Ransomware Group intelligence
Lv
InactiveTrack Lv with 63 published victims and 2 known leak locations in a single intelligence view.
Overview
Lv is tracked by Breach House as a ransomware group with 63 published victims.
France is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | rbvuetuneohce3ouxjlbxtimyyxokb4btncxjbo44fbgxqy7tskinwad.onion |
| Leak location 2 | Onion service | Down checked 1h ago | 4qbxi3i2oqmyzxsjg4fwe4aly3xkped52gq5orp6efpkeskvchqe27id.onion |
Top Activity Sectors (14)
- Not identified 39
- Services 4
- IT 3
- Hospitality / Food & Beverage / Tourism 3
- Telecommunications 2
- Finance / Legal / Insurance 2
- Healthcare / Pharma 2
- NGOs / Associations 2
- Agriculture / Food 1
- Construction / Real Estate 1
- Communication / Marketing 1
- Public Sector 1
- Manufacturing / Engineering 1
- Energy 1
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Lv, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: lv executes malicious commands via PowerShell to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: lv modifies registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: lv disables Windows security tools like antivirus software to evade detection and persistence mechanisms.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: lv deletes Volume Shadow Copies and backup directories via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: lv scans network shares using native tools to identify victim hosts for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: lv exploits SMB/Windows Admin Shares to propagate ransomware across networked victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: lv encrypts victim files using a custom ransomware payload to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: lv halts critical system recovery processes and service restarts to compound operational disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
lv.txt
=== Welcome to LV === [+] What's Happened? [+] Your files have been encrypted and currently unavailable. You can check it. All files in your system have gfiez7d7x extension. By the way, everything is possible to recover (restore) but you should follow our instructions. Otherwise you can NEVER return your data. [+] ATTENTION. YOUR DATA 80GB IS LEAKED [+] All your important documents was downloaded. Data leaked included: - Finance - Accounting - Bank Documents - Insurances - Clients Bases If you do not contact us within 72 hours, the incident will appear on a public blog read by the U.S. and world media at this link: http://rbvuetuneohce3ouxjlbxtimyyxokb4btncxjbo44fbgxqy7tskinwad.onion/post/[snip] [+] What are our guarantees? [+] It's just a business and we care only about getting benefits. If we don't meet our obligations, nobody will deal with us. It doesn't hold our interest. So you can check the ability to restore your files. For this purpose you should visit our website where you can decrypt one file for free. That is our guarantee. It doesn't metter for us whether you cooperate with us or not. But if you don't, you'll lose your time and data cause only we have the private key to decrypt your files. In practice - time is much more valuable than money. [+] How to get access to our website? [+] Use TOR browser: 1. Download and install TOR browser from this site: https://torproject.org/ 2. Visit our website: http://l55ysq5qjpin2vq23ul3gc3h62vp4wvenl7ov6fcn65vir7kc7gb5fyd.onion When you visit our website, put the following data into the input form: Key: [snip] !!! DANGER !!! DON'T try to change files by yourself, DON'T use any third party software or antivirus solutions to restore your data - it may entail the private key damage and as a result all your data loss! !!! !!! !!! ONE MORE TIME: It's in your best interests to get your files back. From our side we (the best specialists in this sphere) ready to make everything for restoring but please do not interfere. !!! !!! !!!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (63)
Search, filter and paginate the victim timeline for Lv. Showing 1–63 of 63.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | GLEN DIMPLEX GROUP UNITS WERE HACKED (DEFOND, DEFONDTECH AND OTHER). MORE THAN 1TB DATA WA id4670 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UNITEDAUTO.MX HAVE BEEN HACKED DUE TO MULTIPLE NETWORK VULNERABILITIES. MORE THAN 2TB OF P id4619 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | THEW ASSOCIATES HACKED. MORE THEN 50 GB SENSETIVE DATA LEAKED. id4577 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BRAZILIAN PET FOODS id4569 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LAW OFFICES OF JOHN T ORCUTT WAS HACKED. MORE THEN 2TB SENSETIVE DATA LEAKED. id4545 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CONSUMAX.COM.AR - WAS HACKED AND MORE THEN 2TB SENSETIVE DATA LEAKED id4453 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Saint Jean Industries - MORE THEN 1.5 TB DATA LEAKED id4449 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AWESOME-DENTAL.COM - HACKED AND MORE THEN 100GB LEAKED id4448 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WICKERSHAMCONSTRUCTION.COM - HACKED AND MORE THEN 1000GB DATA LEAKED! id4447 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PARAMOUNT ENTERPRISE INTERNATIONAL HACKED AND MORE THEN 1.5 TB DATA LEAKED id4446 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | THEHURSTGROUP.CO.UK - HACKED AND MORE THEN 2000GB SENSITIVE DATA LEAKED id4445 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ROUGIER HACKED. 1 TB SENSITIVE DATA LEAKED id4444 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GRUPO SIFU HACKED. MORE THEN 2TB SENSETIVE DATA LEAKED AND READY FOR PUBLICATION id4443 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SUBCARN WAS HACKED AND OVER 200 GB OF SENSETIVE DATA WAS STOLEN id4442 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KINETIC.PH WAS HACKED. 200 GB ENGINEERING AND CONFIDENTIAL DATA LEAKED id4441 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SICOTEC WAS HACKED. 200GB SENSETIVE DATA LEAKED id4440 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ANGT - HACKED. MORE THEN 700 GB SENSITIVE DATA LEAKED id4013 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ELEFONDATI SRL - WAS HACKED. 20 GB OF SENSITIVE DATA STOLEN id3953 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | STTLK - HACKED AND MORE THEN 200GB DATA LEAKED id3951 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | valverdehotel.com id3939 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SEMIKRON - EXTREMELY LOW LEVEL OF CYBERSECURITY. 2 TB OF CORPORATE DATA STOLEN id3907 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WARTSILA DATA - ATTENTION !!! id3906 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | STTLK id3902 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BAFNAGROUP.COM - HACKED AND MORE THEN 20 GB DATA LEAKED id3889 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hong Kong Special Care Dentistry Association Limited id3884 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | studioteruzzi.com - HACKED AND MORE THEN 80GB DATA LEAKED id3874 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ryanhanley.ie - HACKED AND MORE THEN 200GB DATA LEAKED id3864 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | sppc.com.sa - HACKED and more then 900GB data leaked id3863 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WARTSILA.COM - HACKED AND MORE THEN 2000 GB DATA LEAKED id3862 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BAHRA ELECTRIC - HACKED AND MORE THEN 800 GB DATA LEAKED id3679 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MOLTOLUCE - HACKED AND DATA LEAKED id3645 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SCHIFFMANS - HACKED AND DATA LEAKED id3630 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MOTOLUCLE.COM - HACKED AND DATA LEAKED id3629 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CAPECODRTA - HACKED AND DATA LEAKED id3613 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SilTerra - HACKED AND 1 TB DATA LEAKED WITH SOURCES AND NDA id3591 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | XYTECH - HACKED AND 650 GB DATA LEAKED id3574 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CICIS.COM- HACKED AND INFORMATION MORE THEN 120,000 CUSTOMERS LEAKED id3573 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Important announcement id3468 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CPQD - BANCO CENTRAL OF BRASIL BLOCKHAIN. 1.8TB DATA LEAKED WITH ALL SOURCES. id3344 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MOTIVE-ENERGY - HACKED AND 1.5 TB DATA LEAKED id3317 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Importador Ferretero Trujillo Cia. Ltda id3184 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OPS omniplussystem.com id2652 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | gruporoveri.com.br id2647 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | www.tikg.co.jp id2633 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | ufa.com.lb id2610 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | lhotellerie-restauration.fr id2533 View details | France | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | wagstaff.com - 1.5TB LEAKED id2334 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | reliancenj.com - HACKED AND MORE THEN 200GB DATA LEAKED id2252 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | agrofair.nl id2185 View details | Netherlands | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | tt-network.dk id2165 View details | Denmark | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | KOBE BUSSAN - HACKED AND MORE THEN 500Gb DATA LEAKED id2161 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | benlineagencies.com id2136 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | tlpterminal.com.my id2126 View details | Malaysia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | serta.com - MORE THEN 500Gb DATA LEAKED id2111 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | jpbdselangor.gov.my id2068 View details | Malaysia | NGOs / Associations | — | |
|
No additional victim description available. |
|||||
| Ransomware | gaben.cz id2067 View details | Czechia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | promhotel.fr id2066 View details | France | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | ALPSRX.COM - MORE THEN 150GB DATA LEAKED id1983 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | scotttesting.com - MORE THEN 2.5TB DATA LEAKED id1979 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | reigroup.com id1968 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | redsrugby.com.au - more then 300GB data leaked id1959 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | docol.com.br - more then 1.5TB data leaked id1958 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | adhhealth.com - more then 1.2Tb data leaaked id1956 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||