For cybersecurity professionals, malware researchers, and reverse engineers.
🔐 Archive Password: infected
Welcome to the Ultimate Ransomware Collection – a curated, ever-growing archive of real-world ransomware samples collected from active campaigns, dark web leaks, honeypots, and malware telemetry.
This is a research-only repository aimed at:
- 🧪 Malware analysis & reverse engineering
- 🔐 Ransomware detection & evasion testing
- 📊 Behavioral fingerprinting & IOC collection
- 🧱 Threat intelligence and cybersecurity education
🚨 IMPORTANT: This repository is no longer actively maintained. It is preserved as a historical archive and community reference.
📂 This repo contains:
- Encrypted ZIP archives of ransomware samples
- Collected by family, variant, and campaign
- MD5/SHA256 hashes (when available)
- Optional decryptor files or ransom notes (if obtained)
- 🦠 WannaCry / NotPetya / Ryuk
- 👹 Locky / GandCrab / Cerber
- 🐍 Snake / Dharma / Maze
- 💣 New & obscure APT-level ransomware strains
All files are password protected to avoid accidental execution and flagging by GitHub’s automated scanners.
These are live ransomware binaries. Mishandling them can result in total data loss, network infection, or legal consequences.
- 🔒 Only analyze in offline, isolated VMs (e.g., Cuckoo, Remnux, FLARE-VM)
- 🚫 Never run on a host machine or connected network
- ⚖️ Ensure compliance with local laws and institutional policy
By accessing this repository, you agree to:
- Use the content solely for legitimate security research
- Accept full responsibility for any outcomes or misuse
- Understand that the maintainer(s) disclaim all liability for damages, losses, or legal issues
Found a rare strain? Wanna expand the archive?
- 🧾 Submit PRs with samples, hashes, decryptors, or metadata
- 📥 Use GPG encryption or drop links via issue (if GitHub allows)
- ✅ Include family name, source, and hash for verification
All contributors are credited unless anonymity is requested.
- 🔍 Static: Ghidra, IDA Pro, PEStudio
- 🧪 Dynamic: Cuckoo Sandbox, Any.Run, Cape
- 🔒 Safeguards: Snapshots, Deep Freeze, VLAN isolation
- 📚 Intel: VirusTotal, Hybrid Analysis, ANY.RUN, MalwareBazaar
Some samples and intelligence are collected from:
- 🏴☠️ Threat-sharing communities (Tox groups, dark web, etc.)
- 🧲 Public malware feeds & honeypots
- 🔬 Independent researchers & reverse engineers
Special thanks to malware archivists & digital forensics warriors worldwide. 🫡
This repository is intended strictly for educational and professional research purposes.
The author(s) do not condone the use of malware for malicious activity.
Proceed with caution, use responsibly, and always sandbox like your SSD depends on it (because it does).
Stay sharp. Stay safe. Dissect the dark.
