Ransomware Group intelligence
Flocker
InactiveTrack Flocker with 59 published victims and 1 known leak locations in a single intelligence view.
Overview
Flocker is tracked by Breach House as a ransomware group with 59 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | flock4cvoeqm4c62gyohvmncx6ck2e7ugvyqgyxqtrumklhd5ptwzpqd.onion |
Top Activity Sectors (11)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Flocker, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: flocker executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: flocker modifies registry run keys to ensure malware execution upon system reboot and persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: flocker disables security tools like EDR agents and antivirus software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: flocker encodes victim files with symmetric encryption keys to render data inaccessible without decryption.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: flocker deletes Volume Shadow Copies and backup directories via command-line tools to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: flocker performs remote system discovery to map network topology and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: flocker uses network share discovery to identify accessible SMB shares for lateral movement across victim infrastructure.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: flocker archives stolen data using utility commands before exfiltration to support extortion demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: flocker encrypts victim files using custom ransomware binaries, targeting critical data for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: flocker displays internal defacement messages and ransom notes on victim systems to pressure organizations into payment.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (59)
Search, filter and paginate the victim timeline for Flocker. Showing 1–59 of 59.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Ieee-apscon.org id21476 View details | United States | Public Sector | ||
|
To The IEEE Sensors Council We Have Breached APSCON2025 Event And Full Attendees Guest List And Registry System And Global […] |
|||||
| Ransomware | T***********p.com id21457 View details | Finance / Legal / Insurance | |||
|
For The Council Of T*****d Group We Have Breached You Main System T**********p.com a global, multi-manager investment platform exclusively focused […] |
|||||
| Ransomware | G*****n.com id21454 View details | Other | |||
|
For The Board Of G*****n Group We have breached your Main system and exfiltrated backup copy of all the data. |
|||||
| Ransomware | H**u.i*v.tw id21453 View details | Taiwan, Province of China | Education | ||
|
To The Leadership Of National C******i University We Compromised The Department Of Statistics conducted research on data matrix visualization and […] |
|||||
| Ransomware | G*********************y.org id21150 View details | Communication / Marketing | |||
|
For the leadership of G****l H********e A*****y We have compromised your main servers G*********************y.org and 3rd Party Entity’s leveraging your […] |
|||||
| Ransomware | Idgcayman.com id21018 View details | Cayman Islands | Other | ||
|
To The Board Of Interior Design Group As the Cayman Islands longest-standing interior design company, IDG has a long history |
|||||
| Ransomware | S******h.com id20971 View details | Finance / Legal / Insurance | |||
|
The Board Of S******h S**w LLP You Operate one of the world’s largest firms With approximately 900 lawyers across 18 […] |
|||||
| Ransomware | I*******n.com id20901 View details | Other | |||
|
To The Board Of I******r D****n G***p As the C****n Islands’ longest-standing interior design company, I*G has a long history […] |
|||||
| Ransomware | Ajmanre.gov.ae id20641 View details | United Arab Emirates | Construction / Real Estate | ||
|
To The Leadership Of Ajman Department of Land & Real Estate Department of Land & Real Estate Regulation in Ajman […] |
|||||
| Ransomware | A*****e.gov.ae id20465 View details | Other | |||
|
To The Leadership Of A*****e D********t of L**d & R**l E****e We have breached main servers, And We Also Exfiltrated […] |
|||||
| Ransomware | Lts.com.vn id20449 View details | Viet Nam | Finance / Legal / Insurance | ||
|
For The Council Of LTS Group We have breached your main system Lts.com.vn LTS LAW, a key component of LTS […] |
|||||
| Ransomware | Dcsdev.org id20382 View details | United States | Other | ||
|
For The Leadership Of Data-Core Systems Inc In 2016 Data-Core Systems Inc. founded Data-Core The Automation Company, with a focus |
|||||
| Ransomware | Trustgrp.ae id20368 View details | United Arab Emirates | NGOs / Associations | ||
|
To The Board Of Trust Group Firm Trust Group is a well-established, multi-faceted organization with over two decades of expertise |
|||||
| Ransomware | l*s.com.vn id20291 View details | Public Sector | |||
|
For The Council Of L*S GROUP We have breached your main system l*s.com.vn We also took backup copy of all […] |
|||||
| Ransomware | D****v.org id20216 View details | Communication / Marketing | |||
|
For The Leadership Of D**a-C**e S*****s Inc We have compromised your main server D****v.org we also took copy of all […] |
|||||
| Ransomware | T******p.ae id20208 View details | United Arab Emirates | Other | ||
|
To The Board Of T***t L*****s & L***l C*********s We have breached one of your servers and exfiltrated data, we […] |
|||||
| Ransomware | Z****a.com id19255 View details | Other | |||
|
To the Leadership Of S*****r We have gained access to your main system, Z*****a.com and took backup of all data. […] |
|||||
| Ransomware | W*******w.com id18751 View details | Services | |||
|
To the management of W***** LLP We have breached the main servers, and took down W*******w.com, we have also taken […] |
|||||
| Ransomware | Salemerode.com id18281 View details | Germany | Finance / Legal / Insurance | ||
|
To the management of Salem Erode Investment Limited We have breached your system servers Salemerode.com also extracted valuable files, customer […] |
|||||
| Ransomware | S********e.com id18131 View details | Services | |||
|
To the management of S***m E***e I********t Limited We have breached your system servers S********e.com also extracted valuable files, customer |
|||||
| Ransomware | K**d.edu id18130 View details | Other | |||
|
To the board of K*** ********y ******e We have owned your system at k**d.edu we also took backup of data […] |
|||||
| Ransomware | Eservices.gov.zm id17630 View details | Zambia | Services | ||
|
To the leadership of Zamservices We have compromised Eservices.gov.zm main servers, backup, internal network, we also exfiltrated all data before […] |
|||||
| Ransomware | Gpstech2007.com id17556 View details | Thailand | IT | ||
|
To the board of GPSTECH2007 We have compromised your system servers for Gpstech2007.com and locked out all user, we also |
|||||
| Ransomware | Mervis.info id17555 View details | Czechia | Communication / Marketing | ||
|
For the Administration of Mervis.info We have compromised Mervis.info system and extracted data to do with system control and operation |
|||||
| Ransomware | Realtime.tw id17554 View details | Taiwan, Province of China | Public Sector | ||
|
To The council Of Realtime Taiwan We have breached Realtime.tw server and extracted data on all employee, and other company |
|||||
| Ransomware | A*u.edu.au id17553 View details | Australia | Other | ||
|
To the board of A********n N******l U********y We have took over the servers A*u.edu.au and before encryption we extracted all […] |
|||||
| Ransomware | E*******s.gov.zm id17475 View details | Zambia | Telecommunications | ||
|
To the leadership of Z*********S We have compromised E*******s.gov.zm main servers, backup, internal network, we also exfiltrated all data before […] |
|||||
| Ransomware | R******e.tw id17274 View details | Taiwan, Province of China | Public Sector | ||
|
The council Of R******e we look forward to talk We have breached R******e.tw server and extracted data on all employee, […] |
|||||
| Ransomware | G*********7.com id17272 View details | Communication / Marketing | |||
|
To the board of G*********7 We have compromised your system servers for G*********7.com and locked out all user, we also |
|||||
| Ransomware | M****s.info id17271 View details | Communication / Marketing | |||
|
For the Administration of m****s.info We have compromised M****s.info system and extracted data to do with system control and operation […] |
|||||
| Ransomware | Toshapp.com id17227 View details | Tanzania, United Republic of | Transportation / Travel / Logistics | ||
|
To the leadership of TOSH LOGISTICS CO LIMITED We have breached the system entirely we also took all data with |
|||||
| Ransomware | A2b-cargo.com id17226 View details | United States | Transportation / Travel / Logistics | ||
|
To the management of A2B Cargo We have gained access to A2b-cargo.com and have obtained sensitive data including Driver, Employee […] |
|||||
| Ransomware | Punjab.gov.pk id17086 View details | Pakistan | NGOs / Associations | ||
|
To The Organization of Punjab.gov.pk We have owned the servers and extract ed all data of all officers and Employees working |
|||||
| Ransomware | W*****e.com id17085 View details | Other | |||
|
To the managment of w*****e.com We have breached the main system servers and extracted all client details, including all employee |
|||||
| Ransomware | T*****p.com id17084 View details | Other | |||
|
To the leadership of T**H L*******S CO LIMITED We have breached the system entirely we also took all data with |
|||||
| Ransomware | A**-****o.com id17083 View details | Services | |||
|
To the management of A** ****o We have gained access to A**-****o.com and have obtained sensitive data including Driver, Employee […] |
|||||
| Ransomware | K****S CORP id16237 View details | Services | |||
|
To the leadership of K****S.COM, We have gained access to K****S.COM and have obtained Server data including user information and […] |
|||||
| Ransomware | d****I id15155 View details | Communication / Marketing | |||
|
To the board of d****I.org, We have gained access to your system and have procured highly confidential data, including 2.1TB […] |
|||||
| Ransomware | C**********M id15062 View details | Services | |||
|
To the management of C**********M.com, We have breached C**********M.com and have obtained all data including user information and transaction histories. […] |
|||||
| Ransomware | F*******M Corp id14926 View details | Services | |||
|
To the executives of F*******M, We have successfully breached F*******M.com and obtained critical data from your servers. This includes 3.5TB |
|||||
| Ransomware | B****A id14925 View details | Services | |||
|
To the management of Coinmama, We have gained access to B****A.ca and have obtained sensitive data including user information and […] |
|||||
| Ransomware | Q***M id14817 View details | United States | Services | ||
|
We have infiltrated the Q***M.com servers, a well-known Money Management institution. In just 7 days, if payment not submitted in […] |
|||||
| Ransomware | K***N Corp id14710 View details | Korea, Republic of | Communication / Marketing | ||
|
To the board of K***N, We have gained access to your system at K***N.com and have procured highly confidential data, […] |
|||||
| Ransomware | Y*********I id13836 View details | United States | Education | ||
|
We have Access Y*********I.edu servers, a well-known University. In just 7 days, we will leak all data we have taken. […] |
|||||
| Ransomware | A****N id13725 View details | Other | |||
|
To the Firm of A****N, We have gained unauthorized access to A***N.com and have gained highly confidential data, including 145GB […] |
|||||
| Ransomware | A*****D id13449 View details | Other | |||
|
To the executives of A*****D, We have breached A*****D.com servers and your security measures and obtained critical data from your […] |
|||||
| Ransomware | O***M id13299 View details | Other | |||
|
To the board of O***M, We have gained access to your system O***M.com and have highly confidential data, including 450GB […] |
|||||
| Ransomware | F*****H id13241 View details | Communication / Marketing | |||
|
To the board of F*****H, We have gained unauthorized access to your system F*****H.com and have procured highly confidential data, |
|||||
| Ransomware | K*****S id13240 View details | Canada | Finance / Legal / Insurance | ||
|
To the leadership of K*****S.ca We have infiltrated the K*****S.ca servers, a well-known Law Firm institution. In just 7 days, […] |
|||||
| Ransomware | H*******Y id13180 View details | Other | |||
|
To The Leadership Of H*******Y We have Successfully breached H*******y.net servers your systems are Encrypted, We took backup copy of […] |
|||||
| Ransomware | D*****S id13104 View details | Other | |||
|
To The Board Of D*****S We have Successfully breached d*****s.com servers your systems are locked, We took backup copy of […] |
|||||
| Ransomware | SBC Global, Bitfinex, Coinmama, and Rutgers University Part 2 Leak id12347 View details | Education | |||
|
The four victims of our attack – SBC Global, Bitfinex, Coinmama, and Rutgers University. You refused to pay, and now […] |
|||||
| Ransomware | Coinmama id12290 View details | Services | |||
|
To the management of Coinmama, We have gained access to Coinmama.com and have obtained sensitive data including user information and |
|||||
| Ransomware | SBC Global, Bitfinex, Coinmama, and Rutgers University Part 2 id12289 View details | Education | |||
|
The four victims of our attack – SBC Global, Bitfinex, Coinmama, and Rutgers University. You refused to pay, and now […] |
|||||
| Ransomware | SBC Global, Bitfinex, Coinmom, and Rutgers University Part 2 id12287 View details | Education | |||
|
the four victims of our attack – SBC Global, Bitfinex, Coinmom, and Rutgers University. You refused to pay, and now […] |
|||||
| Ransomware | Bitfinex id12265 View details | Virgin Islands, British | Other | ||
|
To the executives of Bitfinex, We have successfully breached your security measures and obtained critical data from your servers. This |
|||||
| Ransomware | SBC Global id12264 View details | Tokelau | Communication / Marketing | ||
|
To the board of SBC Global, We have gained unauthorized access to your system and have procured highly confidential data, |
|||||
| Ransomware | Rutgers University id12263 View details | United States | Education | ||
|
We have infiltrated the Rutgers.edu servers, a well-known educational institution. In just 7 days, we will unveil their hidden truths |
|||||
| Ransomware | Coinmoma id12262 View details | Canada | Services | ||
|
To the management of Coinmoma, We have gained access to Coinmoma.com and have obtained sensitive data including user information and […] |
|||||