Ransomware Group intelligence
Lamashtu
ActiveTrack Lamashtu with 35 published victims and 2 known leak locations in a single intelligence view.
Overview
Lamashtu is tracked by Breach House as a ransomware group with 35 published victims.
Malaysia is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 14 100.0%
- Pending 0 0.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 3h ago | lamashtux5j74mcm7lwwgn5yrvuwtrpxjoyendif3v3hrztjesfoyayd.onion |
| Leak location 2 | Onion service | Down checked 3h ago | 7jhbjbyb3zp5ziqqn6kikfrgyjapd4wusseuu753ddknr37apqrxnpid.onion |
Top Activity Sectors (14)
- Manufacturing / Engineering 10
- Retail / E-commerce 4
- Construction / Real Estate 3
- Healthcare / Pharma 3
- Not identified 2
- IT 2
- Hospitality / Food & Beverage / Tourism 2
- Finance / Legal / Insurance 2
- Agriculture / Food 1
- Services 1
- Telecommunications 1
- Energy 1
- NGOs / Associations 1
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Lamashtu, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: lamashtu uses PowerShell scripts to execute malicious commands and spread payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: lamashtu leverages Registry Run Keys and startup folders to maintain persistence across reboots on infected machines.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: lamashtu disables antivirus and security tools using T1685 techniques to prevent detection and hinder recovery efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: lamashtu deletes Volume Shadow Copies and backup files via T1070.004 to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: lamashtu accesses LSASS memory to steal credentials for privilege escalation and lateral access.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: lamashtu performs network share discovery to identify accessible SMB shares for lateral movement and victim data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: lamashtu uses SMB/Windows Admin Shares for lateral movement between networked hosts within targeted environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: lamashtu exfiltrates stolen victim data over C2 channels before deploying ransomware to preserve leverage.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: lamashtu encrypts critical business files and data using T1486 to maximize operational disruption and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: lamashtu invokes system recovery inhibition mechanisms to prevent automated backups or remediation processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
WHAT_HAPPENED.readme.txt
=======================================================================
YOUR NETWORK HAS BEEN COMPROMISED
=======================================================================
__ _ _ __ _____
/ / /_\ /\/\ /_\ / _\ /\ /\/__ \/\ /\
/ / //_\\ / \ //_\\ \ \ / /_/ / / /\/ / \ \
/ /___/ _ \/ /\/\ \/ _ \_\ \/ __ / / / \ \_/ /
\____/\_/ \_/\/ \/\_/ \_/\__/\/ /_/ \/ \___/
What happened?
------------------------------------------
Your corporate network has been fully compromised. All critical files across your systems have been encrypted with a military-grade algorithm. Backups connected to the network have been encrypted too.
Additionally, a significant volume of sensitive data has been exfiltrated, including:
- Financial records and contracts;
- Employee personal data (PII);
- Client databases;
- Internal communications;
- And much more that you wouldn't want to be public.
Regulatory consequences:
------------------------------------------
Your data is subject to multiple regulatory frameworks. A confirmed breach triggers:
[GDPR — EU/EEA]
- Mandatory notification to authorities within 72 hours
- Notification to ALL affected individuals
- Fines up to 4% of annual global turnover or €20,000,000
- Regulatory investigation, public disclosure, class-action lawsuits from clients and employees
[CCPA/CPRA — California, USA]
- Statutory damages of $100–$750 PER consumer PER incident
- With thousands of records, this adds up to millions
- California AG investigation and civil penalties up to $7,500 per intentional violation
- Private right of action — your customers can sue directly
[HIPAA — if applicable]
- If ANY health-related data was in your systems:
- Fines from $100 to $50,000 PER record, up to $1.5M/year per violation category
- Criminal penalties including imprisonment
- HHS public "Wall of Shame" — permanent reputational record
The math is simple:
Our price << regulatory fines + lawsuits + reputation loss
Resolve this privately. No regulators, no lawsuits, no headlines. Nobody has to know.
If you refuse to negotiate, we will notify every regulatory authority whose jurisdiction covers your data — and your clients whose data we hold.
What NOT to do:
------------------------------------------
- DO NOT contact law enforcement.
They will seize your equipment for months and return it with "sorry, we can't help you with that". They cannot decrypt your files. They cannot prevent the data leak. They WILL forbid you from negotiating, leaving you with nothing.
- DO NOT attempt to restore from backups without verifying them first. Corrupted restores will cause permanent data loss.
- DO NOT MODIFY encrypted files. This will make recovery impossible.
- DO NOT hire a "recovery firm". Most of them simply contact us on your behalf and charge you a premium on top of our price.
What SHOULD you do:
------------------------------------------
1. Read this note completely.
2. Contact us using the information below.
3. You will receive proof that we have your data and can decrypt.
4. We agree on terms. You pay. You get everything back.
5. We delete your data from our servers. Incident stays private.
This is a business transaction. We have a reputation to maintain. Every client who has paid has received full decryption and data deletion.
Contact:
------------------------------------------
Your own chat with us. Use 'Tor Browser' to access it:
- URL: 7jhbjbyb3zp5ziqqn6kikfrgyjapd4wusseuu753ddknr37apqrxnpid.onion
- Access token: [snip]
Here is our blog with files of victims who refused to pay:
- URL: lamashtux5j74mcm7lwwgn5yrvuwtrpxjoyendif3v3hrztjesfoyayd.onion
If law enforcement has advised you not to negotiate, but you understand they cannot actually help you — use the backup channel. Our actual additional contacts you can find on our blog in section 'CONTACTS'.
We are available 24/7.
Deadline:
------------------------------------------
You have 3 days to make contact. After that:
- The price doubles.
- After 10 days, your data will be published on our leak site.
This timer started when your files were encrypted, not when you read this note.
The clock is ticking.
=======================================================================
dtaeXsxNY
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (35)
Search, filter and paginate the victim timeline for Lamashtu. Showing 1–35 of 35.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Great Foods id29957 View details | Egypt | Retail / E-commerce | leaked | ||
|
Great Foods is a major Egyptian food manufacturing and distribution company. Established in 1972 and a proud member of the El Naggar Group, it employs over 3,700 people and exports over 150 products to more than 40 countries. |
||||||
| Ransomware | PatayaFood id29738 View details | Thailand | Retail / E-commerce | leaked | ||
|
PatayaFood is a Thai food manufacturer and supplier producing ingredients, frozen foods, and ready-to-eat products for retail and restaurant customers. They provide quality control and export certifications, plus packaging and logistics services. |
||||||
| Ransomware | Shanpoornam Metals id29405 View details | Malaysia | Construction / Real Estate | leaked | ||
|
Shanpoornam Metals is a metal trading and fabrication company supplying a range of raw and processed metal products to manufacturers and construction firms. They provide custom cutting, processing, and distribution services to meet industrial. |
||||||
| Ransomware | H-W-G & Acros Sport id29501 View details | Germany | Manufacturing / Engineering | leaked | ||
|
HWG (h-w-g.com): German manufacturer of bearings and mechanical components for industrial machinery and automation. Acros Components (acros-components.com): Distributor and supplier of electronic components and related logistics/technical support. |
||||||
| Ransomware | ROTH‑TECHNIK AUSTRIA id29264 View details | Austria | Manufacturing / Engineering | — | ||
|
RTA GmbH manufacturer and distributor of metal pipe fittings, connectors, and forged components; operates in the pipeline fittings sector and provides related services, including import/export across Western Europe. |
||||||
| Ransomware | MSC Group id29222 View details | Malaysia | Manufacturing / Engineering | — | ||
|
MSC Group is a global metals trading and recycling corporation that purchases, processes, and supplies recycled ferrous and non‑ferrous materials to manufacturers and foundries. |
||||||
| Ransomware | Parle Agro id29189 View details | India | Agriculture / Food | — | ||
|
Parle Agro — an Indian company that makes non‑alcoholic beverages and packaged foods (brands: Frooti, Appy/Appy Fizz, Bailley, Hippo). |
||||||
| Ransomware | NaRaYa id29080 View details | Thailand | Other | leaked | ||
|
NaRaYa is a famous Thai brand recognized worldwide for its distinctive fabric bags and accessories. Founded in 1989, it has grown into one of Asia's most influential brands, specializing in high-quality, handcrafted products that showcase Thai crafts |
||||||
| Ransomware | Saharuang id29081 View details | Thailand | Other | — | ||
|
Company operates a large-scale sugar mill and refinery in the Saraburi province, producing various types of sugar for both domestic and export markets. |
||||||
| Ransomware | Depósito Dental Universitario id29059 View details | Mexico | Healthcare / Pharma | — | ||
|
Depósito Dental Universitario (DDU), a Mexican company specializing in the distribution of dental supplies and radiological services. |
||||||
| Ransomware | Sistemas Electrónicos y de Telecomunicaciones id29060 View details | Mexico | Manufacturing / Engineering | leaked | ||
|
Sertes is a Mexican company specializing in industrial automation, control systems, and telecommunications solutions. They provide PLC programming, SCADA systems, IoT integration... |
||||||
| Ransomware | Acros Sport GmbH id28975 View details | Germany | Manufacturing / Engineering | — | ||
|
Acros Sport GmbH is a high-end German bicycle component manufacturer based in Renningen, near Stuttgart. Founded in 1999, the company is a specialist in precision bearing technology for cycling |
||||||
| Ransomware | Ashtech Infotech id28976 View details | India | IT | — | ||
|
Ashtech Infotech (India) Pvt. Ltd. is a leading System Integrator and IT service provider based in Mumbai, India. Established in 1986, the company specializes in delivering end-to-end technology solutions to enterprises. |
||||||
| Ransomware | WOHA id28825 View details | Singapore | Construction / Real Estate | — | ||
|
WOHA is a renowned Singapore-based architectural practice founded in 1994 by Wong Mun Summ and Richard Hassell. The firm is globally recognized for its integration of environmental and social principles into high-density urban settings. |
||||||
| Ransomware | GRANDHOME id28855 View details | Bangladesh | Retail / E-commerce | leaked | ||
|
GRANDHOME is a leading Thai retailer specializing in construction materials, home decor, and furnishing products. Established in 1973, it has grown into a major hub for high-quality tiles, sanitary ware, and kitchen innovations |
||||||
| Ransomware | Luna Group id28886 View details | Egypt | Healthcare / Pharma | — | ||
|
Luna Group is a major Egyptian conglomerate established in 1966. It operates across the Middle East and North Africa (MENA) region, primarily focusing on pharmaceuticals, cosmetics, perfumes, and industrial raw materials. |
||||||
| Ransomware | ROYAL M HOTEL BY GEWAN FUJAIRAH LLC id28888 View details | United Arab Emirates | Hospitality / Food & Beverage / Tourism | — | ||
|
Royal M Hotel Fujairah by Gewan is an upscale 5-star hotel located in the heart of Fujairah, United Arab Emirates. |
||||||
| Ransomware | Apple Film Group id28625 View details | Germany | Services | — | ||
|
Apple Film Co., Ltd. is a leading manufacturer of high-quality plastic bags and films, specializing in Polyethylene (PE) products like HDPE, LDPE, and LLDPE. |
||||||
| Ransomware | Malaysian NPK Fertilizer Sdn. Bhd id28639 View details | Malaysia | Telecommunications | — | ||
|
Malaysian NPK established in 2001 in Kedah, is a leading producer of high-quality NPK compound fertilizers. The company is a joint venture between NAFAS and Petronas Chemicals |
||||||
| Ransomware | Jesin Group id28739 View details | Malaysia | Construction / Real Estate | leaked | ||
|
Jesin Group is a prominent property developer in Northern Malaysia with over 50 years of experience, specializing in residential and commercial real estate development, construction, and asset management. |
||||||
| Ransomware | Biotehnos id28249 View details | Romania | Healthcare / Pharma | leaked | ||
|
Biotehnos is a Romanian pharmaceutical company founded in 1993 by Prof. Dr. Ioan Manzatu. It is currently headquartered in Otopeni, Ilfov County, near the country’s capital, Bucharest, and celebrated its 30th anniversary in 2023. |
||||||
| Ransomware | VOLTERRIES id28213 View details | France | Energy | leaked | ||
|
Volterres, a subsidiary of the Eiffage group, is reinventing the supply of green electricity for businesses and public sector players. |
||||||
| Ransomware | LACROIX id28208 View details | QC | Finance / Legal / Insurance | — | ||
|
Pièces d'Auto Lacroix is a Canadian company specializing in the retail distribution of automotive parts and accessories across several locations in Quebec. |
||||||
| Ransomware | LACROIX id28208 View details | Canada | Finance / Legal / Insurance | — | ||
|
Pièces d'Auto Lacroix is a Canadian company specializing in the retail distribution of automotive parts and accessories across several locations in Quebec. |
||||||
| Ransomware | WEDA ROBOTICS id28179 View details | Sweden | Manufacturing / Engineering | — | ||
|
Over 100 Years of Engineering. Now Pioneering the Future of Sustainable Cleaning. From mechanical pool cleaners in the 1920s to submerged, no drain robotic systems used across 40+ countries. |
||||||
| Ransomware | GRUPO RONDA id28130 View details | Mexico | Finance / Legal / Insurance | — | ||
|
Grupo Ronda Auditores es un despacho constituido por un equipo de: Auditores, Mediadores Concursales, Expertos Contables, Licenciados en Derecho, debidamente colegiados. Licenciados en Administración y Dirección de empresas |
||||||
| Ransomware | IPARBILBAO ABOGADOS - ROCA JUNYENT id28129 View details | Spain | Retail / E-commerce | leaked | ||
|
Prestamos servicios de asesoramiento legal a la empresa y los negocios, incluyendo sus aspectos civiles, mercantiles, tributarios, laborales, de derecho administrativo, tanto de asesoramiento y defensa de administraciones, como de empresas. |
||||||
| Ransomware | Gauthier Tissus id28126 View details | France | Manufacturing / Engineering | leaked | ||
|
Based in the Rhone-Alpes basin, Gauthier Tissus is specialized in the weaving and finishing of multi-risk fabrics for technical usage, fabrics for brand image clothes and uniforms. |
||||||
| Ransomware | CNAOC id28125 View details | France | NGOs / Associations | — | ||
|
Depuis 1924, la CNAOC porte la voix du vignoble français dans toute sa richesse : vins, eaux-de-vie de vin, vins doux naturels et vins de liqueur. Nous sommes un collectif vivant de femmes et d’hommes au service d’une viticulture d’appellation authen |
||||||
| Ransomware | FILAIR id28124 View details | France | Manufacturing / Engineering | — | ||
|
Since 1953, Filair, a French company, has been designing, manufacturing and retrofitting wire equipment and mechanically welded assemblies. |
||||||
| Ransomware | Beaver Engineering id28123 View details | United States | Manufacturing / Engineering | — | ||
|
Beaver Engineering, Inc. is a Nashville-based geotechnical engineering firm founded in 1968, specializing in construction observation, materials testing, and sinkhole investigation throughout the southeastern United States. |
||||||
| Ransomware | ClientSolution EFO Service Srl Logitech Srl Safety id28122 View details | Italy | IT | — | ||
|
ClientSolution — facility management and business support services EFO Service Srl — technical and operational support services Logitech Srl — industrial automation solutions SafetyMed Srl — occupational health and |
||||||
| Ransomware | Servetto Srl id28121 View details | Italy | Manufacturing / Engineering | leaked | ||
|
Servetto Srl, einem weltweit führenden italienischen Unternehmen für Kleiderschrank-Zubehör. Bekannt ist die Marke vor allem für den sogenannten „Servetto“ – einen ausziehbaren Garderobenlift (Saliscendi), der den Zugriff auf hohe Schrankbereiche erl |
||||||
| Ransomware | International Assistance Sdn id28120 View details | Malaysia | Transportation / Travel / Logistics | — | ||
|
To provide the highest standard of service which adds value to our customers with the ultimate goal of becoming the preferred healthcare Contact Centre and Third-Party Administrator infrastructure and service provider in Malaysia. |
||||||
| Ransomware | The Seacare Hotel id28119 View details | Singapore | Hospitality / Food & Beverage / Tourism | leaked | ||
|
The Seacare hotel is strategically located near Singapore's top tourist spots such as Orchard Road, Chinatown and Clarke Quay. Enjoy viewing the skyline at our Sky lounge, sweat it out at our well-equipped Gym and savour the most delectable cuisine a |
||||||