Ransomware Group intelligence
Apos
InactiveTrack Apos with 16 published victims and 2 known leak locations in a single intelligence view.
Overview
Apos is tracked by Breach House as a ransomware group with 16 published victims.
Brazil is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | yrz6bayqwhleymbeviter7ejccxm64sv2ppgqgderzgdhutozcbbhpqd.onion |
| Leak location 2 | Web location | Down checked 1h ago | apos.blog |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Apos, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: apos executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: apos leverages native API calls to bypass detection while executing malicious functions across victim systems.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: apos adds malicious registry run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: apos disables security tools like EDR and AV by terminating processes or modifying system configurations to ensure persistence.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: apos encodes ransom notes and payload binaries using custom XOR or AES routines to evade static analysis.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: apos deletes Volume Shadow Copies and backup directories using vssadmin and system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: apos spreads laterally via SMB/Windows Admin Shares to encrypt additional machines within the victim network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: apos exfiltrates stolen data via encrypted C2 channels before deploying ransomware to maximize extortion leverage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: apos encrypts victim files using custom symmetric encryption routines targeting documents, databases, and critical assets.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: apos invokes system shutdown commands and service termination scripts to cripple operational recovery efforts.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (16)
Search, filter and paginate the victim timeline for Apos. Showing 1–16 of 16.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ACMARK id21755 View details | ?? | Communication / Marketing | ||
|
ACMARK s.r.o. was established in 2009 and its mission is to provide high-quality consulting services designed to support the marketing and business processes in organizations. To support these activities and processes our company supplies globally tested information technology which helps our customers successfully develop their own activities and reach the maximum possible profitability. |
|||||
| Ransomware | RH id20608 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | wow pictures id20607 View details | Australia | Other | — | |
|
we exfiltrate all the data from server ,if ransom not paid we can publish all the data or sale to competitors |
|||||
| Ransomware | Ha******.us id20606 View details | Healthcare / Pharma | — | ||
|
we exfiltrate all the data Ha******.us from server SSN, FINANCIAL RECORD, MEDICAL RECORDS,PERSONAL DATA,if ransom not paid we can publish all the data or sale to competitors |
|||||
| Ransomware | infraestructures.cat id20605 View details | Spain | Communication / Marketing | — | |
|
We have compromised your main server infraestructures.cat we also took copy of all the data. We give you 15 days before we leak the data. this can only be resolved threw our support portal we provided. Do the right thing before things get worse. |
|||||
| Ransomware | Lawton Partners id20604 View details | Canada | Finance / Legal / Insurance | — | |
|
Over the years, Lawton Partners has continued to grow and adapt to meet the ever-changing financial marketplace and the evolving needs of its clients. The company has broadened its services by dedicating whole divisions to specialized fields such as Estate Planning, Business Succession, Planned Giving, and the creation or enhancement of Pensions and Savings Plans. All are under the direction of highly experienced leaders who offer professional advice and guidance in their chosen fields of expertise. We believe that every person who is involved in administering a client account should be working at the highest standards of knowledge and professionalism on your behalf. That's why our company has made it a priority to be an industry leader in encouraging our support staff to enroll in industry-related courses. It's important that everyone involved with handling even the smallest details involved in administering a client's account has the highest possible training and experience. |
|||||
| Ransomware | KIU System Solutions id18461 View details | Argentina | Services | ||
|
🌐 kiusys.com💲 23400000📍 Paraguay |
|||||
| Ransomware | Netcom-World id18152 View details | United States | Other | ||
|
🌐 netcom-world.com💲 Undisclosed📍 Undisclosed |
|||||
| Ransomware | InternetWay id18151 View details | Brazil | Other | ||
|
🌐 www.internetway.com.br💲 Undisclosed📍 Undisclosed |
|||||
| Ransomware | M-1 TOOLWORKS id17658 View details | United States | Public Sector | ||
|
🌐 m1toolworks.com💲 8000000📍 United States |
|||||
| Ransomware | Auxis id16490 View details | United States | Public Sector | ||
|
🌐 www.auxis.com💲 162500000📍 United States |
|||||
| Ransomware | Drogarias Preço Bom id15013 View details | Brazil | Communication / Marketing | ||
|
🌐 bomprecodrogarias.com.br💲 5000000📍 Brazil |
|||||
| Ransomware | Drogaria Preco Bom id12190 View details | Brazil | Communication / Marketing | ||
|
5.6GB5MBrazilPrivate dataPublishedbomprecodrogaria.com.br |
|||||
| Ransomware | Sunlux Group id12189 View details | France | Finance / Legal / Insurance | ||
|
160GB5.1MFrancePrivate dataFinancial dataNot publishedsunlux-group.com |
|||||
| Ransomware | Algen Healthcare id12188 View details | India | Healthcare / Pharma | ||
|
90GB5MIndiaFinancial dataPrivate dataNot publishedalgenhealthcare.co |
|||||
| Ransomware | Bitz Softwares id12187 View details | Brazil | IT | ||
|
18.1MB11.3MBrazilSource codeNot publishedbitzsoftwares.com.br |
|||||