Calling All Hunters: Halcyon Threat Research Incentive Program (TRIP)

Company
Written by
Steve Salinas
Published on
May 5, 2025

Working for a company focused on ransomware is a double-edged sword. On the one hand, when I talk to customers, and they tell me how we saved them from a ransomware attack—or when I am at an event and a customer tells me how much they like what we are doing for them —it’s a great feeling.  

On the other hand, being hyper focused on ransomware means I don’t miss any news on ransomware attacks. It’s kind of like when you are considering purchasing a new car and everywhere you go you seem to see that model of car. Daily, I can't seem to miss stories about large multi-national corporations, school districts, city governments, and more falling victim to ransomware attacks.  

At Halcyon we know we are making a difference for our customers, helping them fight off the onslaught of ransomware attacks they face daily, but we want to do more but cannot do it alone. To that end, today we are announcing Halcyon TRIP (Halcyon Threat Research Incentive Program).

Halcyon TRIP

Halcyon TRIP is the first-ever ransomware-centric threat intelligence bounty program designed to reward independent threat researchers for their hard work in uncovering new and emerging ransomware threats. With the availability of Ransomware-as-a-Service (RaaS) platforms and the ease in which known ransomware groups rebrand and re-emerge under a different moniker, the volume and severity of attacks continues to increase.  

Our Halcyon RISE (Research, Intelligence, Services, Engineering) team, made up of the best and brightest in the world of ransomware threat intelligence researchers, works daily to collect fresh intel on changes in ransomware groups, their newest tactics, updated ransomware encryptors, and more.  

The reality, however, is the volume of potential intelligence they could incorporate into our attacker-driven protections outstrips their capacity to collect, interrogate, and act on. Halcyon TRIP is our outreach to the entire threat intelligence community to contribute their findings and be rewarded handsomely.  

We have committed $250,000 in reward payouts to the program to support independent threat researchers, as well as creating a means to collaborate with the Halcyon RISE team ongoing.  

Researchers who provide valuable intelligence via technical deep-dive write ups and  direct SIEM or Dashboard panel access or exports, will be rewarded based on a tiered  structure:

  • Tier 1: Novel details on ransomware groups, RaaS platforms, affiliate attackers, initial access brokers, and other key players in ransomware operations will be rewarded up to $10,000 per accepted submission  
  • Tier 2: Novel details on attacker tooling, infrastructure, evasion techniques, and other TTPs will be rewarded up to $5,000 per accepted submission.  
  • Tier 3: Novel details on droppers, loaders, packers, and other tooling will be rewarded up to $3,000 per accepted submission.  
  • Tier 4: Novel details on indicators of compromise (IOCs) or behavior chains will be rewarded up to $1,000 per accepted submission.

The Fine Print

Like with any program like this there are rules we must follow, listed below:

What We’re Looking For 

  • Improve detections and behavioral models 
  • Expand attacker infrastructure visibility 
  • Disrupt operations of the ransomware economy  

Keeping It Clean 

  • No payments to individuals affiliated with ransomware groups, extortion groups, or on OFAC list.    
  • All researchers must affirm sourcing and independent status   
  • A dedicated Halcyon vetting team reviews and approves submissions   
  • Payouts go through traceable, compliant channels only 

Learn More

We take ransomware very seriously. We’re building a program that respects your work and maintains our mission integrity. Learn more about Halcyon TRIP.

 

Halcyon.ai eliminates the business impact of ransomware. Modern enterprises rely on Halcyon to prevent ransomware attacks, eradicating cybercriminals’ ability to encrypt systems, steal data, and extort companies – talk to a Halcyon expert today to find out more, and check out our quarterly RaaS and extortion group reference guide, Power Rankings: Ransomware Malicious Quartile.

A laptop screen with a message that says Take Zero Chances With Ransomware.
Get a Demo

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.