Ransomware Group intelligence
Medusalocker
ActiveTrack Medusalocker with 107 published victims and 5 known leak locations in a single intelligence view.
Overview
Medusalocker is tracked by Breach House as a ransomware group with 107 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Down checked 1h ago | t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion |
| Leak location 2 | Onion service | Down checked 1h ago | z6wkgghtoawog5noty5nxulmmt2zs7c3yvwr22v4czbffdoly2kl4uad.onion |
| Leak location 4 | Onion service | Down checked 1h ago | medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion |
| Leak location 3 | Web location | Down checked 1h ago | 95.143.191.148:3000 |
| Leak location 1 | Onion service | Down checked 1h ago | qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion |
Top Activity Sectors (16)
- Communication / Marketing 19
- Not identified 14
- Finance / Legal / Insurance 9
- IT 8
- Public Sector 6
- Services 6
- Manufacturing / Engineering 5
- Education 4
- Agriculture / Food 3
- Retail / E-commerce 3
- Construction / Real Estate 2
- Telecommunications 1
- NGOs / Associations 1
- Energy 1
- Healthcare / Pharma 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Medusalocker, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: medusalocker uses PowerShell scripts to execute ransomware payloads and propagate across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: medusalocker modifies Windows Registry Run keys to ensure ransomware execution upon system startup.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: medusalocker uses registry run keys and startup folders to maintain persistence after reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: medusalocker disables antivirus tools and security processes to prevent detection and hinder system recovery.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: medusalocker deletes Volume Shadow Copies and backup directories via system commands to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: medusalocker accesses and dumps LSASS memory to steal credentials for lateral movement and evasion.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: medusalocker discovers network shares using SMB enumeration to identify additional victims for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: medusalocker moves laterally via SMB/Windows Admin Shares to encrypt additional machines within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: medusalocker encrypts victim files and backups using its ransomware payload to maximize impact and extortion.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: medusalocker calls system recovery inhibitors to block backup restoration and force reliance on decryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (2)
▼Software Medusalocker has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (21)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1AbRxRfP6yHePpi7jmDZkS4Mfpm1ZiatH5 |
bitcoin | $1,194,661 | 388 |
1PopeZ4LNLanisswLndAJB1QntTF8hpLsD |
bitcoin | $866,858 | 17 |
1AereQUh8yjNPs9Wzeg1Le47dsqC8NNaNM |
bitcoin | $731,990 | 75 |
1HEDP3c3zPwiqUaYuWZ8gBFdAQQSa6sMGw |
bitcoin | $658,778 | 94 |
1PormUgPR72yv2FRKSVY27U4ekWMKobWjg |
bitcoin | $450,421 | 59 |
1BkmiGWPLum8MzusqZsq6Tn7v4oUjqPLjC |
bitcoin | $241,977 | 35 |
18wRbb94CjyTGkUp32ZM7krCYCB9MXUq42 |
bitcoin | $200,665 | 57 |
bc1qy7ewkfpfr4x4rp39uwgsh2u698sl2uhfadqfyt |
bitcoin | $190,877 | 1 |
184ZcAoxkvimvVZaj8jZFujC7EwR3BKWvf |
bitcoin | $158,499 | 2 |
1HZHhdJ6VdwBLCFhdu7kDVZN9pb3BWeUED |
bitcoin | $157,077 | 14 |
1Edcufenw1BB4ni9UadJpQh9LVx9JGtKpP |
bitcoin | $139,328 | 14 |
1DyMbw6R9PbJqfUSDcK5729xQ57yJrE8BC |
bitcoin | $129,235 | 16 |
+9 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_RECOVER_DATA.html
<html>
<style type="text/css">
body {
background-color: #f5f5f5;
}
h1, h3{
text-align: center;
text-transform: uppercase;
font-weight: normal;
}
/*---*/
.tabs1{
display: block;
margin: auto;
}
.tabs1 .head{
text-align: center;
float: top;
padding: 0px;
text-transform: uppercase;
font-weight: normal;
display: block;
background: #81bef7;
color: #DF0101;
font-size: 30px;
}
.tabs1 .identi {
font-size: 10px;
text-align: center;
float: top;
padding: 15px;
display: block;
background: #81bef7;
color: #DFDFDF;
}
.tabs .content {
background: #f5f5f5;
/*text-align: center;*/
color: #000000;
padding: 25px 15px;
font-size: 15px;
font-weight: 400;
line-height: 20px; }
.tabs .content a {
color: #df0130;
font-size: 23px;
font-style: italic;
text-decoration: none;
line-height: 35px; }
.tabs .content .text{
padding: 25px;
line-height: 1.2;
}
</style>
<body>
<div class="tabs1">
<div class="head" ><b>Your personal ID:</b></div>
<div class="identi">
<span style="width:1000px; color: #ffffff; font-size: 10px;">[snip]</span> <br>
<!-- !!! dont changing this !!! -->
</div>
</div>
<!-- -->
<div class="tabs">
<!--tab-->
<div class="tab">
<div id="tab-content1" class="content">
<div class="text">
<!--text data -->
<b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br>
<b>All your important files have been encrypted!</b><br><br>
<hr>
Your files are safe! Only modified. (RSA+AES)<br><br>
ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br>
WILL PERMANENTLY CORRUPT IT.<br>
DO NOT MODIFY ENCRYPTED FILES.<br>
DO NOT RENAME ENCRYPTED FILES.<br><br>
No software available on internet can help you. We are the only ones able to<br>
solve your problem.<br><br>
We gathered highly confidential/personal data. These data are currently stored on<br>
a private server. This server will be immediately destroyed after your payment.<br>
If you decide to not pay, we will release your data to public or re-seller.<br>
So you can expect your data to be publicly available in the near future..<br><br>
We only seek money and our goal is not to damage your reputation or prevent<br>
your business from running.<br><br>
You will can send us 2-3 non-important files and we will decrypt it for free<br>
to prove we are able to give your files back.<br><br>
<!--text data -->
<hr>
<b>Contact us for price and get decryption software.</b><br><br>
<a>qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion</a><br>
* Note that this server is available via Tor browser only<br><br>
Follow the instructions to open the link:<br>
1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br>
2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br>
3. Now you have Tor browser. In the Tor Browser open <a>qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion<br>
</a>
4. Start a chat and follow the further instructions. <br>
<hr>
<b>If you can not use the above link, use the email:</b><br>
<a href="[email protected] ">[email protected] </a> <br>
<a href="[email protected] ">[email protected] </a> <br>
<p>* To contact us, create a new free email account on the site: <a href="https://protonmail.com">protonmail.com <br>
<b>
IF YOU DON'T CONTACT US WITHIN 72 HOURS, PRICE WILL BE HIGHER.</b><br>
</div>
</div>
</div>
<!--tab-->
<!--text data -->
</div>
</div>
<!--tab-->
</div>
</div>
</body>
</html>
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (107)
Search, filter and paginate the victim timeline for Medusalocker. Showing 1–100 of 107.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Lawter id32375 View details | United States | IT | ||
|
lawter.com operates within the US IT sector and is cataloged as a ransomware victim in the threat-intelligence index. The entity is associated with medusalocker, a threat actor identified in cyber threat intelligence records. This listing type indicates that lawter.com was recognized as a victim of ransomware activity linked to medusalocker within the indexed dataset. The description remains neutral and avoids speculative claims regarding breach details, data exposure, or operational impact. lawter.com serves as a reference point for monitoring ransomware incidents, threat actor attribution, and sector-specific cybersecurity exposure in the US IT environment. It was listed as a ransomware victim associated with medusalocker. |
|||||
| Ransomware | Lawter id32375 View details | United States | IT | ||
|
Organization with 150 emails extracted. Domain: lawter.com |
|||||
| Ransomware | Jgsee id32180 View details | Thailand | Education | ||
|
jgsee.kmutt.ac.th is a domain identifier associated with an institution operating within the Education sector located in Thailand. The domain corresponds to an academic and institutional context at Kmutt, reflecting its role within regional educational infrastructure. In the threat-intelligence index, this entity is cataloged specifically as a ransomware victim linked to the medusalocker threat actor. The listing type highlights the cybersecurity impact experienced by this organization, contextualized within broader threat actor activity targeting educational and academic environments. This entry documents the entity's association with medusalocker without detailing unverified incident specifics. |
|||||
| Ransomware | Jgsee id32180 View details | Thailand | Education | ||
|
Organization with 4 emails extracted. Domain: jgsee.kmutt.ac.th |
|||||
| Ransomware | Servifruit id32181 View details | Mexico | Agriculture / Food | ||
|
servifruit.com operates within the Agriculture and Food sector and is associated with the country Mexico. The entity represents a business organization targeted within the threat-intelligence index under the ransomware victim classification. This listing correlates the organization with medusalocker, a threat actor identified in cyber threat intelligence records. The catalog entry documents the association neutrally without disclosing unverified incident details such as data stolen, ransom demands, or specific breach timelines. The designation serves to inform threat analysts, security practitioners, and sector-specific monitoring frameworks about this ransomware victim instance tied to medusalocker activity in the agricultural and food supply context. |
|||||
| Ransomware | Servifruit id32181 View details | Mexico | Agriculture / Food | ||
|
Organization with 195 emails extracted. Domain: servifruit.com |
|||||
| Ransomware | Hungry Lion id32182 View details | Ghana | — | ||
|
Hungry Lion is cataloged as a ransomware victim entity operating within the technology and digital services sector, with operational context tied to Ghana (GH). The entity represents organizations or infrastructure impacted by medusalocker activity, a threat actor associated with medusalocker ransomware campaigns. This listing type highlights its role within the threat-intelligence index as a documented victim profile relevant to threat actor tracking and sector-based risk assessment. The description maintains neutrality, focusing on classification, associated threat actor, geographic context, and sector alignment without speculating on unverified incident details. |
|||||
| Ransomware | Hungry Lion id32182 View details | Ghana | — | ||
|
Fast food franchise (burgers, chicken, chips, ice cream) - 111 locations across South Africa, Botswana, Namibia, Zambia, Zimbabwe, Lesotho, Mauritius. Three POS systems: Unity POS (242MB monthly), GAAP POS (daily), CoSoft POS (145 terminals). | Botswana |
|||||
| Ransomware | Qualisteel id32183 View details | United States | IT | ||
|
Qualisteel.com operates within the IT sector and serves as a technology-focused entity located in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically linked to the medusalocker threat actor. This designation reflects its inclusion within records documenting cybersecurity incidents and associated adversary activity. The description remains neutral and factual, focusing on the entity's sector, geographic context, and verified association with medusalocker without elaborating on unconfirmed incident details. Such indexing supports threat-resilience efforts by mapping affected organizations to active threat actors for defensive intelligence. |
|||||
| Ransomware | Qualisteel id32183 View details | United States | IT | ||
|
Organization with 7568 emails extracted. Domain: qualisteel.com |
|||||
| Ransomware | Health id32184 View details | Australia | Public Sector | ||
|
health.nsw.gov.au is the official web presence of New South Wales public health services, supporting healthcare administration, citizen information, and sector-wide health governance within Australia. The entity operates within the Public Sector, providing digital services and resources aligned with state health infrastructure and government accountability functions. In the threat-intelligence index, this listing identifies health.nsw.gov.au as a ransomware victim associated with medusalocker, a threat actor documented in cyber threat reporting. This designation reflects inclusion in ransomware victim records tied to medusalocker activity in the Australian context. The description remains factual and neutral, focusing on the entity’s sector role and its indexed association without asserting unconfirmed breach details. |
|||||
| Ransomware | Health id32184 View details | Australia | Public Sector | ||
|
Organization with 103 emails extracted. Domain: health.nsw.gov.au |
|||||
| Ransomware | Twal Family IT Lab id31769 View details | — | |||
|
Personal IT home lab. AD domain: twalfamily.com. VMware vSphere, multiple AD domains. Daniel Al Twal works at Technology North Corp (Edmonton), former DND co-op. No corporate target. Previously misidentified as Forces/forces.gc.ca. | 4172 Wolfe Point Way, Ottawa, ON K1V 1P5, Canada |
|||||
| Ransomware | All Parts Dry Cleaning id31770 View details | United Kingdom | — | ||
|
Dry cleaning & laundry. Domain: allpartsdrycleaning.co.uk. | United Kingdom |
|||||
| Ransomware | Idex Group id31771 View details | Germany | — | ||
|
Organization with 30 emails extracted. Domain: idex-group.com |
|||||
| Ransomware | Bija Industrie id31772 View details | France | — | ||
|
Organization with 693 emails extracted. Domain: bija-industrie.com |
|||||
| Ransomware | Thecourierguy id31773 View details | South Africa | — | ||
|
Organization with 2018 emails extracted. Domain: thecourierguy.co.za |
|||||
| Ransomware | Forces id30308 View details | Canada | Public Sector | ||
|
Forces.gc.ca is the official website of the Canadian Armed Forces, providing information on the military's role, operations, and services in Canada. The Canadian Armed Forces operate within the public sector, offering various services and support to the country. Forces.gc.ca was listed as a ransomware victim associated with MedusaLocker. |
|||||
| Ransomware | Forces id30308 View details | Canada | Public Sector | ||
|
Organization with 28 emails extracted. Domain: ***.gc.ca |
|||||
| Ransomware | Estrela id30168 View details | Brazil | Agriculture / Food | ||
|
Estrela.ind is a company based in Brazil, operating in the agriculture and food sector. The company likely provides products or services related to food production or distribution. Estrela.ind was listed as a ransomware victim associated with MedusaLocker. |
|||||
| Ransomware | Estrela id30168 View details | Brazil | Agriculture / Food | ||
|
Organization with 11 emails extracted. Domain: estrela.ind |
|||||
| Ransomware | Karneslegal id30169 View details | United States | Finance / Legal / Insurance | ||
|
Karneslegal.com is a US-based company operating in the finance and legal sector, offering services to clients. The company is located in the United States and provides legal and financial expertise to its customers. Karneslegal.com was listed as a ransomware victim associated with MedusaLocker |
|||||
| Ransomware | Karneslegal id30169 View details | United States | Finance / Legal / Insurance | ||
|
Organization with 23 emails extracted. Domain: karneslegal.com |
|||||
| Ransomware | Sgs Gmbh id30170 View details | Germany | Manufacturing / Engineering | ||
|
SGS-GmbH is a German company operating in the manufacturing and engineering sector, providing various services and solutions to its clients. The company is based in Germany and offers a range of products and services related to its sector. SGS-GmbH was listed as a ransomware victim associated with MedusaLocker. |
|||||
| Ransomware | Sgs Gmbh id30170 View details | Germany | Manufacturing / Engineering | ||
|
Organization with 933 emails extracted. Domain: sgs-gmbh.com |
|||||
| Ransomware | Dadolighting id30171 View details | United States | Manufacturing / Engineering | ||
|
Dadolighting.com is a company operating in the manufacturing and engineering sector, based in the United States. The company likely provides various products and services related to lighting solutions, given its name. Dadolighting.com is involved in the production and distribution of lighting products, catering to different industries. It was listed as a ransomware victim associated with MedusaLocker |
|||||
| Ransomware | Dadolighting id30171 View details | United States | Manufacturing / Engineering | ||
|
Organization with 17 emails extracted. Domain: dadolighting.com |
|||||
| Ransomware | T Online id30172 View details | Germany | Telecommunications | ||
|
T-online.de is a German telecommunications company that provides internet and telephone services to individuals and businesses in Germany. The company operates in the telecommunications sector, offering a range of services including broadband internet, mobile phone plans, and television packages. T-online.de is a well-established brand in Germany, providing essential services to millions of customers. It was listed as a ransomware victim associated with medusalocker |
|||||
| Ransomware | T Online id30172 View details | Germany | Telecommunications | ||
|
Organization with 823 emails extracted. Domain: t-online.de |
|||||
| Ransomware | FunkeScheid id30173 View details | Germany | IT | ||
|
FunkeScheid.com is an IT company based in Germany, providing various IT services. The company operates in the IT sector, offering its services to clients in the region. FunkeScheid.com was listed as a ransomware victim associated with medusalocker |
|||||
| Ransomware | FunkeScheid id30173 View details | Germany | IT | ||
|
Notarkanzlei FunkeScheid, Kanzlei im Ostend, Frankfurt. 9755 emails. AD: Kanzlei.FunkeScheid.com |
|||||
| Ransomware | Mairie Thiverval Grignon id30174 View details | France | Public Sector | ||
|
Mairie Thiverval Grignon is a local government office in France, providing various public services to its community. As a public sector entity, it plays a vital role in the administration and governance of the local area. Mairie Thiverval Grignon is listed as a ransomware victim associated with MedusaLocker |
|||||
| Ransomware | Mairie Thiverval Grignon id30174 View details | France | Public Sector | ||
|
Organization with 162 emails extracted. Domain: mairie-thiverval-grignon.fr |
|||||
| Ransomware | Dolrad id30175 View details | United Arab Emirates | Construction / Real Estate | ||
|
Dolrad ae operates in the construction and real estate sector in the United Arab Emirates, providing various services to clients. The company is involved in development and management of properties. Dolrad ae was listed as a ransomware victim associated with MedusaLocker |
|||||
| Ransomware | Dolrad id30175 View details | United Arab Emirates | Construction / Real Estate | ||
|
Organization with 69 emails extracted. Domain: dolrad.ae |
|||||
| Ransomware | Bd id30176 View details | Switzerland | Public Sector | ||
|
The Building Department of the Canton of Zurich, bd.zh.ch, is a public sector entity responsible for construction and infrastructure projects in the Canton of Zurich, Switzerland. It provides various services related to building permits, construction supervision, and urban planning. bd.zh.ch was listed as a ransomware victim associated with medusalocker |
|||||
| Ransomware | Bd id30176 View details | Switzerland | Public Sector | ||
|
Organization with 772 emails extracted. Domain: bd.zh.ch |
|||||
| Ransomware | Penticton and District Society for Community Living id30177 View details | Canada | IT | ||
|
pdscl.org operates within the IT sector in Canada, providing various services. The organization is involved in activities related to its sector. pdscl.org was listed as a ransomware victim associated with medusalocker |
|||||
| Ransomware | Penticton and District Society for Community Living id30177 View details | Canada | IT | ||
|
Canadian charity providing disability-related services. CRA Registration: 119090686RR0001 | Penticton, British Columbia, Canada |
|||||
| Ransomware | Elken Sdn Bhd id29024 View details | Malaysia | Retail / E-commerce | ||
|
MLM / health & beauty products company. ~16k emails extracted. |
|||||
| Ransomware | Bandeirante Supermercados id29025 View details | Brazil | Retail / E-commerce | ||
|
Brazilian supermarket chain. |
|||||
| Ransomware | Strategic Imports id29026 View details | Australia | Manufacturing / Engineering | ||
|
Australian auto parts/batteries importer. Brands: Strategic Imports, Auto Parts Now, Discount Batteries Now. User: bstuart (Brad Stuart). QNAP NAS (CACHEDEV1_DATA). |
|||||
| Ransomware | Magnolia (Israel) id29027 View details | Israel | Manufacturing / Engineering | ||
|
Israeli jewelry company. Silver & accessories, participates in Vicenza jewelry fair (2025/2026). Sells via buyme.co.il gift cards. ~38k files, invoices in Hebrew (SI/IN/OV prefix). |
|||||
| Ransomware | Trimble Inc / Gerrard Inc id29028 View details | United States | IT | ||
|
Technology company Trimble (trimble.com) and Gerrard Inc (gerrardinc.com). ~18 Trimble email addresses. |
|||||
| Ransomware | Atencio Engineering id29029 View details | United States | Construction / Real Estate | ||
|
Civil engineering & land surveying firm. Services: site plans, boundary surveys, OWTS (septic) design, fire line design, elevation certificates, flood plain analysis. Clients in Las Animas County, Pueblo County, Florence CO area. |
|||||
| Ransomware | SIT Group / Robusta id29030 View details | Italy | Other | ||
|
Italian company SIT Group (sitgroup.it) and Bulgarian Robusta (robusta.bg). Also abv.bg emails. |
|||||
| Ransomware | Desert Christian Schools (DCS) id29031 View details | United States | Public Sector | ||
|
K-12 Christian school affiliated with First Baptist Church of Lancaster, CA. ADP payroll, DCFS childcare program, City of Lancaster Water Safety program. Financial docs: P&L, Balance Sheet, Trial Balance, 1099s. School Board minutes 2025. |
|||||
| Ransomware | CourtSmart id29032 View details | United States | IT | ||
|
Court technology company. Domain courtsmart.com / COURTSMART2. Dev server: dev-rich20.courtsmart.com. Connections to JIS.org, nashville.org. |
|||||
| Ransomware | Hathcock (Personal) id29033 View details | Other | |||
|
Personal comprehensive reports. Individuals: Noel Ray Hathcock, Trinity John Hathcock. |
|||||
| Ransomware | ActionAid / TACOSA id29034 View details | United Kingdom | NGOs / Associations | ||
|
NGO sector. Domains: actionaid.org, tacosa.org.za, immigration.go.tz. |
|||||
| Ransomware | Palmers Relocations id29035 View details | United Kingdom | Services | ||
|
Australian international removals & relocation company. FIDI accredited, ISO 9001:2015 certified. Services: household moves, storage, customs, immigration (IMMI/VEVO). Operates Melbourne area (Pascoe Vale, Dandenong, Caulfield). |
|||||
| Ransomware | Académie de Montpellier / CSJM id29036 View details | France | Education | ||
|
French public school network. Domain CSJM.BEZIERS, part of Académie de Montpellier (ac-montpellier.fr). Occitanie region (laregion.fr). Teacher and admin staff credentials. |
|||||
| Ransomware | Colegio María Inmaculada (CMI) id29037 View details | Costa Rica | Education | ||
|
Catholic school in Moravia, Costa Rica. Domain cmi.local / mariainmaculada.ed.cr. Servers: CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2. |
|||||
| Ransomware | CEAGESP / Netfeirasp id29038 View details | Brazil | Retail / E-commerce | ||
|
Brazilian produce wholesale market network. Domain netfeirasp.ceagesp (CEAGESP). Also demarchibrasil.com.br accounts. |
|||||
| Ransomware | Raycolighting id29039 View details | United Kingdom | Other | ||
|
Organization with 2 emails extracted. Domain: raycolighting.com |
|||||
| Ransomware | dulay.ca id23957 View details | Canada | Communication / Marketing | ||
|
Price-$40000 (sale in one hand there are options for making a profit from these files will be included in the deal) 500Gb |
|||||
| Ransomware | usenergy id22359 View details | United States | Energy | ||
|
Price-$120000 (sale in one hand there are options for making a profit from these files will be included in the deal) |
|||||
| Ransomware | Looking for pentesters id21590 View details | Other | |||
|
Looking for pentesters is an Other-sector listing identified in threat-intelligence coverage as a MedusaLocker target. Public reporting describes MedusaLocker as a ransomware group that posted a recruitment-style notice on its leak site seeking pentesters with direct access to corporate networks, including environments such as ESXi, Windows, and ARM systems. The available reporting does not establish a formal corporate profile, offering set, or geographic location for this entity beyond the listing context. It was listed as a ransomware victim associated with medusalocker. |
|||||
| Ransomware | UnigazJordan id20337 View details | Jordan | Other | ||
|
www.unigaz.net $690.6 Million The list of files is available at the link https://dropmefiles.com/9HGAJ |
|||||
| Ransomware | Mulia Raya id20305 View details | Indonesia | Other | ||
|
www.muliaraya.co.id $34.8 Million The list of files is available at the link https://dropmefiles.com/lAZQo |
|||||
| Ransomware | Curtain Bluff id18702 View details | Antigua and Barbuda | Finance / Legal / Insurance | ||
|
www.curtainbluff.com Curtain Bluff files Vacationer information (personal data), audit information (including past years), bank activity (statements with all transactions), internal organization documentation (even the menu) and other documents.There are also large amounts of account data (about 500 unique login/password pairs). Price – $120,000 |
|||||
| Ransomware | Inversiones Clinica Del Meta SA id18092 View details | Colombia | Healthcare / Pharma | ||
|
www.clinicameta.co Description employee information – patient information – agreements – password data – appointment information Sold with 1-day access Price-$100000 (sale in one hand there are options for making a profit from these files will be included in the deal) |
|||||
| Ransomware | MICRO MANUFACTRING id17454 View details | United States | Communication / Marketing | ||
|
Micro Manufacturing Inc. Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files. password data\\ Sold with 1-day access Price-$120000 (sale in one hand there are options for making a profit from these files will be included in the deal |
|||||
| Ransomware | bendixengineering id16545 View details | United States | Manufacturing / Engineering | ||
|
Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files Data-2016-2024 years Price-$50000 (sale in one hand there are options for making a profit from these files will be included in the deal |
|||||
| Ransomware | SILKNET COMPANY id15662 View details | United States | Finance / Legal / Insurance | ||
|
URL:https://silknet.com https://geocell.ge/ On sale:Company email base(about 1tb)Customer dataCompany audit for 2023\24and more than 3tb of data. Price-$800000 There are a lot of corporate data, passports and other information. |
|||||
| Ransomware | Protected: HIDE NAME id12401 View details | Communication / Marketing | |||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | SHAMASS.ORG id12239 View details | United States | Communication / Marketing | ||
|
Descriptionemployee information – agreement – customer email(.xls)-.msg outlook files Price-$50000 (sale in one hand there are options for making a profit from these files will be included in the deal) |
|||||
| Ransomware | Protected: HIDE NAME SELL DATA SOON id12147 View details | Communication / Marketing | |||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | Protected: Name is hidden id9793 View details | Communication / Marketing | |||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | skalar.com id9786 View details | Communication / Marketing | |||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | Ada-Borup-West School id9182 View details | Education | |||
|
Descriptionemployee information – student information – all contracts Price: 35000$ |
|||||
| Ransomware | wellons.org id9181 View details | Communication / Marketing | |||
|
Descriptionemployee information – agreement – customer email(.xls)- pst files 15+GB all outlook message 2006-2023 year Price: 55000$ |
|||||
| Ransomware | Confidential files id8933 View details | Finance / Legal / Insurance | |||
|
A large number of documents of large companies are available for sale Revenue-$10-$70kk Financial documents, client cases, passports, tax evasion and many other documents are in closed sale, please contact qtox to coordinate the sale |
|||||
| Ransomware | INSULCANA CONTRACTING LTD id8032 View details | Communication / Marketing | |||
|
Descriptionemployee information – agreement – customer email(.xls)- passport all canada and other documents Price: 35000$ |
|||||
| Ransomware | Protected: INSULCANA CONTRACTING LTD id7950 View details | Communication / Marketing | |||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | Protected: Hidden name id7335 View details | Communication / Marketing | |||
|
There is no excerpt because this is a protected post. |
|||||
| Ransomware | Hoosier Equipment company id7114 View details | Communication / Marketing | |||
|
DescriptionClient Case – agreement – email(.msg)- and other documents Price: 60000$ |
|||||
| Ransomware | Ucamco Belgium id7100 View details | Finance / Legal / Insurance | |||
|
DescriptionClient Case – customers email-Audit information-There is also access to email for newsletters on behalf of the company PRICE-$80000 |
|||||
| Ransomware | reutlingen.ihk.de id7011 View details | Germany | Communication / Marketing | ||
|
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents PRICE-$80000 |
|||||
| Ransomware | Hausamman company id7010 View details | Communication / Marketing | |||
|
DescriptionClient Case – customers email-documents PRICE-$20000 |
|||||
| Ransomware | kafflogistic.hu id7009 View details | Hungary | Communication / Marketing | ||
|
DescriptionClient Case – agreement – email(outlook files)- contracts – and other documents PRICE-$50000 |
|||||
| Ransomware | SELL DATA(qtox) id7008 View details | Communication / Marketing | |||
|
Available for sale: to buy please contact qtox price negotiable qtox-E9CD65687463F67F64937E961DD723DC82C79CB548375AAE8AA4A0698D356C5E7E157B22E8CD |
|||||
| Ransomware | Jalux Americas, Inc. id6855 View details | Communication / Marketing | |||
|
DescriptionClient Case – agreement – email(.msg) – and other documents Price: 160000$The company failed to take care of the data leak and therefore ,many contracts and other documents have been leaked to the Internet.We are also going to provide any documents related to the aforementioned company if any law enforcement agency should request it |
|||||
| Ransomware | arborsct.com id6854 View details | Finance / Legal / Insurance | |||
|
DescriptionClient Case – agreement – email(.msg)- and other documents Price: 60000$ One copy will be sold, confidential informationThe company did not take care of the data leak, and therefore we will sell many contracts, customer data, financial component and other documentsin one lot for $ 60,000 for verification in the darknet or bank |
|||||
| Ransomware | Salmon Software id6720 View details | IT | |||
|
DescriptionClient Case – agreement – email(.msg)- passport- and other documents Price: 120000$ Three copies will be sold, confidential informationThe company failed to take care of the data leak and therefore ,many contracts and other documents have been leaked to the Internet.Other: contracts, agreements and other bank checks, we will sell everything in one lot for… Continue reading Salmon Software |
|||||
| Ransomware | LETAPE JEUNES id6719 View details | Communication / Marketing | |||
|
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents(passports) PRICE-$40000 |
|||||
| Ransomware | bsw-architects.com id6080 View details | Communication / Marketing | |||
|
DescriptionClient Case – agreement – email(.msg)- contracts – and other documents PRICE-$80000 There are many projects, agreements and contracts that can be sold separately |
|||||
| Ransomware | DGLEGAL id4602 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | emscrm id4601 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MIDAS Company id4600 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AURIS KONINKLIJKE AURIS GROEP id4599 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | fidelityunited.ae id4598 View details | United Arab Emirates | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | goldcreekfoods id4597 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | exheat.com id4596 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | hwrpc.com id4595 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | tristatefabricators_inc id4593 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | atlantisholidays id4592 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | archimages inc id4591 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ALTlTUDE AEROSPACE INC id4590 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Fonderia Boccacci id4589 View details | Other | — | ||
|
No additional victim description available. |
|||||