Ransomware Group intelligence
Arvinclub
InactiveTrack Arvinclub with 35 published victims and 2 known leak locations in a single intelligence view.
Overview
Arvinclub is tracked by Breach House as a ransomware group with 35 published victims.
Iran, Islamic Republic of is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | 3kp6j22pz3zkv76yutctosa6djpj4yib2icvdqxucdaxxedumhqicpad.onion |
| Leak location 2 | Onion service | Down checked 1h ago | arvinc7prj6ln5wpd6yydfqulsyepoc7aowngpznbn3lrap2aib6teid.onion |
Top Activity Sectors (9)
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Arvinclub, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: arvinclub executes malicious commands via PowerShell scripts to stage payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: arvinclub modifies Registry Run Keys to ensure malware execution upon system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: arvinclub disables antivirus tools and security software to evade detection during intrusion.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: arvinclub deletes Volume Shadow Copies and backup directories to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: arvinclub performs remote system discovery to locate high-value targets within victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: arvinclub scans network shares to identify victim systems and map lateral movement paths.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: arvinclub exploits SMB/Windows Admin Shares to move laterally across networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: arvinclub encrypts victim files using custom ransomware binaries to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: arvinclub invokes system recovery inhibition commands to block forensic analysis and remediation.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (35)
Search, filter and paginate the victim timeline for Arvinclub. Showing 1–35 of 35.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Islamic Azad University Electronic Campus id9093 View details | Iran, Islamic Republic of | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Jahesh Innovation id9086 View details | Colombia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Kimia Tadbir Kiyan id9082 View details | Iran, Islamic Republic of | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Islamic Azad University of Shiraz id8999 View details | Iran, Islamic Republic of | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Pasouk biological company id8930 View details | Iran, Islamic Republic of | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Shirin Travel Agency id8917 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aban Tether & OK exchange id8429 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | sti company id8232 View details | Colombia | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sabalan Azmayesh id8091 View details | Iran, Islamic Republic of | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Parsian Bitumen id8072 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Draje food industrial group id8068 View details | Iran, Islamic Republic of | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | seaside-kish co id8047 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AFTA Isfahan id8040 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | hamyari Shahrdari golestan id8039 View details | Iran, Islamic Republic of | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Haraz dairy id8038 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 150k sib360 Database id8037 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Padena Factory id8036 View details | Iran, Islamic Republic of | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | Bitimen id171 View details | Other | |||
|
A harmful truth is better than a useful lie |
|||||
| Ransomware | Al Bijjar id3237 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AM International id3216 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | stormous id2900 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bedfordshire.police.uk id2815 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | afcx.co id2000 View details | Colombia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | vidisha.kvs.ac.in id1700 View details | India | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Revil id1683 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bureau van Dijk(bvdinfo.com) id1403 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Compilation of Many Breaches (COMB) id1350 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CardPayPortal id714 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 33M Bank Mellat – Iran id713 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Etoudplus.ir id712 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Beh Pardakht Mellat Cards id711 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UtAir id710 View details | Russian Federation | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Leiden University Hacked id709 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | T-Mobile id708 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | elitemate.com id696 View details | Other | — | ||
|
No additional victim description available. |
|||||