups of critical data.
Loki is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Loki primarily uses TTPs such as ransomware encryption, data exfiltration, and double-extortion tactics.
Defenders are recommended to monitor for exposed infrastructure, enforce network segmentation, and maintain regular offline backups of critical data.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.