Ransomware Group intelligence
Coinbasecartel
ActiveTrack Coinbasecartel with 228 published victims and 1 known leak locations in a single intelligence view.
Overview
Coinbasecartel is tracked by Breach House as a ransomware group with 228 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion |
Top Activity Sectors (17)
- IT 33
- Services 22
- Communication / Marketing 22
- Manufacturing / Engineering 21
- Not identified 20
- Finance / Legal / Insurance 16
- Construction / Real Estate 12
- Healthcare / Pharma 11
- Telecommunications 8
- Transportation / Travel / Logistics 8
- Energy 7
- Retail / E-commerce 7
- Public Sector 4
- Education 2
- NGOs / Associations 1
- Agriculture / Food 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Coinbasecartel, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: coinbasecartel uses PowerShell scripts to execute malicious commands and stage ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: coinbasecartel modifies registry run keys to ensure ransomware execution persists across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: coinbasecartel disables security tools like EDR and AV by terminating processes or modifying system configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: coinbasecartel encodes victim data with symmetric encryption keys before exfiltration to protect stolen information.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: coinbasecartel deletes Volume Shadow Copies and backup directories via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: coinbasecartel uses remote system discovery to map network topology and identify additional targets for infection.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: coinbasecartel performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: coinbasecartel archives victim data using utility tools prior to encryption to facilitate exfiltration and extortion.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: coinbasecartel encrypts victim files using custom ransomware binaries to maximize impact and force ransom payments.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: coinbasecartel performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (228)
Search, filter and paginate the victim timeline for Coinbasecartel. Showing 201–228 of 228.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | SK-Telecom id23463 View details | Korea, Republic of | Telecommunications | ||
|
South Koreas largest wireless carrier offering mobile services broadband IPTV and cutting-edge AI and IoT solutions |
|||||
| Ransomware | Limocar by Transdev.ca id23355 View details | Canada | Transportation / Travel / Logistics | ||
|
Limocar, operated by Transdev Canada, is an intercity bus service offering reliable and efficient transportation between Sherbrooke, Bromont, and M... |
|||||
| Ransomware | Desjardin Bank / Group id23178 View details | Canada | Finance / Legal / Insurance | ||
|
Desjardins.com is the online presence of Desjardins Group, a major Canadian financial cooperative based in Quebec that serves personal and business clients. The organization offers banking, wealth management, and insurance services, including life and health insurance, property and casualty insurance, savings, and investment products. Its public site supports customer access to statements, account management, insurance information, and related financial services, reflecting a broad finance, legal, and insurance footprint in Canada. The entity aligns with the country code CA and operates as part of one of Canada’s largest cooperative financial institutions. It was listed as a ransomware victim associated with coinbasecartel. |
|||||
| Ransomware | [#1648] Redacted id23360 View details | Canada | Other | ||
|
They did not want to pay |
|||||
| Ransomware | ChampionX id23120 View details | United States | Services | ||
|
Headquartered in The Woodlands, Texas, ChampionX is a global leader in chemistry solutions and highly engineered equipment and technologies that he... |
|||||
| Ransomware | Schedler-translog id23023 View details | Austria | Healthcare / Pharma | ||
|
Since the company was founded in 1984, the company has been characterized by its family structure, under which the crucial goals of healthy growth ... |
|||||
| Ransomware | PLC-Transportation id23001 View details | Bulgaria | Transportation / Travel / Logistics | ||
|
PLC Trans is an established company in the field of international transport and logistics. In the last 10 years we have established ourselves as th... |
|||||
| Ransomware | dsv.com id23000 View details | Denmark | Transportation / Travel / Logistics | ||
|
DSV is a global transport and logistics company that provides and manages supply chain solutions for thousands of companies every day. The company ... |
|||||
| Ransomware | Kuehne + Nagel id22999 View details | Switzerland | Transportation / Travel / Logistics | ||
|
With more than 82,000 employees at almost 1,300 sites in close to 100 countries, the Kuehne+Nagel Group is one of the world's leading logistics pro... |
|||||
| Ransomware | Borrowell.com id22997 View details | Canada | Finance / Legal / Insurance | ||
|
Founded in 2014, Borrowell is a financial consulting firm that offers free credit score and report monitoring, automated credit coaching tools, and... |
|||||
| Ransomware | Legal Boutique id22996 View details | Finance / Legal / Insurance | |||
|
This is a private legal services firm representing high‑net‑worth individuals which would not want their business leaked online. Contact us or ... |
|||||
| Ransomware | Canias ERP id22995 View details | Germany | Communication / Marketing | ||
|
Canias ERP is a brand of IAS, an Industrial application software and ERP solution provider. Canias ERP is a software product that provides Enterpri... |
|||||
| Ransomware | Carewell id22994 View details | Communication / Marketing | |||
|
No description available. |
|||||
| Ransomware | C Well id22685 View details | Other | |||
|
You will be posted if you do not reply |
|||||
| Ransomware | The L B id22682 View details | Other | |||
|
You will be posted if you do not reply, do not play with us |
|||||
| Ransomware | BAM id22619 View details | Other | |||
|
You are fully aware of what we have, yet you’ve chosen not to uphold your end of the agreement. This is unacceptable. If you do not get in touch ... |
|||||
| Ransomware | BW-RF id22618 View details | Germany | Other | ||
|
We suggest you contact us asap |
|||||
| Ransomware | SK Telecom id22412 View details | Korea, Republic of | Telecommunications | ||
|
South Koreas largest wireless carrier offering mobile services broadband IPTV and cutting-edge AI and IoT solutions |
|||||
| Ransomware | Desjardins Banking/Group id22411 View details | Canada | Finance / Legal / Insurance | ||
|
Desjardins.com is the digital platform of Desjardins Group, the largest financial institution in Québec and the largest co-operative financial group in Canada. It provides personal financial services including insurance, loans, credit cards, online banking, apps, mortgages, and investing tools. The organization serves communities across Canada with a focus on cooperative finance and local economic development. Desjardins.com was listed as a ransomware victim associated with the threat actor coinbasecartel. |
|||||
| Ransomware | [Removed] #1534 id22495 View details | Canada | Other | — | |
|
Removed by request of the company which denied any breach throught ticket #1534 |
|||||
| Ransomware | AdScale id22410 View details | Germany | Retail / E-commerce | ||
|
AdScale is an AI-driven advertising platform tailored for e‑commerce and digital marketers, offering unified campaign management across Google Se... |
|||||
| Ransomware | Dreyfuss Williams & Associates Co , LPA id22409 View details | United States | Finance / Legal / Insurance | ||
|
Dreyfuss Williams Attorneys & Counselors at Law is a law firm specializing in Health Care Law, offering legal representation to hospitals and medic... |
|||||
| Ransomware | Focus R Technologies Pvt id22408 View details | India | IT | ||
|
Focus R Technologies is a leading technology consulting firm that specializes in delivering tailored software solutions and IT services to help bus... |
|||||
| Ransomware | NTT Data/Vectorform id22407 View details | United States | Services | ||
|
NTT Data is a global IT services provider based in Japan, delivering innovative solutions across a variety of industries including finance, healthc... |
|||||
| Ransomware | Plug Power id22406 View details | United States | Energy | ||
|
Plug Power is a premier provider of innovative hydrogen fuel cell solutions, specializing in clean energy technologies that enable the transition t... |
|||||
| Ransomware | Volt id22405 View details | United States | Services | ||
|
Volt is a global talent solutions provider, specializing in workforce management, recruitment, and staffing across industries such as technology, e... |
|||||
| Ransomware | Wakefield & Associates id22404 View details | United States | Services | ||
|
Wakefield & Associates is a financial services company specializing in debt collection and billing services. Wakefield & Associates helps clients i... |
|||||
| Ransomware | Ceva Logistics id22403 View details | United Kingdom | Transportation / Travel / Logistics | ||
|
CEVA Logistics is a global asset-light supply chain management company. It designs and implements freight forwarding, contract logistics, transport... |
|||||