Ransomware Group intelligence
Arkana
InactiveTrack Arkana with 6 published victims and 2 known leak locations in a single intelligence view.
Overview
Arkana is tracked by Breach House as a ransomware group with 6 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 3h ago | arkanabb66ee4nsdji6la2bu6bwqe3dbtsyf3rxrv6vhiehod7utagad.onion |
| Leak location 1 | Onion service | Down checked 3h ago | ransomwvbabemdnwl7lzgeenyfmmhskaed6jcruwhkvapsia76vttzyd.onion |
Top Activity Sectors (5)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Arkana, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: arkana executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: arkana persists by injecting malicious registry run keys to ensure recurring execution after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: arkana disables antivirus tools and modifies security software configurations to evade detection and persistence mechanisms.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: arkana deletes Volume Shadow Copies and system restore points via vssadmin to prevent data recovery and increase victim pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: arkana scans network shares using built-in Windows tools to identify additional victim systems for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: arkana moves laterally through SMB/Windows Admin Shares to compromise additional servers within victim networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: arkana encrypts critical files and backups using custom ransomware binaries to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: arkana invokes system shutdown commands and service termination scripts to disrupt operational continuity.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (6)
Search, filter and paginate the victim timeline for Arkana. Showing 1–6 of 6.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Ticketmaster id20513 View details | United States | Communication / Marketing | ||
|
[AI generated] Ticketmaster Entertainment, Inc. is an American ticket sales and distribution company headquartered in Beverly Hills, California. It operates in more than 20 countries, delivering over 100 million tickets annually. They provide services for worldwide events including concerts, sports events, theatre performances, and family shows. Apart from ticket distribution, Ticketmaster offers marketing and support for event organizers. |
|||||
| Ransomware | Synopsys id20512 View details | United States | Energy | ||
|
[AI generated] Synopsys is a leading company in electronic design automation (EDA) and semiconductor IP. It also provides software integrity tools. Founded in 1986 and headquartered in Mountain View, California, Synopsys offers innovative solutions that help designers manage complexity, develop high-quality, and high-performance silicon, meet critical time to market and power consumption requirements, and avoid costly redesigns. |
|||||
| Ransomware | Infinox id20515 View details | United Kingdom | Services | ||
|
[AI generated] Infinox is a UK-based financial services company that offers clients the ability to trade FX, indices, commodities and equities. It provides a variety of trading platforms, including MT4 and IXO, and offers multilingual customer support. Infinox aims for transparency and customer empowerment, offering resources for traders to increase their market knowledge. It's regulated by the FCA. |
|||||
| Ransomware | Anglo American plc id20514 View details | United Kingdom | Manufacturing / Engineering | ||
|
[AI generated] Anglo American plc is a multinational mining corporation based in Johannesburg, South Africa and London, UK. It is the world's largest platinum and diamond producer, with operations in more than 40 countries. Besides platinum and diamonds, it mines copper, nickel, iron ore, metallurgical and thermal coal. Founded in 1917, it is one of the world's top mining and natural resource companies. |
|||||
| Ransomware | Oregon Surveillance Network - OSN! id18721 View details | United States | Telecommunications | — | |
|
[AI generated] "Oregon Surveillance Network - OSN!" is a company that specializes in providing cutting-edge surveillance systems and security solutions in Oregon, USA. They cater to a variety of sectors ranging from residential, commercial, to industrial clientele. Their services include installing CCTV systems, alarm systems, access control mechanisms, and offering security consultations. |
|||||
| Ransomware | Wide Open West - WOW! id18685 View details | United States | Telecommunications | — | |
|
[AI generated] Wide Open West (WOW!) is the sixth largest cable operator in the United States. It provides telecommunications, broadband, and cable television services. Its portfolio includes high-speed internet, data, voice, cloud services, and cable television. Operating mainly in the Midwest and Southeast, WOW! is recognized for exceptional service and nationally ranked for customer satisfaction. |
|||||