Ransomware Group intelligence
Blackbyte
InactiveTrack Blackbyte with 147 published victims and 9 known leak locations in a single intelligence view.
Overview
Blackbyte is tracked by Breach House as a ransomware group with 147 published victims.
United States is currently the most targeted country in this dataset.
9 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (9)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 3h ago | dlyo7r3n4qy5fzv4645nddjwarj7wjdd6wzckomcyc7akskkxp4glcad.onion |
| Leak location 8 | Onion service | Down checked 3h ago | tj3ty2q5jm5au3bmd2embtjscd3qjt7nfio2o7cr6moyy5kgil5pieqd.onion |
| Leak location 5 | Onion service | Down checked 3h ago | ce6roic2ykdjunyzazsxmjpz5wsar4pflpoqzntyww5c2eskcp7dq4yd.onion |
| Leak location 7 | Onion service | Down checked 3h ago | 53d5skw4ypzku4bfq2tk2mr3xh5yqrzss25sooiubmjz67lb3gdivcad.onion |
| Leak location 9 | Onion service | Down checked 3h ago | dounczge5jhw4iztnnpzp54kd4ot3tikhjsimurtcewqssgye6vvrhqd.onion |
| Leak location 6 | Onion service | Down checked 3h ago | jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion |
| Leak location 4 | Onion service | Down checked 3h ago | fl3xpz5bmgzxy4fmebhgsbycgnz24uosp3u4g33oiln627qq3gyw37ad.onion |
| Leak location 2 | Onion service | Down checked 3h ago | f5uzduboq4fa2xkjloprmctk7ve3dm46ff7aniis66cbekakvksxgeqd.onion |
| Leak location 1 | Onion service | Down checked 3h ago | 6iaj3efye3q62xjgfxyegrufhewxew7yt4scxjd45tlfafyja6q4ctqd.onion |
Top Activity Sectors (16)
- Not identified 43
- Communication / Marketing 28
- Services 15
- Manufacturing / Engineering 10
- Public Sector 9
- Finance / Legal / Insurance 6
- Healthcare / Pharma 5
- Construction / Real Estate 5
- IT 5
- Energy 4
- Transportation / Travel / Logistics 4
- Telecommunications 3
- Education 3
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- NGOs / Associations 2
Typical Attacks (48)
▼How Blackbyte typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via BlackByte.
-
T1583.003 Virtual Private Server Resource Development
What they do: BlackByte staged encryption keys on virtual private servers operated by the adversary.
What that means: Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting.
-
T1608.001 Upload Malware Resource Development
What they do: BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.
What that means: Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting.
-
What they do: BlackByte has gained access to victim environments through legitimate VPN credentials.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: BlackByte captured credentials for or impersonated domain administration users.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1047 Windows Management Instrumentation Execution
What they do: BlackByte used WMI to delete Volume Shadow Copies on victim machines.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: BlackByte created scheduled tasks for payload execution.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.001 PowerShell Execution
What they do: BlackByte used encoded PowerShell commands during operations.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: BlackByte executed ransomware using the Windows command shell.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1569.002 Service Execution Execution
What they do: BlackByte created malicious services for ransomware execution.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: BlackByte performed Registry modifications to escalate privileges and disable security tools.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1136.002 Domain Account Persistence
What they do: BlackByte created privileged domain accounts during intrusions.
What that means: Adversaries may create a domain account to maintain access to victim systems.
-
T1505.003 Web Shell Persistence
What they do: BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: BlackByte modified multiple services on victim machines to enable encryption operations.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
What they do: BlackByte has used Registry Run keys for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions.
What that means: Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: BlackByte used process hollowing for defense evasion purposes.
What that means: Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
-
T1068 Exploitation for Privilege Escalation Privilege Escalation
What they do: BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.
What that means: Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
-
What they do: BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.
What that means: Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls.
-
T1036.008 Masquerade File Type Stealth
What they do: BlackByte masqueraded configuration files containing encryption keys as PNG files.
What that means: Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.
-
T1070.004 File Deletion Stealth
What they do: BlackByte deleted ransomware executables post-encryption.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1480 Execution Guardrails Stealth
What they do: BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1686 Disable or Modify System Firewall Defense Impairment
What they do: BlackByte modified firewall rules on victim machines to enable remote system discovery.
What that means: Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action.
-
T1003 OS Credential Dumping Credential Access
What they do: BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.
What that means: Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.
-
T1012 Query Registry Discovery
What they do: BlackByte queried registry values to determine system language settings.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1016 System Network Configuration Discovery Discovery
What they do: BlackByte used tools such as Arp to pull system network information and identify connected devices.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: BlackByte used tools such as Arp to identify remotely-connected devices.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1046 Network Service Discovery Discovery
What they do: BlackByte has used tools such as NetScan to enumerate network services in victim environments.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1082 System Information Discovery Discovery
What they do: BlackByte used various system commands and tools to pull system information during operations.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1087.002 Domain Account Discovery
What they do: BlackByte has used tools such as AdFind to identify and enumerate domain accounts.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1135 Network Share Discovery Discovery
What they do: BlackByte enumerated network shares on victim devices.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1482 Domain Trust Discovery Discovery
What they do: BlackByte enumerated Active Directory information and trust relationships during operations.
What that means: Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
-
T1518.001 Security Software Discovery Discovery
What they do: BlackByte enumerated installed security products during operations.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1614.001 System Language Discovery Discovery
What they do: BlackByte identified system language settings to determine follow-on execution.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: BlackByte has used RDP to access other hosts within victim networks.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1560 Archive Collected Data Collection
What they do: BlackByte compressed data collected from victim environments prior to exfiltration.
What that means: An adversary may compress and/or encrypt data that is collected prior to exfiltration.
-
T1071.001 Web Protocols Command and Control
What they do: BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: BlackByte has used tools such as AnyDesk in victim environments.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1567 Exfiltration Over Web Service Exfiltration
What they do: BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.
What that means: Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: BlackByte has encrypted victim files for ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: BlackByte left ransom notes in all directories where encryption takes place.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (9)
▼Software Blackbyte has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery & enumeration
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
BB_Readme_[rand].txt
██████╗ ██╗ █████╗ ██████╗██╗ ██╗██████╗ ██╗ ██╗████████╗███████╗ ███╗ ██╗████████╗ ██╔══██╗██║ ██╔══██╗██╔════╝██║ ██╔╝██╔══██╗╚██╗ ██╔╝╚══██╔══╝██╔════╝ ████╗ ██║╚══██╔══╝ ██████╔╝██║ ███████║██║ █████╔╝ ██████╔╝ ╚████╔╝ ██║ █████╗ ██╔██╗ ██║ ██║ ██╔══██╗██║ ██╔══██║██║ ██╔═██╗ ██╔══██╗ ╚██╔╝ ██║ ██╔══╝ ██║╚██╗██║ ██║ ██████╔╝███████╗██║ ██║╚██████╗██║ ██╗██████╔╝ ██║ ██║ ███████╗ ██║ ╚████║ ██║ ╚═════╝ ╚══════╝╚═╝ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═╝ ╚═══╝ ╚═╝ +-----------------------------------------------------------------------------+ | All your files have been encrypted, your confidential data has been stolen, | | in order to decrypt files and avoid leakage, you must follow our steps. | +-----------------------------------------------------------------------------+ +------------------------------------------------------------------------------------------------------------------------------------+ | 1) Download and install TOR Browser from this site: https://torproject.org/ | | | | 2) Paste the URL in TOR Browser and you will be redirected to our chat with all information that you need. | | | | 3) If you read this message thats means your files already for sell in our Auction. | | Everyday of delaying will cause higer price. after 4 days if you wont connect us, | | We will remove your chat access and you will lose your chance to get decrypted. | | | +------------------------------------------------------------------------------------------------------------------------------------+ +---------------------------------------------------------------------------------------------------+ | Warning! Communication with us occurs only through this link, or through our mail on our Auction. | | We also strongly DO NOT recommend using third-party tools to decrypt files, | | as this will simply kill them completely without the possibility of recovery. | | I repeat, in this case, no one can help you! | +---------------------------------------------------------------------------------------------------+ Your URL: http://a2dbso6dijaqsmut36r6y4nps4cwivmfog5bpzf6uojovce6f3gl36id.onion:81/[snip] Your Key to access the chat: [snip] Find our Auction here (TOR Browser): http://jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion/
BB_Readme.txt
██████╗ ██╗ █████╗ ██████╗██╗ ██╗██████╗ ██╗ ██╗████████╗███████╗ ██████╗ ██████╗ ██╔══██╗██║ ██╔══██╗██╔════╝██║ ██╔╝██╔══██╗╚██╗ ██╔╝╚══██╔══╝██╔════╝ ╚════██╗ ██╔═████╗ ██████╔╝██║ ███████║██║ █████╔╝ ██████╔╝ ╚████╔╝ ██║ █████╗ █████╔╝ ██║██╔██║ ██╔══██╗██║ ██╔══██║██║ ██╔═██╗ ██╔══██╗ ╚██╔╝ ██║ ██╔══╝ ██╔═══╝ ████╔╝██║ ██████╔╝███████╗██║ ██║╚██████╗██║ ██╗██████╔╝ ██║ ██║ ███████╗ ███████╗██╗╚██████╔╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚══════╝╚═╝ ╚═════╝ +-----------------------------------------------------------------------------+ | All your files have been encrypted, your confidential data has been stolen, | | in order to decrypt files and avoid leakage, you must follow our steps. | +-----------------------------------------------------------------------------+ +------------------------------------------------------------------------------------------------------------------------------------+ | 1) Download and install TOR Browser from this site: https://torproject.org/ | | | | 2) Paste the URL in TOR Browser and you will be redirected to our chat with all information that you need. | | | | 3) If you read this message thats means your files already for sell in our Auction. | | Everyday of delaying will cause higer price. after 4 days if you wont connect us, | | We will remove your chat access and you will lose your chance to get decrypted. | | | +------------------------------------------------------------------------------------------------------------------------------------+ +---------------------------------------------------------------------------------------------------+ | Warning! Communication with us occurs only through this link, or through our mail on our Auction. | | We also strongly DO NOT recommend using third-party tools to decrypt files, | | as this will simply kill them completely without the possibility of recovery. | | I repeat, in this case, no one can help you! | +---------------------------------------------------------------------------------------------------+ Your URL: http://inbukcc4xk67uzbgkzufdqq3q3ikhwtebqxza5zlfbtzwm2g6usxidqd.onion:81/[snip] Your Key to access the chat: [snip] Find our Auction here (TOR Browser): http://jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion/
blackbyte_v2.txt
██████╗ ██╗ █████╗ ██████╗██╗ ██╗██████╗ ██╗ ██╗████████╗███████╗ ██╔══██╗██║ ██╔══██╗██╔════╝██║ ██╔╝██╔══██╗╚██╗ ██╔╝╚══██╔══╝██╔════╝ ██████╔╝██║ ███████║██║ █████╔╝ ██████╔╝ ╚████╔╝ ██║ █████╗ ██╔══██╗██║ ██╔══██║██║ ██╔═██╗ ██╔══██╗ ╚██╔╝ ██║ ██╔══╝ ██████╔╝███████╗██║ ██║╚██████╗██║ ██╗██████╔╝ ██║ ██║ ███████╗ ╚═════╝ ╚══════╝╚═╝ ╚═╝ ╚═════╝╚═╝ ╚═╝╚═════╝ ╚═╝ ╚═╝ ╚══════╝ +-----------------------------------------------------------------------------+ | All your files have been encrypted, your confidential data has been stolen, | | in order to decrypt files and avoid leakage, you must follow our steps. | +-----------------------------------------------------------------------------+ +------------------------------------------------------------------------------------------------------------------------------------+ | 1) Download and install TOR Browser from this site: https://torproject.org/ | | | | 2) Paste the URL in TOR Browser and you will be redirected to our chat with all information that you need. | | | | 3) If you do not contact us within 4 days, your chat access key won't be valid. | | Also, your company will be posted on our blog, darknet and hacker forums, | | which will attract unnecessary attention from journalists and not only them. | | You are given 4 days to think over the situation, and take reasonable actions on your part. | +------------------------------------------------------------------------------------------------------------------------------------+ +------------------------------------------------------------------------------------------------+ | Warning! Communication with us occurs only through this link, or through our mail on our blog. | | We also strongly DO NOT recommend using third-party tools to decrypt files, | | as this will simply kill them completely without the possibility of recovery. | | I repeat, in this case, no one can help you! | +------------------------------------------------------------------------------------------------+ Your URL: http://p5quu5ujzzswxv4nxyuhgg3fjj2vy2a3zmtcowalkip2temdfadanlyd.onion/[snip] Your Key to access the chat: [snip] Find our blog here (TOR Browser): http://dlyo7r3n4qy5fzv4645nddjwarj7wjdd6wzckomcyc7akskkxp4glcad.onion/
BB_Readme2.txt
??????? ??? ?????? ?????????? ?????????? ??? ???????????????????? ???? ???????????? ??????????? ??????????????????? ???????????????? ????????????????????? ????? ???????????? ??????????? ??????????? ??????? ???????? ??????? ??? ?????? ?????? ??? ??? ??????????? ??????????? ??????? ???????? ????? ??? ?????? ?????????? ??? ??????????????????? ?????????????? ??????????? ??? ??? ???????? ??? ?????? ??? ??????? ??????????? ??? ?????????? ?????????? ??? ??? ???????? ??? ????? ??? +-----------------------------------------------------------------------------+ | All your files have been encrypted, in order to decrypt files, | | you must follow our steps. | +-----------------------------------------------------------------------------+ +------------------------------------------------------------------------------------------------------------------------------------+ | 1) Download and install TOR Browser from this site: https://torproject.org/ | | | | 2) Paste the URL in TOR Browser and you will be redirected to our chat with all information that you need. | | | | 3) Everyday of delaying will cause higer price. After 4 days if you wont connect us, | | We will remove your chat access and you will lose your chance to get decrypted. | | | +------------------------------------------------------------------------------------------------------------------------------------+ +---------------------------------------------------------------------------------------------------+ | We also strongly DO NOT recommend using third-party tools to decrypt files, | | as this will simply kill them completely without the possibility of recovery. | | I repeat, in this case, no one can help you! | +---------------------------------------------------------------------------------------------------+ Your URL: http://vzzf6yg67cffqndnwg56e4psw45rup45f2mis7bwblg5fs7e5voagsqd.onion:81/[snip] Your Key to access the chat: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (147)
Search, filter and paginate the victim timeline for Blackbyte. Showing 101–147 of 147.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | INVIMA id2796 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | San Francisco 49ers id2615 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aeronamic id2598 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Venture Machine & Tool, Inc. id2597 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Prince Jewellery & Watch Co., Ltd. id2586 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bud Griffin and Associates id2569 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Petrolimex id2568 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rector Hayden Realtors id2567 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Taylor and Martin id2566 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Argonaut Gold id2565 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kangean Energy Indonesia id2244 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dental Health Products id2243 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | P&R ENTERPRISES id2135 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unique Home Solutions id2134 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Quanticate id2133 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bemis Associates id2074 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Karges-Faulconbridge, Inc. id2045 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MOTOR VEHICLE ACCIDENT FUND PENSION FUND id2044 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Koltepatil id2043 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Goodwill of Central and Coastal Virginia, Inc. id1977 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | INOXPA id1976 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Canada West Land id1923 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Emery Jensen Distribution id1922 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Purifoy Chevrolet Co. id1921 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Williams & Rowe Company, Inc. id1920 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Visage Imaging id1915 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ASPECT STUDIOS ASIA PTY LTD id1914 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Glass House id1913 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Regence Footwear id1771 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Napili Kai Foundation Gallery id1753 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | H Hotels Collection id1736 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MINT Investments id1709 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DiGioia Gray & Associates, LLC id1686 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GENERALE PREFABBRICATI SPA id1653 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Medical Designs id1614 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Statcomm id1613 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Distribuidora de Industrias Nacionales id1608 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tom Lange Company, Inc. id1554 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Farmers Cooperative Elevator id1553 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aluflexpack id1524 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Clay County Clerk id1523 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AZA chili id1522 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BOSCA S.p.A id1521 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Plastic Forming Company id1520 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GEO-Alpinbau id1519 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Goss Dodge Chrysler Ram Jeep id1518 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Matic Transport id1517 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||