A Deep Dive into the Ransomware Timeline and Its Shadow Empire | Cyber Codex

Terminology Used

Timeline of Ransomware

1989: The First Sting — AIDS Trojan

2005–2006: GpCode, Archiveus


2013: CryptoLocker

2015–2016: Tox, Satan — Rise of Ransomware-as-a-Service (RaaS)

2017: WannaCry & NotPetya


2018–2020: GandCrab, Maze, REvil



2021: Colonial Pipeline Breach (DarkSide)

2022: Conti Leaks & LockBit Ascendancy


2023–2024: Fragmentation & Op Cronos


2025: Decentralized Chaos + Solo Affiliates
The Conti Corporation: A Ransomware Startup at Scale


Modern Ransomware Kill Chains (MITRE Mapped)

Top Threat Actors & Their Traits

The Bassterlord Manual Leak

LockBit vs Conti: Negotiation Engineered

Current Landscape: Decentralized, Agile, Relentless

PreviousAI-Powered Social Engineering: The New Cybercrime Playbook | Cyber CodexNextThe OSINT Hacker’s Cheat Sheet in 2025 | Cyber Codex
Last updated
Was this helpful?
