Ransomware Group intelligence
Fulcrumsec
ActiveTrack Fulcrumsec with 25 published victims and 4 known leak locations in a single intelligence view.
Overview
Fulcrumsec is tracked by Breach House as a ransomware group with 25 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 52m ago | 4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion |
| Leak location 2 | Web location | Up checked 52m ago | 4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion/shame |
| Leak location 3 | Web location | Down checked 52m ago | fulcrumsec.net |
| Leak location 4 | Web location | Down checked 52m ago | fulcrumsec.net/shame |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Fulcrumsec, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: fulcrumsec executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: fulcrumsec adds malicious registry run keys to ensure persistence across reboots on compromised systems.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: fulcrumsec disables antivirus tools by terminating security processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: fulcrumsec deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: fulcrumsec accesses LSASS memory using native API calls to steal credentials for lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: fulcrumsec scans network shares using Windows Explorer APIs to identify valuable files for encryption across victim infrastructure.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: fulcrumsec moves laterally through SMB shares to encrypt additional servers within the victim network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: fulcrumsec exfiltrates stolen data via encrypted channels before deploying ransomware to maximize extortion leverage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: fulcrumsec encrypts victim files using AES-256 encryption with custom keys stored in memory to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: fulcrumsec calls shutdown commands to halt critical services and disrupt victim operations during encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (25)
Search, filter and paginate the victim timeline for Fulcrumsec. Showing 1–25 of 25.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Novo Nordisk id29936 View details | Denmark | Healthcare / Pharma | ||
|
[AI generated] Novo Nordisk is a Danish multinational pharmaceutical company headquartered in Bagsværd, Denmark. Founded in 1923, it specializes in treatments for diabetes, obesity, hemophilia, and other chronic conditions. The company is a global leader in insulin production and develops drugs such as semaglutide. It operates in over 80 countries and is one of Europe's most valuable corporations by market capitalization. |
|||||
| Ransomware | Global Schools Foundation id29717 View details | Singapore | Education | ||
|
[AI generated] Global Schools Foundation is a Singapore-based non-profit organization operating in the international education sector. It manages a network of private schools across Asia and the Middle East under brands such as Global Indian International School. The foundation focuses on providing quality education with an Indian curriculum framework to students from diverse nationalities, emphasizing holistic development and academic excellence across multiple campuses worldwide. |
|||||
| Ransomware | Arup Group id29002 View details | United Kingdom | Construction / Real Estate | ||
|
[AI generated] Arup Group is a British multinational professional services firm headquartered in London, United Kingdom. Founded in 1946, it operates in the engineering, design, planning, and consulting industries. The firm provides structural, civil, mechanical, and electrical engineering services, alongside architecture and project management. Arup works across sectors including infrastructure, buildings, transport, and energy, delivering projects in over 140 countries worldwide. |
|||||
| Ransomware | Stuf Storage id28960 View details | United States | Services | ||
|
[AI generated] Stuf Storage is a US-based company operating in the self-storage industry. It offers on-demand, flexible storage solutions primarily in urban markets, allowing customers to rent storage units without long-term commitments. The company focuses on converting underutilized urban spaces such as basements and parking structures into storage facilities. Stuf operates across several major US cities and targets city dwellers seeking convenient, accessible storage options. |
|||||
| Ransomware | Avnet id28338 View details | United States | IT | ||
|
[AI generated] Avnet is a global electronic components distributor and technology solutions provider headquartered in Phoenix, Arizona, USA. Founded in 1921, it operates in the technology and electronics distribution industry, serving manufacturers and designers worldwide. Avnet supplies semiconductors, interconnects, passives, and electromechanical components, while also offering supply chain management, design, and engineering services across North America, Europe, and Asia. |
|||||
| Ransomware | Lena Health id28339 View details | United States | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | Woundtech id28340 View details | United States | Healthcare / Pharma | ||
|
[AI generated] Woundtech is a US-based healthcare company specializing in advanced wound care management services. It provides in-home and facility-based wound care treatment to patients, primarily serving Medicare and Medicaid populations. The company employs clinicians who deliver specialized wound care directly to patients in skilled nursing facilities and home settings, focusing on chronic and complex wound treatment across the United States. |
|||||
| Ransomware | youX / Drive IQ id28341 View details | Australia | NGOs / Associations | ||
|
[AI generated] youX, formerly known as Drive IQ, is an Australian technology company specializing in connected vehicle data and mobility intelligence. The company collects and analyzes telematics and driving behavior data to deliver insights for insurers, fleet operators, and automotive businesses. Its platform enables usage-based insurance and risk assessment solutions. youX operates primarily in Australia and positions itself within the insurtech and automotive data analytics sectors. |
|||||
| Ransomware | LexisNexis id28342 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] LexisNexis is a global information and analytics company headquartered in the United States. It operates in the legal, regulatory, and business intelligence industries, providing research tools, data analytics, and risk management solutions. Its platforms are widely used by legal professionals, law enforcement, and enterprises to access vast databases of legal documents, news, public records, and compliance information. |
|||||
| Ransomware | MCO id28343 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] N/A The acronym "MCO" is too ambiguous to identify a specific company with confidence. Multiple organizations share this abbreviation across different industries and countries. Please provide additional context such as the full company name, industry, or country of operation to allow for an accurate and reliable description. |
|||||
| Ransomware | ReFocus AI id28344 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | Hatica id28345 View details | United States | IT | ||
|
[AI generated] Hatica is an engineering analytics platform founded in India that helps software development teams improve productivity and well-being. It aggregates data from tools like GitHub, Jira, and Slack to provide insights into developer workflows, sprint performance, and team health metrics. Operating in the developer productivity and engineering management industry, Hatica serves engineering leaders seeking data-driven decisions to reduce burnout and optimize delivery. |
|||||
| Ransomware | Analog Gold / Prospector id28346 View details | United States | Communication / Marketing | ||
|
[AI generated] N/A |
|||||
| Ransomware | Nordstern Technologies id28347 View details | Mexico | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | ParkEngage id28348 View details | United States | IT | ||
|
[AI generated] ParkEngage is a US-based technology company specializing in smart parking solutions. It provides cloud-based software platforms that help parking operators manage reservations, payments, and customer engagement. Its services cater to airports, hospitals, universities, and commercial facilities. The company focuses on enhancing the parking experience through digital tools including mobile apps, contactless payments, and data analytics to optimize parking operations and revenue management. |
|||||
| Ransomware | Saleskido id28349 View details | India | Communication / Marketing | ||
|
[AI generated] N/A |
|||||
| Ransomware | Interzero id28350 View details | Germany | Services | ||
|
[AI generated] Interzero is a European environmental services company headquartered in Germany. It specializes in waste management, recycling, and circular economy solutions. The company helps businesses comply with extended producer responsibility regulations, manages packaging take-back systems, and provides consulting on sustainable resource use. Interzero operates across multiple European countries and serves clients in retail, manufacturing, and industry sectors. |
|||||
| Ransomware | IMEVI id28351 View details | Colombia | Healthcare / Pharma | ||
|
[AI generated] N/A |
|||||
| Ransomware | Raptor Supplies id28352 View details | Netherlands | Retail / E-commerce | ||
|
[AI generated] Raptor Supplies is an online industrial and commercial supplies distributor operating in the United Kingdom and Europe. The company offers a broad catalogue of products including tools, safety equipment, electrical components, storage solutions, and maintenance supplies. It serves businesses across various sectors such as manufacturing, construction, and facilities management, providing procurement solutions for industrial and workplace needs. |
|||||
| Ransomware | Rotary Club id28353 View details | United States | NGOs / Associations | ||
|
[AI generated] Rotary Club, formally known as Rotary International, is a global humanitarian service organization founded in 1905 in Chicago, USA. It operates across more than 200 countries with over 35,000 clubs and 1.4 million members. The organization focuses on community service, vocational development, and international goodwill, with notable initiatives including the near-eradication of polio worldwide through its PolioPlus program. |
|||||
| Ransomware | JOT id28354 View details | Japan | NGOs / Associations | ||
|
[AI generated] N/A |
|||||
| Ransomware | BookBlock id28355 View details | United Kingdom | Retail / E-commerce | ||
|
[AI generated] BookBlock is a UK-based premium printing and bookbinding company specializing in high-quality custom notebooks, journals, books, and printed products. It serves both businesses and individual consumers, offering bespoke design and manufacturing services. Operating in the print and publishing industry, BookBlock is known for its craftsmanship and attention to detail, producing products for corporate clients, publishers, and retail customers across the United Kingdom and internationally. |
|||||
| Ransomware | Crank Communications id28356 View details | United States | Communication / Marketing | ||
|
[AI generated] N/A |
|||||
| Ransomware | CrediElite id28357 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | Fashinza id28358 View details | India | IT | ||
|
[AI generated] Fashinza is an AI-driven B2B fashion supply chain platform founded in India. It connects fashion brands and retailers with manufacturers, streamlining apparel production by managing sourcing, sampling, production tracking, and quality control. Operating primarily in India with global clientele, the company leverages technology to improve transparency and efficiency in garment manufacturing, reducing lead times and costs for fashion businesses. |
|||||