Ransomware Group intelligence
Datacarry
InactiveTrack Datacarry with 16 published victims and 1 known leak locations in a single intelligence view.
Overview
Datacarry is tracked by Breach House as a ransomware group with 16 published victims.
Belgium is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | dcarryhaih5oldidg3tbqwnde4lxljytnpvberrwgj2vlvunopd46dad.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Datacarry, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: datacarry executes PowerShell scripts to stage ransomware payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: datacarry modifies Registry Run Keys to ensure ransomware execution upon user logon or system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: datacarry disables antivirus tools and security monitoring utilities to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: datacarry encodes victim files with custom symmetric encryption routines before demanding ransom payments.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: datacarry deletes Volume Shadow Copies and backup directories via command-line utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: datacarry brute-forces local accounts using password lists to gain initial access to victim systems.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1135 Network Share Discovery Discovery
What they do: datacarry scans network shares using native tools to identify victim file servers and data repositories.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: datacarry leverages SMB/Windows Admin Shares for lateral movement across networked servers in targeted IT environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: datacarry encrypts victim files with custom ransomware binaries, targeting communication and marketing data heavily.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: datacarry calls system recovery inhibitors like shutdown scripts to disrupt backup restoration attempts.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
R3ADM3.txt
Your network has been attacked. All files have been encrypted with a strong encryption algorithm. Shadow copies also removed, so F8 or any other methods may damage encrypted data but not recover. We exclusively have decryption software for your situation. No decryption software is available in the public. If you wish to try decryption on your own, do it on a file that does not matter. DO NOT RESET OR SHUTDOWN, files may be damaged. DO NOT RENAME OR MOVE the encrypted and readme files. DO NOT DELETE readme files. This may lead to the impossibility of recovery of the certain files. We can provide free decryption samples. To get info (decrypt your files) contact us at: [email protected] NOTE: We have also successfully backed up data such as customer information from your databases. We can provide listing. Ensuring if you DO NOT comply your data will be leaked. (http://dcarryhaih5oldidg3tbqwnde4lxljytnpvberrwgj2vlvunopd46dad.onion/) Current price: 1 BTC, can be negotiated Failure to meet the payment will result in your data being leaked to the public. Failure to contact will result in a dataleak. If contacting via email and you receive no response please refer to our session ID: 050d1feda2751e807b2a731f1f5fe764910ba9ea8bc46e2643d3180876a5bc953c (getsession.org)
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (16)
Search, filter and paginate the victim timeline for Datacarry. Showing 1–16 of 16.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Camomilla id24468 View details | Italy | Communication / Marketing | — | |
|
[AI generated] Camomilla is an Italian brand renowned for its elegant accessories and refined clothing. Founded in 1983 by Monica Bianco, the company encapsulates Italian craftsmanship and design aesthetics in their fashion line, which includes bags, clothes, shoes, and jewelry for women. It offers a wide spectrum of on-trend, creative, and stylish accessories for every occasion. |
|||||
| Ransomware | UAM id24085 View details | Spain | Services | — | |
|
[AI generated] UAM, officially known as Universal Asset Management, is a global leader in the aviation services industry. They specialize in whole asset management, from leasing, trading to dismantling end-of-life commercial aircraft. Established in 1992 and headquartered in Tennessee, USA, UAM utilizes advanced technology to serve a wide range of clients around the world. They are dedicated to environmental sustainability through recycling aircraft materials. |
|||||
| Ransomware | Miljödata (1 day left) id22316 View details | Sweden | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Miljödata id22315 View details | Sweden | Communication / Marketing | — | |
|
[AI generated] Miljödata, based in Sweden, specializes in developing systems to monitor environment quality. Their products are used in studying environmental changes within aspects like groundwater, surface water, air, and precipitation. They develop measuring methods and systems for tracking mercury in the environment and offer turn-key solutions for environmental monitoring stations. |
|||||
| Ransomware | Peggy Sage id21747 View details | France | Communication / Marketing | — | |
|
[AI generated] Peggy Sage is a French beauty brand with a history spanning over 90 years. It specializes in cosmetic and nail care products. Their diverse range includes nail polish, nail treatments, and beauty products such as perfumes, make-up, skincare products, and beauty accessories. Over the years, Peggy Sage has become a go-to professional beauty brand for both individual users and salon professionals around the world. |
|||||
| Ransomware | Món Sant Benet id20635 View details | Spain | Energy | — | |
|
[AI generated] Món Sant Benet is a unique cultural, tourist, and leisure project in Catalonia, Spain. It encompasses a medieval monastery that dates back to the 10th century, the modernist summer home of the famous painter Ramón Casas, the Alícia Foundation (which focuses on gastronomic research), and a luxury 4-star hotel. The company offers fascinating tours, events, gastronomy experiences, and education workshops. |
|||||
| Ransomware | V² Development id20447 View details | Greece | Construction / Real Estate | — | |
|
[AI generated] "V² Development" is a comprehensive real estate development company that specializes in various aspects of real estate sectors, including residential, commercial, and industrial development. The company prides itself on creating sustainable and innovative solutions to meet the evolving needs of their clients. V² Development focuses on successful property development projects through insightful investment strategies, implying extensive market research and reliable partnership formations. |
|||||
| Ransomware | Alliance Healthcare IT id20309 View details | Italy | Healthcare / Pharma | — | |
|
[AI generated] Alliance Healthcare IT is a company dedicated to providing advanced healthcare information technology solutions. They specialize in enhancing operational efficiency and reducing costs for healthcare providers by offering services like system implementation, software development, data management, and IT infrastructure service. Their mission is to improve patient care and healthcare outcomes through advanced IT. |
|||||
| Ransomware | La Maison Liégeoise id20246 View details | Belgium | Communication / Marketing | — | |
|
[AI generated] "La Maison Liégeoise" is a Belgian company that sells Carlina tapioca, an original product from Belgium. The company stands out for its regional, quality product, which it sources, packages and markets meticulously. They specialize in Carlina tapioca, a product known for its fine and soft grains. |
|||||
| Ransomware | Executive Jet Support id20245 View details | United Kingdom | Services | — | |
|
[AI generated] Executive Jet Support is a UK-based company that specializes in providing comprehensive support services for the global aviation industry. They offer a wide range of services, including supply of aircraft parts, engine sales and leasing, component repair and overhaul, and aircraft disassembly. The company caters to both commercial and military sectors, ensuring maintenance, repair and operational support for fleets worldwide. |
|||||
| Ransomware | alles Lægehus id20244 View details | Denmark | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Mammut Sports Group id20243 View details | Switzerland | Communication / Marketing | — | |
|
[AI generated] Mammut Sports Group is a Swiss multinational company that specializes in producing and retailing mountaineering and trekking equipment. Known for their high-quality outdoor gear, their product range includes clothing, backpacks, footwear, climbing gear, and sleeping equipment. Noted for their commitment to sustainability and fair working conditions, Mammut emphasizes innovation and technology in their product designs. |
|||||
| Ransomware | FrontierCo id20242 View details | South Africa | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Étude Bordet id20241 View details | Belgium | Communication / Marketing | — | |
|
[AI generated] "Étude Bordet" is a estate firm specializing in property auctions. They provide a variety of services, including property valuations, asset management, and legal guidance related to property transactions. They support both buyers and sellers in the process of acquiring or disposing assets through auctions. Known for their expertise, they offer a comprehensive approach towards property auctions. |
|||||
| Ransomware | ALB Forex id20240 View details | Türkiye | Communication / Marketing | — | |
|
[AI generated] ALB Forex is a financial services company based in Turkey. It specializes in forex trading, allowing individual and corporate investors to trade in the forex market. ALB Forex offers a range of service including online forex trading, professional forex training, and market analysis. The company aims to provide its clients with secure, fast, and advanced technology for forex trading. |
|||||
| Ransomware | Balcia Insurance id20239 View details | Latvia | Finance / Legal / Insurance | — | |
|
[AI generated] Balcia Insurance SE is a European insurer founded in 1993 and based in Latvia. It offers a wide range of non-life insurance products, including car, property, travel, accident and liability insurance. It operates in nine European countries. Besides its main field, Balcia Insurance also focuses on innovative digital solutions to simplify insurance processes. |
|||||