// THREAT ACTOR
KILLADA_
DormantKILLADA is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of KILLADA — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Leak site mirrors
6 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
killadaayyuzdshwskrnsvh5owzuwa4yj7gs2vbhkcjpfslrplfgwwqd.onionKILLADA snapshot · 2026-07-07 04:00 -
killadaxczzw3wnuaxkygib67lk2qkgnki4gyjqoo76vh53egitoyaqd.onionKILLADA snapshot · 2026-07-07 03:09 -
killadax36r6bbb3md67ekcfv5yasdlnoaklyag66ot4tefa32ywgnyd.onionKILLADA snapshot · 2026-07-07 04:14 -
killadahaynpqrkppe2m2tgindbruaeiefzr7pm3cp47tzohhhnogwad.onionKILLADA snapshot · 2026-07-07 03:32 -
killada7qgdpvzpezjxaa64b47bz47hzbn6oql5aa4lppzzwymnukqqd.onionKILLADA snapshot · 2026-07-07 04:17 -
killada5556ahpb4cwmatv5qpzku2qmdlwawshtykpq37cvfva7zjhid.onionKILLADA snapshot · 2026-07-07 03:25