Ransomware Group intelligence
Meow
InactiveTrack Meow with 145 published victims and 2 known leak locations in a single intelligence view.
Overview
Meow is tracked by Breach House as a ransomware group with 145 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | meow6xanhzfci2gbkn3lmbqq7xjjufskkdfocqdngt3ltvzgqpsg5mid.onion |
| Leak location 2 | Onion service | Down checked 2h ago | totos7fquprkecvcsl2jwy72v32glgkp2ejeqlnx5ynnxvbebgnletqd.onion |
Top Activity Sectors (15)
- Communication / Marketing 34
- Not identified 24
- Services 23
- Finance / Legal / Insurance 18
- Healthcare / Pharma 10
- Manufacturing / Engineering 6
- Hospitality / Food & Beverage / Tourism 5
- Agriculture / Food 5
- Education 4
- Construction / Real Estate 4
- Energy 4
- Public Sector 3
- IT 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Meow, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: meow executes PowerShell scripts to stage payloads and perform initial reconnaissance across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: meow leverages registry run keys to maintain persistence across reboots on infected endpoints.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: meow disables antivirus tools and modifies security software configurations to evade detection during execution.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: meow encrypts and encodes victim files with custom symmetric cryptography before demanding payment.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: meow deletes Volume Shadow Copies and backup directories via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: meow accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: meow scans network shares using native tools to identify victim directories and expand lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: meow uses SMB/Windows Admin Shares to propagate ransomware binaries across networked servers.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: meow encrypts victim files using custom ransomware binaries targeting communication and marketing data sectors.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: meow displays internal defacement messages and ransom notes on victim systems to pressure recovery.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (145)
Search, filter and paginate the victim timeline for Meow. Showing 101–145 of 145.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Premier Equities id13664 View details | United States | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Texas Tech University id13570 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | Global Industry Analysts id13569 View details | United States | Services | ||
|
669 |
|||||
| Ransomware | Encore id13568 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Daikin id13567 View details | Japan | Other | ||
|
692 |
|||||
| Ransomware | Miami Gardens Florida id13566 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Nuclep id13565 View details | Brazil | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Andersen Tax id13564 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | The Physical Medicine Rehabilitation Center id13563 View details | United States | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Villarreal and Begum Law Firm id13562 View details | United States | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | Greenheck id13393 View details | Other | |||
|
9000$ |
|||||
| Ransomware | CBIZ Inc id13392 View details | United States | Services | ||
|
6999$ |
|||||
| Ransomware | Hewlett Packard Enterprise id13391 View details | Communication / Marketing | |||
|
199$ |
|||||
| Ransomware | BCS Systems id13390 View details | Services | |||
|
2000$ |
|||||
| Ransomware | Guhring id13389 View details | Other | |||
|
10000$ |
|||||
| Ransomware | Odfjell Drilling id13388 View details | Other | |||
|
3000$ |
|||||
| Ransomware | Golan Christie Taglia id13387 View details | Other | |||
|
500$ |
|||||
| Ransomware | First Commonwealth Federal Credit Union id13386 View details | Finance / Legal / Insurance | |||
|
100000$ |
|||||
| Ransomware | CBIZ, Inc id13106 View details | United States | Services | ||
|
SALE |
|||||
| Ransomware | Greenheck Fan id13105 View details | United States | Other | ||
|
SALE |
|||||
| Ransomware | GE Aerospace id12633 View details | United States | Transportation / Travel / Logistics | ||
|
SALE |
|||||
| Ransomware | Biomedical Research Institute id11111 View details | United States | Healthcare / Pharma | ||
|
SALE |
|||||
| Ransomware | Future Generations Foundation id11099 View details | Canada | NGOs / Associations | ||
|
SALE |
|||||
| Ransomware | River Delta Unified School District id10913 View details | United States | Education | ||
|
FREE |
|||||
| Ransomware | Disaronno International id10791 View details | Italy | Services | ||
|
SALE |
|||||
| Ransomware | Allmetal Inc. id10790 View details | United States | Manufacturing / Engineering | ||
|
SALE |
|||||
| Ransomware | Freedom Munitions id10789 View details | United States | Other | ||
|
SALE |
|||||
| Ransomware | Arlington Perinatal Associates id10788 View details | United States | Other | ||
|
FREE |
|||||
| Ransomware | Southwark Council id10636 View details | United Kingdom | Public Sector | ||
|
PREVIEW |
|||||
| Ransomware | Winona Pattern & Mold id10545 View details | United States | Other | ||
|
SALE |
|||||
| Ransomware | Lake of the Woods County id10313 View details | United States | Public Sector | ||
|
PREVIEW |
|||||
| Ransomware | Bladen County Public Library id10233 View details | Public Sector | |||
|
SALE |
|||||
| Ransomware | RCSB PDB id10187 View details | Communication / Marketing | |||
|
PREVIEW |
|||||
| Ransomware | Tulane University id10000 View details | Education | |||
|
PREVIEW |
|||||
| Ransomware | Memorial Sloan Kettering Cancer Center id9975 View details | Communication / Marketing | |||
|
PREVIEW |
|||||
| Ransomware | Agamatrix id9809 View details | Communication / Marketing | |||
|
PREVIEW |
|||||
| Ransomware | Katsky Korins id9715 View details | Communication / Marketing | |||
|
PREVIEW |
|||||
| Ransomware | Giti id9694 View details | Other | |||
|
100% leaked |
|||||
| Ransomware | WemaBank id9693 View details | Finance / Legal / Insurance | |||
|
Preview |
|||||
| Ransomware | Es Saadi id9692 View details | Other | |||
|
100% LEAKED |
|||||
| Ransomware | Zenithpharma id9691 View details | Healthcare / Pharma | |||
|
15% LEAKED |
|||||
| Ransomware | Back Roads id9690 View details | Other | |||
|
1% LEAKED |
|||||
| Ransomware | Equaldex id9689 View details | Other | |||
|
100% LEAKED |
|||||
| Ransomware | Vanderbilt University Medical Center id9688 View details | Healthcare / Pharma | |||
|
100% LEAKED |
|||||
| Ransomware | Standard Filter id9687 View details | Communication / Marketing | |||
|
PREVIEW |
|||||