Netskope Threat Labs

Knight

ATP Sandbox Adv. HeuristicsAV

Knight is ransomware that encrypts files on infected systems and demands payment for decryption. Its operators ran an affiliate program that rented the encryptor to crews that handled access and negotiation, and they pressured victims through data theft and leak site threats. The brand surfaced in 2023 and later rebranded, reflecting the fast churn of ransomware franchises whose operators reuse infrastructure and tactics under new names.

First seen
November 2023
Last seen
October 2026
Alert Name
ByteCode-MSIL.Ransomware.Knight
Gen:Variant.Ransom.Knight.11
Gen:Variant.Ransom.Knight.2
Gen:Variant.Ransom.Knight.8
Trojan.Ransom.Knight.A
Trojan.Ransom.Knight.B
Trojan.Ransom.Knight.C
Trojan.Ransom.Knight.D
Trojan.Ransom.Knight.E
Trojan.Ransom.Knight.F