Ransomware Group intelligence
Malekteam
InactiveTrack Malekteam with 7 published victims and 2 known leak locations in a single intelligence view.
Overview
Malekteam is tracked by Breach House as a ransomware group with 7 published victims.
Israel is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Web location | Up checked 1h ago | 195.14.123.2. |
| Leak location 1 | Web location | Down checked 1h ago | malekteam.ac |
Top Activity Sectors (6)
Typical Attacks (7)
▼MITRE ATT&CK does not currently catalogue Malekteam, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: malekteam executes PowerShell scripts to run payload installation and system reconnaissance commands.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: malekteam disables security tools such as EDR and antivirus processes to evade detection during compromise.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: malekteam deletes Volume Shadow Copies and backup directories to prevent recovery from restore points.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: malekteam uses network share discovery to locate victim file shares and identify high-value data for exfiltration.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: malekteam exfiltrates stolen healthcare and financial records before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: malekteam encrypts victim files using a custom ransomware payload to maximize disruption and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: malekteam invokes system recovery inhibition commands to block automatic restoration attempts post-encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (7)
Search, filter and paginate the victim timeline for Malekteam. Showing 1–7 of 7.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | emalon.co.il id11523 View details | Israel | Transportation / Travel / Logistics | ||
|
🔥Malek team in the newest cyber attack to Israeli sites, recently hacked emalon.co.il. "emalon" in hebrew "אימלון" was an travelling site that hacked by "Malek team".🔥🔴 & MALEK TEAM DESTROYED ALL DATA 🔴🔥 MALEK TEAM has everything 🔪🩸 |
|||||
| Ransomware | Doctorim id11521 View details | Israel | Healthcare / Pharma | ||
|
🔥"Doctorim" ,in Hebrew "דוקתורים" ,is the online medical site in Israel which attacked by Malek teambased on this successful cyber attack, we have the information of more than 1,200,000 persons and companions ☠️information includes: ☠️🩸 verified names🩸 verified identity numbers,🩸 verified contact numbers🩸 verified emails & phones🩸 & etc ...🧨⚠️and we destroyed all data⚠️🧨 MALEK TEAM has everything 🔪🩸 |
|||||
| Ransomware | Beit Handesai id10432 View details | Israel | Manufacturing / Engineering | ||
|
Beit Handesai ,in Hebrew "בית ההנדסאי" , the engineering company in Israel attacked by Malek team 🔥 based on this successful cyber attack, we have the information of more than 60,000 persons and companions ☠️ information includes: ☠️documents including:🩸 names & identity numbers,🩸 contact numbers and emails,🩸 phones & home addresses🩸 PDFs of passports️🩸 & etc ...🧨⚠️and we destroyed all data⚠️🧨 MALEK TEAM has everything 🔪🩸 |
|||||
| Ransomware | Ono Academic College id10286 View details | Education | |||
|
👁 130000 records of Personal Information include First name Last name Email Address Phone number Home Number Password ... |
|||||
| Ransomware | dorimedia id10285 View details | Switzerland | Communication / Marketing | ||
|
🩸 Dori Media Group Hacked by Malek Team 🩸We have destroyed more than 100 TB data from this company. Since 1998 This is just the beginning of the story. Wait 🧨👀 Dori Media Group LTDDori Media Group is an international group of media companies, located in Israel, Switzerland, Argentina, Spain and Singapore. The group produces and distributes TV and New Media content, broadcasts various TV channels and operates video-content internet sitesWe will leaks all this information soon 👁 |
|||||
| Ransomware | gav.co.il id10284 View details | Israel | Finance / Legal / Insurance | ||
|
🔥🔥After infiltrating the network system of this site, we took the necessary access to it and transferred its useful data And at the end, we deleted part of the existing information. Some information transferred from the GAV site:Identity information and identification documents ☠️a large of financial and administrative files and documentsInformation and details of projects 🩸This amount of sensitive site information (about 10 terabytes) which was not worth transferring in terms of volume and time was deleted and destroyed 🔥 |
|||||
| Ransomware | ZIV Hospital id10283 View details | Israel | Healthcare / Pharma | ||
|
The ZIV medical center in northern Israel, in Safed, hacked by Malek team 🔥 based on this successful cyber attack, we have the information of more than 300,000 patients and companions ☠️documents including:🩸 names & identity numbers,🩸 contact numbers and emails,🩸 types of diseases and drugs,🩸 genetic codes of patients,️🩸 their DNAs & RNAs,🩸 & etc ...MALEK TEAM has everything 🔪🩸 |
|||||