Skip to content
skopnix
← adversaries
Crime

mamona

ransomware.liverefreshed 2026-09-15

sigil

Analyst brief

Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed before reverting; as a standalone strain it operates entirely offline with no C2 communication, uses custom encryption, and targets Windows systems.

Take it with you
References
Early access

Track mamona on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected