A representative of the Knight ransomware gang is reportedly selling the source code of the third version of the ransomware on a hacking forum.

Knight ransomware appeared in late July 2023 as a new name for the Cyclops operation. It targets Windows, macOS, and Linux/ESXi systems
KELA security researchers spotted the ad two days ago on a hacking forum, by someone using the alias Cyclops (known as a representative of the Knight ransomware gang). The ad said that the source code would be sold to a single person , but no information was given about the price.
See also: PSI Software confirms ransomware attack
“By selling the source code for the Knight 3.0 ransomware, the source code for the panel and locker will be sold. All source code is owned and written in Glong C++,” Cyclops says in the post.
Version 3.0 of the Knight locker was released on November 5, 2023, with 40% faster encryption, a new ESXi module, and various other improvements.
Regarding the sale, Cyclops said that it will prioritize trusted users with a deposit and that the purchase will be made through a transaction guarantor either on RAMP or the XSS hacking forum.
The seller has published contact addresses for the Jabber and TOX messaging services so that potential buyers can reach the seller and negotiate a final deal.
KELA told BleepingComputer that Jabber is new, but the TOX ID mentioned in the forum post is known and has been previously associated with the Knight ransomware.
See also: LockBit ransomware: Member arrests and decryption tool
The reason behind the sale of the source code for the Knight ransomware remains unclear. However, according to KELA, no activity by the ransomware's representatives has been detected on forumssince December 2023.
Also, the victim extortion site is currently offline, with the last victim reported on February 8. The Knight ransomware gang claims that since July 2023, it has compromised 50 organizations.
Based on the details from KELA, the Knight ransomware operation appears to have been inactive for some time, so a withdrawal of the group is likely.

What does the sale of Knight ransomware source code mean?
By selling the ransomware code, we may be faced with new, more dangerous attacks. Knight ransomware is a sophisticated tool , and its buyer can improve it even further to cause more damage to victims. Fortunately, it will only be sold to one person, so there will be no widespread exploitation of the source code, which could lead to the creation of many new variants and therefore a drastic increase in ransomware attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Cactus ransomware gang: Stole Schneider Electric data
However, there is a risk that we will see new versions of Knight ransomware, even more sophisticated and difficult to deal with.
At this stage, it is vital that individuals and companies take all precautionary measures to protect themselves. This may include promoting education cybersecurity, updating software and security, and creating backups.
Source: www.bleepingcomputer.com
