Ransomware group profile · #569 by claimed victims
Onepercent ransomware
OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using phishing with IcedID trojans, Cobalt Strike, and double-extortion, threatening a "one percent leak" of data before escalating to a full dump or sale to REvil; the FBI issued a formal flash advisory in August 2021.
Tactics, techniques and procedures
ATT&CK technique mapping for Onepercent is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Onepercent ransomware still active?
How many victims has Onepercent claimed?
Which industries does Onepercent target?
Which countries are most affected by Onepercent?
Where does VULONE get Onepercent victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].