Ransomware Group intelligence
Killsec
ActiveTrack Killsec with 293 published victims and 3 known leak locations in a single intelligence view.
Overview
Killsec is tracked by Breach House as a ransomware group with 293 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 1h ago | ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion |
| Leak location 3 | Onion service | Up checked 1h ago | ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion |
| Leak location 1 | Onion service | Down checked 1h ago | kill432ltnkqvaqntbalnsgojqqs2wz4lhnamrqjg66tq6fuvcztilyd.onion |
Top Activity Sectors (16)
- Not identified 106
- Communication / Marketing 39
- Services 30
- Healthcare / Pharma 27
- Finance / Legal / Insurance 24
- Retail / E-commerce 11
- Education 10
- IT 9
- Public Sector 6
- Hospitality / Food & Beverage / Tourism 6
- Transportation / Travel / Logistics 6
- Construction / Real Estate 3
- Energy 3
- Telecommunications 2
- Manufacturing / Engineering 2
- Agriculture / Food 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Killsec, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: killsec executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: killsec modifies Windows Registry Run Keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: killsec disables security tools like EDR agents and antivirus software to prevent detection and response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.002 Software Packing Stealth
What they do: killsec packs its malware binaries to evade signature-based detection by security vendors.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1070.004 File Deletion Stealth
What they do: killsec deletes Volume Shadow Copies and backup directories via vssadmin and command-line tools to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: killsec accesses and dumps LSASS memory using credential-extraction tools to harvest user credentials.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1018 Remote System Discovery Discovery
What they do: killsec performs remote system discovery via Nmap scans to map internal networks and identify high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: killsec scans network shares using SMB tools to identify victim hosts and data repositories for targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: killsec leverages SMB/Windows Admin Shares for lateral movement across networked machines within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: killsec exfiltrates stolen data via encrypted C2 channels before deploying ransomware to maximize extortion leverage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: killsec encrypts victim files using custom symmetric encryption routines targeting documents, images, and databases.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: killsec invokes system shutdown commands and service termination scripts to disrupt operational continuity.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (293)
Search, filter and paginate the victim timeline for Killsec. Showing 101–200 of 293.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Fancy Films id18887 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Lendco id18886 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Nydegger + Finger AG id18885 View details | Switzerland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Dorel Home id18989 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Dorel Home id18989 View details | United States | Other | ||
|
Dorelhome.com is the digital storefront of Dorel Home, a North American furniture brand headquartered in Quebec that designs and manufactures ready-to-assemble home furniture and commercial hardware for major retailers. Since 1962, the company has been globally recognized for producing quality furniture for every home, room, and lifestyle, operating across diverse furniture segments throughout North America. The brand offers a wide range of home furnishings and commercial hardware, serving major retailers with a focus on sustainable growth and customer-centric strategies. Dorel Home was listed as a ransomware victim associated with the threat actor killsec, with no confirmed details on stolen data or breach specifics. |
|||||
| Ransomware | Hexicor id18988 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Hexicor id18988 View details | Australia | Other | ||
|
Hexicor is an Australian technology solutions provider headquartered in Brisbane, Queensland, with operations across Queensland, South Australia, and the Northern Territory. Its services include communications and digital access control, mobility and IoT, and managed IT services for business customers. Company profiles describe it as a national ICT integrator and technology leader serving organisations that need connectivity and operational support. It was listed as a ransomware victim associated with killsec. |
|||||
| Ransomware | AAPG id18987 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | AAPG id18987 View details | United States | Other | ||
|
aapg.org is the official website of the American Association of Petroleum Geologists, a US-based international professional organization focused on petroleum geology and geoscience. It supports research, professional development, technical publishing, student programs, and local section activities for members in the energy and geology community. The organization publishes peer-reviewed content and provides educational and membership resources through its digital platform. It was listed as a ransomware victim associated with killsec. |
|||||
| Ransomware | Hanna Global Solutions id18986 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Hanna Global Solutions id18986 View details | United States | Services | ||
|
Workforce Junction is a US-based services company that describes itself as a boutique technology partner for benefit advisors and their employer clients. Its offerings include employee benefits support, customer success management, invoice reconciliation and audit services, payroll deduction reconciliation, enrollment support, and related HR services. The company’s site also presents it as a provider of solutions such as OE Express and The Benefits Desk, focused on improving benefits administration and operational efficiency. Workforce Junction was listed as a ransomware victim associated with KillSec. |
|||||
| Ransomware | Flagship Press Flagship Press id18880 View details | Communication / Marketing | |||
|
No additional victim description available. |
|||||
| Ransomware | Lee & Sakahara Architects id18858 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Kyocera Document Solutions Europe id18857 View details | Netherlands | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Design Design id18856 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Lupin Limited id18752 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Precision Accounting Intl id18628 View details | Finance / Legal / Insurance | |||
|
No additional victim description available. |
|||||
| Ransomware | SPARSH Hospital id18615 View details | India | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Innovative Surfaces id18614 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Cayman National Bank id18579 View details | Cayman Islands | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | Officio Medical id18574 View details | Germany | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Obra Play id18553 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | interiseworld.com id18552 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Instituto de Ojos id18551 View details | Argentina | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Harcourts Prime Properties id18483 View details | United States | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Skyward Specialty Insurance id18337 View details | United States | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | Trymata id18336 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Wendy Wu Tours id18159 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Workforce Group id18116 View details | Nigeria | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Shaghalni id17720 View details | Egypt | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | BluAgent Technologies, Inc id17719 View details | United States | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | Novi Community School District id17718 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | G&M Direct Hire id17717 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Medical File id17680 View details | Mexico | Healthcare / Pharma | ||
|
El expediente clínico más innovador del mercado |
|||||
| Ransomware | DR.Claims FL LLC id17639 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | EzyLegal id17638 View details | India | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | BeniPlus id17626 View details | Canada | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Brolly id17625 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Revi id17624 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Help Me Grow Yolo id17623 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | NimuSoft id17622 View details | Finland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Obex Medical id17501 View details | New Zealand | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Logix Corporate Solutions id17422 View details | India | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | TMC id17420 View details | Mexico | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Enfin id17362 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Capital Cell Global (CCG) id17346 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | ASRAM Medical College and Hospita id17345 View details | India | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Albright Institute id17293 View details | Australia | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | WhoHire id17292 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Ponte16 Hotel & Casino id17133 View details | Macao | Hospitality / Food & Beverage / Tourism | ||
|
No additional victim description available. |
|||||
| Ransomware | Nano Health id17098 View details | India | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | payahmedabadechallan.org id17006 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Let’s Secure Insurance id16867 View details | India | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | DataSociete id16863 View details | France | Finance / Legal / Insurance | ||
|
DataSociete is a comprehensive B2B platform specializing in global business intelligence and financial analysis. The company provides access to a vast database of over 12.8 million companies, offering tools for advanced searches, financial data analysis, and corporate document retrieval. |
|||||
| Ransomware | Keepz id16856 View details | United States | Communication / Marketing | ||
|
Keepz is a cutting-edge digital payment solution provider based in Tbilisi, Georgia, offering innovative tools for businesses to streamline transactions. The company’s flagship product is its QR-based payment system, which enables businesses to accept payments without physical terminals or user registration. |
|||||
| Ransomware | PrimoTicketing id16853 View details | United States | Communication / Marketing | ||
|
Primo Ticketing is a leading provider of digital ticketing solutions tailored for youth sports, cheer, and dance events. The company specializes in offering a seamless, all-in-one platform that simplifies ticket sales, purchases, and tracking for event organizers. Primo Ticketing’s key offerings include customizable ticket purchase links, real-time sales tracking, and dedicated equipment for on-site payment processing and ticket scanning. |
|||||
| Ransomware | FAAB Invest Advisors Private Limited id16736 View details | India | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Nimbus Facility Services id16735 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Farmacia Cofar id16686 View details | Chile | Agriculture / Food | ||
|
No additional victim description available. |
|||||
| Ransomware | anupalanonline.com id16685 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Blome International id16265 View details | Germany | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | BRIGHT BOLT ENTERPRISES INC id16264 View details | Canada | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Casa Juarez Restaurant Supply Co id16263 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
No additional victim description available. |
|||||
| Ransomware | Davis Products Company Inc id16262 View details | United States | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Economy Restaurant Equipment And Supply Company id16261 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
No additional victim description available. |
|||||
| Ransomware | GAMKA SALES CO. INC id16260 View details | United States | Retail / E-commerce | ||
|
No additional victim description available. |
|||||
| Ransomware | Greater Michigan Distributors id16259 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | GPM Lawn Sprinkler Supply id16258 View details | United States | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | Greene Supply Company id16257 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Hammons Supply Company id16256 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | J AND S Electrical And Lighting Supply LLC id16255 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | LAMERS ENTERPRISE INC id16254 View details | United States | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Langford Tool And Drill Co id16253 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | McCally Tool and Supply id16252 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Abrasive Supply Corporation id16250 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Albert Paper Company id16249 View details | Canada | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Allied Packing And Rubber Inc id16248 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Avana Electrotek id16247 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Badger Popcorn And Concession Supply Company id16246 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Accolent ERP Software id16235 View details | United States | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | PT Pertamina id16225 View details | Indonesia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Khalil Center id16222 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Water Utilities Corporation id16221 View details | Botswana | Energy | ||
|
No additional victim description available. |
|||||
| Ransomware | Verosa LLC id16185 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | JSSR Options Co., Ltd. (JSSR) id16094 View details | Thailand | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Tumeny Payments Limited id16093 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Interforos Casting id15993 View details | Mexico | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | USA2ME id15868 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | briatek.com.ng id15706 View details | Nigeria | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | clubfitsoftware.com.au id15705 View details | Australia | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | cloudofgoods.com id15699 View details | United States | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | gehnaindia.com id15698 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | gajicermat.com id15697 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | waltersgardens.com id15647 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | goformz.com id15643 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | empowersettlementservices.com id15642 View details | United States | Energy | ||
|
No additional victim description available. |
|||||
| Ransomware | mydelux.com.my id15641 View details | Malaysia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Ithbar id15611 View details | Saudi Arabia | Hospitality / Food & Beverage / Tourism | ||
|
Choose ithbar.com as your solution to start your own crowdfunding platform. Start your own Real estate, Equity crowdfunding platform. |
|||||
| Ransomware | Dardoc id15610 View details | United Arab Emirates | Healthcare / Pharma | ||
|
Experience doorstep home healthcare services and home nursing services in UAE with DarDoc, the front-runner in home health medical centres. |
|||||
| Ransomware | inv[...]nator id15609 View details | United States | Finance / Legal / Insurance | ||
|
The Investment Dominator is a real estate investment CRM that allows you manage your contacts, property records, marketing campaigns and deal flow process for both land and house investing. |
|||||