Loki
Loki is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
source: ransomware.live1 refs →
Loki is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Loki primarily uses TTPs such as ransomware encryption, data exfiltration, and double-extortion tactics.
Defenders are recommended to monitor for exposed infrastructure, enforce network segmentation, and maintain regular offline backups of critical data.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.