Ransomware Group intelligence
Argonauts
InactiveTrack Argonauts with 13 published victims and 1 known leak locations in a single intelligence view.
Overview
Argonauts is tracked by Breach House as a ransomware group with 13 published victims.
Italy is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | jbmk7h6xlkedn2gg5yi76zca6y3jgdlp5wchlsrd7735tlnrmmvqe5ad.onion |
Top Activity Sectors (3)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Argonauts, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: argonauts uses PowerShell scripts to execute malicious commands and spread payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: argonauts leverages native API calls to interact with system functions for execution and evasion.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: argonauts modifies registry run keys to establish persistence and ensure recurring execution.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: argonauts disables security tools like antivirus software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: argonauts forces Safe Mode Boot to disable non-essential services and evade detection mechanisms.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1070.004 File Deletion Stealth
What they do: argonauts deletes Volume Shadow Copies and backup files via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: argonauts performs process discovery to identify active processes and select targets for manipulation or termination.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: argonauts uses SMB/Windows Admin Shares for lateral movement between networked victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: argonauts encrypts victim files using custom ransomware binaries to achieve data encryption for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: argonauts performs internal defacement by replacing victim files with ransom notes or altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (13)
Search, filter and paginate the victim timeline for Argonauts. Showing 1–13 of 13.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | baseisapis.it id16106 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | ACM_IT id15809 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | RDC id15808 View details | Canada | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | ivylifesciences.com id15682 View details | United States | Other | ||
|
Due to the company’s refusal to pay the ransom,We continue to sell ALL DATA SIZE: 200GB+ |
|||||
| Ransomware | BOCCHI S.r.l. id15681 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | contactsrl.eu id15680 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | 弘潔科技股份有限公司 id15679 View details | Taiwan, Province of China | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | avisinterac.it id15678 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | 藤森工業株式会社 id15677 View details | Japan | Other | ||
|
ALL DATA SIZE: 140GB [news:00.pdf] Due to the company’s refusal to pay the ransom,We continue to sell |
|||||
| Ransomware | AIAD.IT id15676 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | crollatelecom.it id15675 View details | Italy | Telecommunications | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | fitcisl id15674 View details | Italy | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | NUUO id15673 View details | Taiwan, Province of China | Communication / Marketing | ||
|
There is no excerpt because this is a protected post. |
|||||