Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Knight ransomware

10 victims listed on the Knight leak site across 7 countries. Most recent disclosure .

Victims
10
0% of all tracked
Countries
7
Most: United States
Sectors
7
Most: Business Services
First seen
Jan 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Knight and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Knight, previously Cyclops, has emerged as a threat actor causing 10 incidents globally involving seven different countries, with the United States, Brazil, and Spain hit most frequently by Business Services, Public Sector, and Transportation/Logistics sectors.

Who Knight is

[Cyclops](group/cyclops) rebrand

Recorded activity

Disclosures attributed to Knight in this database run from January 2024 to February 2024, totalling 10 victims — 0% of everything tracked here. Knight has listed victims in 7 countries in this database, most often United States, followed by Spain and Brazil. The sectors appearing most in its listings are Business Services, Public Sector, Transportation/Logistics.

YARA detection rules

knight.yar
/*
Knight ransomware (rebranded Cyclops)
*/

rule Knight_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.knight"
        description = "Detects Knight ransomware ransom note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = "knight_l" ascii nocase
        $s2 = "How To Restore Your Files.txt" ascii nocase
        $s3 = "Knight" ascii
        $s4 = ".knight_l" ascii

    condition:
        2 of them
}

Community-contributed rules for Knight, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Knight has disclosed 10 victims on its leak site, 0% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.

The group has listed organisations in 7 countries, most often in United States (2 victims), followed by Spain, Brazil, Vietnam.

By industry, its listings concentrate in Business Services, Public Sector, Transportation/Logistics — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Knight is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Knight victims 10

Organization Disclosed
DHX–Dependable Hawaiian Express
USUnited States
GRUPO SCA(Release of all data)
ESSpain
FEPCO Zona Franca SAS
COColombia
AbelSantosyAsociados
ARArgentina
CityDfDefiance(Disclosure of all)
USUnited States
DIROX LTDA (Vietnã)
VNVietnam
ABECOM LTDA
BRBrazil
Chamber of Deputies of Romania (Camera Deputaților din România)
RORomania
Agro Baggio LTDA
BRBrazil
GRUPO SCA
ESSpain

Frequently asked questions

What is Knight ransomware?

Knight is a ransomware threat group that has claimed 10 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Knight attacked?

Knight has claimed 10 victims in our database, representing 0% of all tracked ransomware attacks. The most targeted countries are United States, Spain, Brazil, Vietnam.

Which countries does Knight target?

Knight has attacked organizations in 7 countries. The top targeted countries are: United States, Spain, Brazil, Vietnam.

Which industries does Knight target?

Knight most frequently targets the Business Services, Public Sector, Transportation/Logistics sectors based on victim disclosures in our database.

Is Knight still active?

Knight's most recent victim disclosure in our database was on February 12, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.