Ransomware Group intelligence
Benzona
InactiveTrack Benzona with 14 published victims and 2 known leak locations in a single intelligence view.
Overview
Benzona is tracked by Breach House as a ransomware group with 14 published victims.
Romania is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 55m ago | benzona6x5ggng3hx52h4mak5sgx5vukrdlrrd3of54g2uppqog2joyd.onion |
| Leak location 2 | Onion service | Down checked 55m ago | rwsu75mtgj5oiz3alkfpnxnopcbiqed6wllyoffpuruuu6my6imjzuqd.onion |
Top Activity Sectors (5)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Benzona, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: benzona executes PowerShell scripts to run payload logic, disable defenses, and propagate across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: benzona disables or modifies security tools such as EDR agents and monitoring services to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: benzona deletes Volume Shadow Copies and backup artifacts via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: benzona performs remote system discovery to identify additional hosts and network topology.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: benzona performs process discovery to identify active services and processes for disruption or privilege escalation.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1135 Network Share Discovery Discovery
What they do: benzona uses network share discovery to locate victim file shares and staging directories for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: benzona uses SMB/Windows Admin Shares for lateral movement between networked hosts.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: benzona encrypts victim files and data stores using its ransomware payload to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: benzona stops critical services and processes to disrupt operations before or during encryption.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: benzona inhibits system recovery by destroying backups, disabling restore mechanisms, and altering recovery settings.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
RECOVERY_INFO.txt
ATTENTION! Your files have been encrypted by Benzona Ransomware. Sensitive data has been exfiltrated. Do not attempt to decrypt files yourself - this will lead to irreversible data loss and information leak. WHAT YOU MUST NOT DO: - Do not use recovery tools - Do not rename files - Do not contact law enforcement You have 72 hours to contact us: TO START NEGOTIATIONS: 1. Download TOR Browser: https://www.torproject.org/download/ 2. Install and open TOR Browser 3. Go to our chat: http://rwsu75mtgj5oiz3alkfpnxnopcbiqed6wllyoffpuruuu6my6imjzuqd.onion/ 4. Enter your Chat ID: [SNIP] News public: https://benzona6x5ggng3hx52h4mak5sgx5vukrdlrrd3of54g2uppqog2joyd.onion/ After deadline your data will be sold or published. Follow our instructions to avoid reputational losses.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (14)
Search, filter and paginate the victim timeline for Benzona. Showing 1–14 of 14.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | casamedica.com.gt id26002 View details | Guatemala | Communication / Marketing | — | |
|
[AI generated] "Casamedica.com.gt" is a Guatemala-based company that provides a range of medical equipment and supplies. Their product range includes everything from surgical instruments to hospital furniture and diagnostic equipment. Not just limited to sales, Casamedica also provides maintenance services for the equipment. They aim to improve the healthcare sector by catering to the specific needs of professionals in the field. |
|||||
| Ransomware | empreinte-hotel.com id25692 View details | France | Hospitality / Food & Beverage / Tourism | — | |
|
[AI generated] The Empreinte Hotel is a luxury establishment located in Orleans, France. This 4-star hotel is situated alongside the Loire River, providing guests with charming views. The hotel comprises of rooms and suites with elegant décor and amenities. Besides comfortable accommodation, the property also features a lounge bar and a wellness area, ensuring a truly restful and enjoyable stay for its guests. |
|||||
| Ransomware | *a*ame*i*a.com.g* id25691 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ccbrt.org id25566 View details | Tanzania, United Republic of | Healthcare / Pharma | — | |
|
[AI generated] Comprehensive Community Based Rehabilitation in Tanzania (CCBRT) is a healthcare organization that operates primarily in Tanzania. The organization aims to provide affordable, high-quality healthcare services to the local community, particularly those with disabilities. It focuses on areas like disability hospital services, rehabilitation, eye health, maternal and newborn healthcare. CCBRT is also known for its training and capacity building activities. |
|||||
| Ransomware | em***int*-ho***.com id25565 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cc***.or.*z id25439 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | taminsho.com id24984 View details | Iran, Islamic Republic of | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | platinumone.in id24479 View details | India | Services | — | |
|
[AI generated] PlatinumOne.in is a company based in India that provides outsourced sales force services for various industries such as telecom services, financial services, and consumer goods. They have an integrated sales force solution that covers prospect and database management, sales process outsourcing, and performance management. They are committed to delivering quality sales results for their clients. |
|||||
| Ransomware | SUNNYGO.COM.TW id24411 View details | Taiwan, Province of China | Communication / Marketing | — | |
|
[AI generated] "SUNNYGO.COM.TW" is an online retailer based in Taiwan. The company specializes in the sales and distribution of a broad range of products across various categories. These include electronics, beauty products, home goods, fashion items, and more. It's well-renowned for providing quality products at competitive prices. Through its platform, it offers a comprehensive shopping experience to its customers, involving easy payment methods and quick delivery services. |
|||||
| Ransomware | suzuki-ploiesti.ro id24254 View details | Romania | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | poliserv.ro id24253 View details | Romania | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | mazda-ploiesti.ro id24252 View details | Romania | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | dacia-ploiesti.ro id24251 View details | Romania | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | sevci.org id24250 View details | Côte d'Ivoire | Other | — | |
|
Santé, Espoir et Vie, dans un système de soin fort |
|||||