Ransomware Group intelligence
AuditTeam
ActiveTrack AuditTeam with 17 published victims and 2 known leak locations in a single intelligence view.
Overview
AuditTeam is tracked by Breach House as a ransomware group with 17 published victims.
Russian Federation is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 1d ago | cjg2avmzoly7k6mw7xobnyre354jxro4qegkoazhsmigdk2j3aziexyd.onion |
| Leak location 1 | Onion service | Up checked 1d ago | 6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion |
Top Activity Sectors (6)
Typical Attacks (11)
▼MITRE ATT&CK does not currently catalogue AuditTeam, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: AuditTeam executes PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: AuditTeam leverages native API calls to interact with Windows services and evade detection.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: AuditTeam modifies Registry Run Keys to ensure persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: AuditTeam disables antivirus tools and security software to prevent system recovery attempts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: AuditTeam encrypts victim files using encoded data streams to maximize impact.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: AuditTeam performs file deletion to remove evidence and disable backup mechanisms.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: AuditTeam uses process discovery to identify critical system processes for targeted disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: AuditTeam exploits SMB/Windows Admin Shares for lateral movement across networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: AuditTeam exfiltrates sensitive data via C2 channels to increase ransom demands.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: AuditTeam encrypts critical data files for impact, holding encrypted content as leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: AuditTeam invokes Inhibit System Recovery techniques to block volume shadow copy restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[rand].README.txt
==================================================================== [ AUDIT LOG: SEVERE INFRASTRUCTURE COMPROMISE VERIFIED ] ==================================================================== ATTN: Executive Management and Legal Compliance Teams This notice serves as absolute cryptographic proof that your network defenses have been fully bypassed. We have acquired extensive archives of your corporate data, internal communications, and protected records. Your failure to implement adequate security controls is now a severe liability for your board of directors and stakeholders. [ CURRENT STATUS ] Your entity is currently operating within a private Remediation Window on our DATA EXPOSURE LOGS. You have two options: OPTION A (REMEDIATION): Access our secure portal, initiate contact, and pay the Audit & Consulting fee. We will permanently purge the acquired data and provide a report on your vulnerabilities. Your reputation and compliance status remain intact. OPTION B (PUBLIC TRANSPARENCY): Ignore this notice. Once the countdown expires, we will release the entire data archive to the public internet. We will also directly notify your clients, partners, and regulatory oversight bodies of your negligence. Prepare for massive statutory fines and lawsuits. 1. Download and install the Tor Browser: https://www.torproject.org/ 2. Open the Tor Browser and enter the following address: http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion 3. Use your Audit ID to contact us: [snip] The decision belongs to your executive board. Disclosure is imminent. ====================================================================
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (17)
Search, filter and paginate the victim timeline for AuditTeam. Showing 1–17 of 17.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | De***up id31812 View details | Russian Federation | — | ||
|
No additional victim description available. |
|||||
| Ransomware | I-SYS id30016 View details | Russian Federation | Other | ||
|
I-SYS is an entity based in Russia, operating in the other sector. The company likely provides specialized services or products, given its sector classification. I-SYS was listed as a ransomware victim associated with AuditTeam. |
|||||
| Ransomware | I-SYS id30016 View details | Russian Federation | Other | ||
|
I-SYS is a Russian software development and business automation company with 25 years of experience, offering custom development, digital transformation consulting, and DevOps services, with core products including the DocTrix electronic document management platform and the AI assistant Матрёшка, serving over half of Russia's TOP-100 enterprises. |
|||||
| Ransomware | I-***YS id29864 View details | Russian Federation | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Paid Victim 111CEAA5AD9DA2F1 id29624 View details | Russian Federation | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | ca***lm id29563 View details | Russian Federation | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Paid Victim B35411691DDC2265 id29421 View details | Russian Federation | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | On***de id29454 View details | Russian Federation | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Mopas Online Supermarket id29328 View details | Türkiye | Agriculture / Food | ||
|
mopas.com.tr is a prominent Turkish retail chain and e-commerce platform primarily serving the Marmara region, offering an extensive online shopping experience that covers everything from fresh produce, halal meat, and dairy to household cleaning supplies and personal care products, all backed by a robust local delivery network that ensures fast, same-day service for residents in cities like Istanbul and Kocaeli. |
|||||
| Ransomware | Trésor Public id29221 View details | Senegal | Public Sector | ||
|
DGCPT (Direction Générale de la Comptabilité Publique et du Trésor) is Senegal's public treasury authority under the Ministry of Finance, responsible for public accounting, government fund management, cash flow, and public debt operations. |
|||||
| Ransomware | Mo***et id29160 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Tr***ic id29009 View details | Senegal | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Kawasaki Motors Philippines Corporation id27991 View details | Philippines | Manufacturing / Engineering | ||
|
Kawasaki Motors Philippines Corporation (KMPC), located in Muntinlupa, Metro Manila, is a leading manufacturer and distributor of Kawasaki motorcycles in the Philippines, operating for over 40 years. As an affiliate of Kawasaki Heavy Industries, Ltd. (KHI), it produces commuter bikes, tricycles, and underbones, with an annual capacity of 250,000 units, making it one of the largest plants in Kawasaki's global network. |
|||||
| Ransomware | joycity id27990 View details | Korea, Republic of | IT | ||
|
Joycity is a prominent South Korean game developer and publisher founded in 1994 and listed on the KOSDAQ. Renowned for its innovation and global reach, the company originally pioneered the hip-hop-themed sports genre with its self-developed FreeStyle series, which became a cultural milestone for players across Asia. In the mobile era, Joycity successfully pivoted to the Strategy (SLG) genre, producing high-revenue titles like Gunship Battle: Total Warfare and Pirates of the Caribbean: Tides of War, with international markets consistently accounting for over 70% of its total revenue. Currently, Joycity is actively expanding into Web3 technologies and major cross-platform projects. Its blockbuster collaboration with Capcom and Aniplex, Resident Evil Survival Unit, has already surpassed 5 million global downloads as of early 2026, demonstrating the company’s robust R&D and operational expertise in managing world-class intellectual properties. |
|||||
| Ransomware | Paid Victim CCD233FEE92FFA2D id27989 View details | Hong Kong | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Paid Victim A98A624456DA525F id27988 View details | Thailand | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Paid Victim D3C1388C1B73BCA2 id27987 View details | China | Other | ||
|
[AI generated] N/A |
|||||