Ransomware Group intelligence
Brotherhood
InactiveTrack Brotherhood with 19 published victims and 1 known leak locations in a single intelligence view.
Overview
Brotherhood is tracked by Breach House as a ransomware group with 19 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 56m ago | brohoodyaifh2ptccph5zfljyajjabwjjo4lg6gfp4xb6ynw5w7ml6id.onion |
Top Activity Sectors (5)
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Brotherhood, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Brotherhood executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: Brotherhood leverages Registry Run Keys to ensure malware execution upon system reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Brotherhood disables antivirus tools by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Brotherhood encodes malicious binaries to evade signature-based detection during deployment.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Brotherhood deletes Volume Shadow Copies and backup files via vssadmin to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: Brotherhood discovers remote systems via port scanning to map the internal network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: Brotherhood scans network shares using SMB tools to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: Brotherhood encrypts victim files using strong symmetric encryption to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: Brotherhood displays victim-specific defacement messages alongside encrypted files to pressure payment.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (19)
Search, filter and paginate the victim timeline for Brotherhood. Showing 1–19 of 19.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Italgrafica Sistemi id25332 View details | Italy | Communication / Marketing | — | |
|
Contains: 6 Gb Compressed Free Files, 470 Gb Compressed Paid Files, E-mails |
|||||
| Ransomware | häussermann stauden gehölze gmbh id24685 View details | Germany | Communication / Marketing | — | |
|
Contains: 1 Gb Compressed Free Files, 26 Gb Compressed Paid Files |
|||||
| Ransomware | Ingenieurbüro Laudi id24285 View details | Germany | Communication / Marketing | — | |
|
Contains: 4 Gb Compressed Free Files, 139 Gb Compressed Paid Files |
|||||
| Ransomware | Announcement till 20/11 id23932 View details | Germany | Other | — | |
|
Announcement till 20/11 appears to be an entity in Germany classified in the broad Other sector, which suggests it does not fit a standard industry category such as healthcare, finance, or manufacturing. In threat-intelligence catalogs, such entries typically identify an organization or notice associated with ransomware activity without adding operational detail beyond the listing context. The record is indexed for Germany and uses the name as provided, indicating the subject of the entry rather than a full corporate profile. It was listed as a ransomware victim associated with brotherhood. |
|||||
| Ransomware | Horst Realty id23922 View details | United States | Communication / Marketing | — | |
|
Contains: 27 Gb compressed Files, Emails |
|||||
| Ransomware | Spoleta Construction id23921 View details | United States | Construction / Real Estate | — | |
|
Contains: 4 Gb compressed Free Files + 33 Gb compressed Paid Files, Database |
|||||
| Ransomware | Cera Stribley id23920 View details | Australia | Communication / Marketing | — | |
|
Contains: 2 Gb compressed Free Files + 138 Gb compressed Paid Files |
|||||
| Ransomware | Kaener Personal id23919 View details | Switzerland | Communication / Marketing | — | |
|
Contains: 139 Gb compressed Paid Files |
|||||
| Ransomware | Ninas Jewellery id23918 View details | Australia | Transportation / Travel / Logistics | — | |
|
[AI generated] Nina's Jewellery is a family-owned jewelry business with over 30 years of experience in the industry. Based in Australia, it offers a wide selection of fine jewelry featuring diamonds, colored gemstones, gold and pearls. Known for its exquisite craftsmanship and quality, Nina's Jewellery caters to customers seeking luxurious and timeless pieces for all occasions. With a strong commitment to ethical sourcing, the company ensures the sustainability and traceability in their supply chain. |
|||||
| Ransomware | Integlia id22977 View details | Canada | Communication / Marketing | — | |
|
Contains: 66 Gb compressed Files |
|||||
| Ransomware | Citizens' Committee for Children of New York id22976 View details | United States | Communication / Marketing | — | |
|
Contains: 45 Gb compressed Files |
|||||
| Ransomware | Momentum Logistics id22941 View details | South Africa | Transportation / Travel / Logistics | ||
|
Contains: 124 Gb compressed Files, Databases |
|||||
| Ransomware | Sternthal Montigny Greenberg St-Germain id22940 View details | Canada | Communication / Marketing | ||
|
Contains: 22 Gb compressed Files |
|||||
| Ransomware | Kevmor id22939 View details | Australia | Communication / Marketing | ||
|
Contains: 45 Gb compressed Files, Databases, E-mails |
|||||
| Ransomware | Woodmen Valley Chapel id22938 View details | United States | Communication / Marketing | ||
|
Contains: 274 Gb compressed Files |
|||||
| Ransomware | UVJ Technologies id22937 View details | United States | IT | ||
|
Contains: NO DATA |
|||||
| Ransomware | Motility Software id22936 View details | United States | IT | ||
|
Contains: 3.3 Gb compressed Files, Databases |
|||||
| Ransomware | Orion Communications and Public Relations id22935 View details | United States | Communication / Marketing | ||
|
Contains: 13 Gb compressed Files, Databases |
|||||
| Ransomware | Coal Industry Social Welfare Organisation id22934 View details | United Kingdom | Other | ||
|
Contains: NO DATA |
|||||