Skip to content
skopnix
← adversaries
Crime

onepercent

ransomware.liverefreshed 2026-09-15

sigil

Analyst brief

OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using phishing with IcedID trojans, Cobalt Strike, and double-extortion, threatening a "one percent leak" of data before escalating to a full dump or sale to REvil; the FBI issued a formal flash advisory in August 2021.

Take it with you
References
Early access

Track onepercent on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected