Ransomware Group intelligence
Arcusmedia
ActiveTrack Arcusmedia with 121 published victims and 1 known leak locations in a single intelligence view.
Overview
Arcusmedia is tracked by Breach House as a ransomware group with 121 published victims.
Brazil is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion |
Top Activity Sectors (17)
- Not identified 36
- Communication / Marketing 19
- IT 9
- Retail / E-commerce 6
- Transportation / Travel / Logistics 6
- Services 6
- Finance / Legal / Insurance 6
- Telecommunications 4
- Public Sector 3
- Hospitality / Food & Beverage / Tourism 3
- Manufacturing / Engineering 2
- Healthcare / Pharma 2
- Education 2
- Energy 1
- Agriculture / Food 1
- Construction / Real Estate 1
- NGOs / Associations 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Arcusmedia, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: arcusmedia executes malicious payloads via PowerShell scripts to stage ransomware deployment across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: arcusmedia persists by creating registry run keys containing paths to their encrypted ransomware executable.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: arcusmedia disables antivirus tools by terminating security processes and modifying Windows Defender settings to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: arcusmedia injects junk code into legitimate binaries to evade static analysis and pack their malicious components.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: arcusmedia deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: arcusmedia discovers remote systems via SMB and LDAP queries to map the victim network for expansion.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: arcusmedia scans network shares using net share commands to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: arcusmedia exfiltrates stolen data using encrypted channels before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: arcusmedia encrypts victim files using custom ransomware binaries targeting documents and backups with high-entropy ciphers.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: arcusmedia calls system recovery inhibitors like shutdown scripts to prevent forensic analysis and system restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (121)
Search, filter and paginate the victim timeline for Arcusmedia. Showing 101–121 of 121.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Exhaustpro shops id13084 View details | United States | Retail / E-commerce | ||
|
This female owner and her partners... |
|||||
| Ransomware | BankSelfStorage id13083 View details | United Kingdom | Finance / Legal / Insurance | ||
|
We offer personal and business storage... |
|||||
| Ransomware | GED Lawyers & .. id13082 View details | United States | Finance / Legal / Insurance | ||
|
Gedlawyers.com Proudly Serving Clients For Personal... |
|||||
| Ransomware | WinFashion ERP id12956 View details | United States | Other | ||
|
WinFashion is an international company supplying... |
|||||
| Ransomware | Langescheid GbR id12811 View details | Germany | Other | ||
|
your traditional logistic partner from Germany.... |
|||||
| Ransomware | Franja IT Integradores de Tecnología id12810 View details | Colombia | Other | ||
|
Franja IT is a company that... |
|||||
| Ransomware | Duque Saldarriaga id12809 View details | Colombia | Communication / Marketing | ||
|
We are a marketing company, established... |
|||||
| Ransomware | BHMAC id12808 View details | Croatia | Other | ||
|
Bhmac is a company that operates... |
|||||
| Ransomware | Botselo id12807 View details | South Africa | Other | ||
|
Botselo.co.za Botselo Mills is a company... |
|||||
| Ransomware | Immediate Transport – UK id12806 View details | United Kingdom | Communication / Marketing | ||
|
Immediatetransport.comImmediate Transportation Co. is a privately... |
|||||
| Ransomware | Colégio Nova Dimensão id12614 View details | Brazil | Other | ||
|
colegiond.com.br The world has changed and... |
|||||
| Ransomware | RIO TECHNOLOGY id12571 View details | United States | IT | ||
|
Riotechnology.com.co Riotechnology, experts in software, hardware... |
|||||
| Ransomware | Egyptian Sudanese id12570 View details | Sudan | Other | ||
|
Egyptiansudanese.com The Egyptian Sudanese company was... |
|||||
| Ransomware | BRAZIL GOV id12555 View details | Brazil | Public Sector | ||
|
Santoantoniodapatrulha.rs.gov.br : City Hall of Santo... |
|||||
| Ransomware | Braz Assessoria Contábil id12554 View details | Brazil | Other | ||
|
Brazcontabil.com.br Braz Assessoria Contábil is a company... |
|||||
| Ransomware | Thibabem Atacadista id12553 View details | Brazil | Other | ||
|
Thibabem.com.br Thibabem Atacadista e Distribuidor operates... |
|||||
| Ransomware | FILSCAP id12552 View details | Philippines | NGOs / Associations | ||
|
Filscap.com.ph : Filipino Society of Composers,... |
|||||
| Ransomware | Cusat id12551 View details | Argentina | Other | ||
|
Cusat.com.ar Cusat develop and operate Geo-Location... |
|||||
| Ransomware | Frigrífico Boa Carne id12550 View details | Brazil | Other | ||
|
Frigboacarne.com.br The BOA CARNE Refrigerator was... |
|||||
| Ransomware | GOLD RH S.A.S id12549 View details | Colombia | Other | ||
|
Goldrh.com.coGold RH is a company with... |
|||||
| Ransomware | Grupo SASMET id12548 View details | Brazil | Other | ||
|
Grupo SASMET is a company that... |
|||||