Ransomware Group intelligence
Marketo
InactiveTrack Marketo with 32 published victims and 4 known leak locations in a single intelligence view.
Overview
Marketo is tracked by Breach House as a ransomware group with 32 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Down checked 1h ago | jvdamsif53dqjycuozlaye2s47p7xij4x6hzwzwhzrqmv36gkyzohhqd.onion |
| Leak location 3 | Onion service | Down checked 1h ago | fvki3hj7uxuirxpeop6chgqoczanmebutznt2mkzy6waov6w456vjuid.onion |
| Leak location 2 | Onion service | Down checked 1h ago | g5sbltooh2okkcb2.onion |
| Leak location 1 | Onion service | Down checked 1h ago | marketojbwagqnwx.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Marketo, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: marketo uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: marketo adds malicious registry run keys to ensure persistence and automatic execution upon system reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: marketo disables security tools by terminating antivirus processes and modifying system configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: marketo deletes Volume Shadow Copies and backup files via vssadmin commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: marketo accesses LSASS memory using tools like Mimikatz to steal credentials for privilege escalation and lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1049 System Network Connections Discovery Discovery
What they do: marketo queries system network connections to identify active hosts and prioritize targets for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: marketo discovers network shares using net view and similar commands to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: marketo moves laterally through SMB shares to encrypt additional machines within the victim network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: marketo encrypts victim files using a custom ransomware algorithm targeting documents, images, and system directories for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: marketo calls system recovery inhibitors like shutdown scripts to prevent backup restoration and increase pressure on victims.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (32)
Search, filter and paginate the victim timeline for Marketo. Showing 1–32 of 32.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Vehicle Service Group (VSG) id2638 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Millensys id2108 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GigaTribe id2107 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Morgan Truck Body, LLC id2106 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Luxottica Group S.p.A. id2105 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kawasaki Kisen Kaisha, Ltd. (“K” LINE) id2104 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | X-FAB id2103 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Axis Communications id2102 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gamesa Corporation leaked data id2101 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sea Mar Community Health Centers id2100 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Elm3 Financial Group, LLC id2099 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Virginia Department of Military Affairs id2098 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sandhills Center id2097 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Virginia Defense Force id2096 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Otto Instrument id2095 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Navistar (Volkswagen Group) id2094 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Align Technology, Inc id2093 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | puma.com id2092 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | meditopia.com id2091 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | tpicorp.com id2090 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | elementia.com id2089 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | gigatribe.com id2088 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | millensys.com id2087 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cbsltrans.com id2086 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bowmanplating.com id2085 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | morgancorp.com id2084 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | fujitsu.com id2083 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | spsr-law.com id2082 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | esited.com id2081 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | epicor.com id2080 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | luxottica.com id2079 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | dwr.virginia.gov id2078 View details | United States | Other | — | |
|
No additional victim description available. |
|||||