Ransomware Group intelligence
Majinahanashi
ActiveTrack Majinahanashi with 22 published victims and 4 known leak locations in a single intelligence view.
Overview
Majinahanashi is tracked by Breach House as a ransomware group with 22 published victims.
France is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 22 100.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 13h ago | rtypxnzdjus6slwtzhmnh7dnc35q3sdzbiuhaammefl5u2ce2lxkg5yd.onion |
| Leak location 2 | Onion service | Up checked 13h ago | cc666mzpsjhn3yi6t7hqkwi5thjeh7prxg3mndpceb7xtchsbsmct3ad.onion |
| Leak location 1 | Onion service | Up checked 13h ago | lthicpjqc7gkn5eq3epxndc2uig3yngvcbdya4u3m3byjod5km4yuwqd.onion |
| Leak location 4 | Onion service | Down checked 13h ago | rz45lyi2ehl2e2xs3ivwbah65tumebztmypmtqpc6cigc3wadwjicgad.onion |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Majinahanashi, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: majinahanashi executes PowerShell scripts to deploy payloads and manipulate system processes on targeted hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: majinahanashi modifies Windows Registry Run keys to maintain persistence across reboots on compromised systems.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: majinahanashi uses startup folders to launch ransomware components automatically during user logon.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: majinahanashi disables antivirus tools and modifies security utilities to evade detection during lateral movement.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: majinahanashi deletes Volume Shadow Copies and backup directories to prevent recovery from ransomware encryption.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: majinahanashi uses file and directory discovery to enumerate critical retail and agricultural data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1560.001 Archive via Utility Collection
What they do: majinahanashi archives stolen retail transaction data using utility tools prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: majinahanashi encrypts victim files with impact-oriented payloads targeting e-commerce and healthcare databases.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: majinahanashi stops critical Windows services like backup and monitoring tools to maximize disruption.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: majinahanashi inhibits system recovery by corrupting backup services and disabling restore mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (22)
Search, filter and paginate the victim timeline for Majinahanashi. Showing 1–22 of 22.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | TERRACOM & MONTCAU id32385 View details | Spain | Services | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
||||||
| Ransomware | TERRA*** & MON**** id32258 View details | Spain | — | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
||||||
| Ransomware | MONTCAU id32257 View details | France | Services | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
||||||
| Ransomware | PCA Group Sdn. Bhd. id32093 View details | Malaysia | Services | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 1844 FILES] |
||||||
| Ransomware | PCA ***** id32013 View details | — | pending | |||
|
PUBLICATION SCHEDULED. [LEAK / 1844 FILES] |
||||||
| Ransomware | Grand Ion Delemen Hotel id31862 View details | — | pending | |||
|
PUBLICATION SCHEDULED. [LEAK / 5045 FILES] |
||||||
| Ransomware | The Margo Hotel id31863 View details | United Kingdom | — | pending | ||
|
PUBLICATION SCHEDULED. [LEAK / 8080 FILES] |
||||||
| Ransomware | PIO PIO id31742 View details | Colombia | Retail / E-commerce | pending | ||
|
TARGET: piopio.com.co REVENUE: $5m EMPLOYEES: 33 staff [LEAK / 6306 FILES] |
||||||
| Ransomware | BONJOUR GROUP id31743 View details | India | — | pending | ||
|
TARGET: bonjourgroup.net, bonjourretail.com REVENUE: $57.8 Million EMPLOYEES: 501-1,000 employees [LEAK / 5620 FILES] |
||||||
| Ransomware | KT RESTAURANT id31744 View details | Thailand | — | pending | ||
|
TARGET: ktr.co.th REVENUE: ~$55M USD EMPLOYEES: ~ [LEAK / 1853 FILES] |
||||||
| Ransomware | SON-VIDEO id31585 View details | France | Retail / E-commerce | pending | ||
|
TARGET: Son-Video.com REVENUE: $54M EMPLOYEES: ~51-200 employees [LEAK / 10382 FILES] |
||||||
| Ransomware | GRUPO STARFOODS id31586 View details | Portugal | Agriculture / Food | — | pending | |
|
TARGET: starfoods.pt REVENUE: ~ EMPLOYEES: ~ [LEAK / 3420 FILES] |
||||||
| Ransomware | CDA id31587 View details | Italy | Healthcare / Pharma | — | pending | |
|
TARGET: https://centrodiagnosticocda.it/ REVENUE: ~ EMPLOYEES: ~ [LEAK / 135426 FILES] |
||||||
| Ransomware | WONDR DIAMONDS & D GEM MOUNT id31588 View details | United States | Retail / E-commerce | — | pending | |
|
TARGET: wondrdiamonds.com & gemmount.com REVENUE: $12m USD EMPLOYEES: 200+ [LEAK / 247 FILES] |
||||||
| Ransomware | CARIBE / SUBRA id31589 View details | Colombia | Hospitality / Food & Beverage / Tourism | — | pending | |
|
TARGET: kalimancaribe.com & subra.bg. REVENUE: ~ EMPLOYEES: ~ [LEAK / 21311 FILES] |
||||||
| Ransomware | SCHMITZ & NITTENWILM id31590 View details | Germany | Manufacturing / Engineering | — | pending | |
|
TARGET: schmitz-nittenwilm.de REVENUE: €13,8M EMPLOYEES: ~ [LEAK / 886 FILES] |
||||||
| Ransomware | Goccia S.p.A. id31591 View details | Italy | Retail / E-commerce | — | pending | |
|
TARGET: https://www.joygioielli.com/ https://www.gocciagioielli.com/ REVENUE: €19.2M EMPLOYEES: ~ [LEAK / 3557 FILES] |
||||||
| Ransomware | Camandona SA id31592 View details | Switzerland | Retail / E-commerce | — | pending | |
|
TARGET: https://www.camandona.ch/ REVENUE: $61.7M EMPLOYEES: 200 [LEAK / 9584 FILES] |
||||||
| Ransomware | ALTAIR id31593 View details | United States | IT | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 84251 FILES] |
||||||
| Ransomware | UAB Biotecha id31594 View details | Lithuania | Healthcare / Pharma | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 20888 FILES] |
||||||
| Ransomware | ETICOD id31595 View details | Other | — | pending | ||
|
PUBLICATION SCHEDULED. [LEAK / 5730 FILES] |
||||||
| Ransomware | CALICHE id31596 View details | Chile | Energy | — | pending | |
|
PUBLICATION SCHEDULED. [LEAK / 39200 FILES] |
||||||