Ransomware Group intelligence
Moneymessage
ActiveTrack Moneymessage with 41 published victims and 1 known leak locations in a single intelligence view.
Overview
Moneymessage is tracked by Breach House as a ransomware group with 41 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | blogvl7tjyjvsfthobttze52w36wwiz34hrfcmorgvdzb6hikucb7aqd.onion |
Top Activity Sectors (10)
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Moneymessage, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: moneymessage executes malicious payloads using PowerShell scripts to stage ransomware operations on compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: moneymessage modifies Windows Registry Run Keys to ensure ransomware execution persists across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: moneymessage disables security tools like antivirus software to prevent detection and hinder incident response efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: moneymessage deletes Volume Shadow Copies and backup files via command-line tools to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: moneymessage accesses LSASS memory to steal credentials for privilege escalation and lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: moneymessage scans network shares to identify victim file directories for selective encryption and impact.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: moneymessage uses SMB/Windows Admin Shares for lateral movement between networked systems within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: moneymessage exfiltrates stolen victim data via encrypted C2 channels before deploying ransomware for double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: moneymessage encrypts victim files using strong symmetric cryptography to maximize ransomware impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
money_message.log
Your files was stolen by "Money message" profitable organization. Dear managers and founders of the company! Your business uses the possibilities of modern information technologies for its own brand and business reputation, which results in an increase in sales of insurance services and the attraction of both new and existing customers. Our specialists found that your company did not have sufficient protection against the leakage of personal data. You have neglected the trust of your customers and the laws of the United States, which regulate the full protection of personal data and confidential information of clients. To run your business, you need to build the right security system. We have found flaws in your defense, so we offer you, relatively for a certain amount, to resolve your issue and preserve your reputation. So, how much data we have? More than 500Gb. Starting with office documents and ending with open and closed cases. All data is in our storage. You can get it as soon as we make a common decision in the chat. Referring to US law, we can say that you will suffer large losses due to leaks of personal information, such as SSN(social security number), client’s place of registration, driver license, phone number, email and many others.We received this information from your servers .You can find out how much personal information we have by communicating with us via Tor, the link will be provided. In case you refuse to pay, we will post the files we stole from your internal network, in our blog: http://blogvl7tjyjvsfthobttze52w36wwiz34hrfcmorgvdzb6hikucb7aqd.onion If you think that only your documents were leaked, then you are mistaken, we also found documents from your employees from other companies, signed by other employees. We can give an example of a case where a company did not take care of an information leak and suffered losses due to lawsuits -https://www.cybertalk.org/hospital-faces-class-action-lawsuit-over-cyber-attack/ -https://www.insurancejournal.com/news/east/2024/01/23/756814.htm For further negotiations open this xuutya4qc5zxpz2pgl3zpfnzr6memzf7g62k4koc7fktn4ekzcebssid.onion/chat.php?chatId=[snip] using tor browser https://www.torproject.org/download/
money_message.txt
Your files was encrypted by "Money message" profitable organization and can't be accessed anymore. If you pay ransom, you will get a decryptor to decrypt them. Don't try to decrypt files yourself - in that case they will be damaged and unrecoverable. For further negotiations open this clientcuworpelkdwecucgvfhp5uz5n7uohsnokndrlhm2zkntyg3had.onion/chat.php?chatId=[snip] using tor browser https://www.torproject.org/download/ In case you refuse to pay, we will post the files we stole from your internal network, in our blog: blogvl7tjyjvsfthobttze52w36wwiz34hrfcmorgvdzb6hikucb7aqd.onion Encrypted files can't be decrypted without our decryption software.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (41)
Search, filter and paginate the victim timeline for Moneymessage. Showing 1–41 of 41.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ProCare id32228 View details | United States | Healthcare / Pharma | ||
|
ProCare operates within the United States healthcare and medicine sector, providing clinical services and patient-related solutions. As a ransomware victim, ProCare is documented within the threat-intelligence index under association with the moneymessage threat actor. This listing type identifies ProCare as a target of ransomware activity within its operational domain. The entry reflects the cybersecurity context surrounding this entity without disclosing unverified incident details, operational impacts, or confirmed breach specifics. ProCare remains cataloged for threat-awareness purposes across healthcare threat landscapes. |
|||||
| Ransomware | ProCare id32228 View details | United States | Healthcare / Pharma | ||
|
[AI generated] N/A ProCare is a relatively common business name used by multiple unrelated companies across different industries and countries. Without additional context such as industry sector, country, or full legal name, it is not possible to identify a specific organization with confidence and provide accurate threat intelligence relevant information. |
|||||
| Ransomware | Yourway Transportation id30840 View details | United States | Transportation / Travel / Logistics | — | |
|
Yourway Transportation is a company operating in the transportation sector in the United States, providing logistics and travel services. The company's offerings cater to various needs within the industry. Yourway Transportation was listed as a ransomware victim associated with moneymessage. |
|||||
| Ransomware | Yourway Transportation id30840 View details | United States | Transportation / Travel / Logistics | — | |
|
[AI generated] Yourway Transportation is a US-based specialty transportation and logistics company operating primarily in the pharmaceutical and life sciences industries. It provides temperature-controlled, time-sensitive courier and freight services, ensuring compliant transport of clinical trial materials, biological samples, and sensitive cargo. The company serves biotech, pharmaceutical, and healthcare clients across North America and globally. |
|||||
| Ransomware | Indigo Energy id30763 View details | Canada | Energy | ||
|
Indigo Energy operates in the energy sector in Canada, providing various energy-related services. As a company in this sector, it plays a crucial role in the country's energy infrastructure. Indigo Energy was listed as a ransomware victim associated with moneymessage. |
|||||
| Ransomware | Indigo Energy id30763 View details | United States | Energy | ||
|
[AI generated] N/A |
|||||
| Ransomware | Envision Unlimited id30382 View details | United States | Healthcare / Pharma | ||
|
Envision Unlimited is a healthcare organization based in the United States, providing various medical services. As a part of the healthcare sector, Envision Unlimited plays a crucial role in delivering medical care to patients. Envision Unlimited was listed as a ransomware victim associated with moneymessage. |
|||||
| Ransomware | Envision Unlimited id30382 View details | United States | Healthcare / Pharma | ||
|
[AI generated] Envision Unlimited is a nonprofit human services organization based in the United States, primarily operating in Illinois. Founded in Chicago, it provides support services for individuals with intellectual and developmental disabilities. Its programs include residential services, day programs, employment support, and behavioral health services, aimed at promoting independence, inclusion, and quality of life for the people it serves. |
|||||
| Ransomware | X-Copper Professional id30223 View details | Other | |||
|
X-Copper Professional is a company that operates in the other sector. The company's specific location and offerings are not well-documented. X-Copper Professional was listed as a ransomware victim associated with moneymessage. |
|||||
| Ransomware | X-Copper Professional id30223 View details | Other | |||
|
[AI generated] X-Copper Professional is a Canadian legal and paralegal services firm specializing in traffic ticket defense and driving-related legal matters. Based in Ontario, Canada, the company represents clients facing speeding tickets, careless driving charges, and other Highway Traffic Act violations. It employs licensed paralegals and lawyers to help clients reduce or dismiss charges, minimizing fines, demerit points, and insurance premium impacts. |
|||||
| Ransomware | X-Copper Professional id30223 View details | United States | Other | ||
|
[AI generated] X-Copper Professional is a Canadian legal and paralegal services firm specializing in traffic ticket defense and driving-related legal matters. Based in Ontario, Canada, the company represents clients facing speeding tickets, careless driving charges, and other Highway Traffic Act violations. It employs licensed paralegals and lawyers to help clients reduce or dismiss charges, minimizing fines, demerit points, and insurance premium impacts. |
|||||
| Ransomware | Forestdale id29058 View details | United Kingdom | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Family Partnerships of Central Florida id25885 View details | United States | Services | ||
|
[AI generated] Family Partnerships of Central Florida is a non-profit organization that offers care for children with special needs. The services are aimed at enhancing the quality of life for children and their families by providing medical, emotional, educational, and social support services. They focus on early intervention and work directly with families to customize care plans for each child’s unique needs. |
|||||
| Ransomware | Bucks County Opportunity Council, INC. id21527 View details | United States | Public Sector | ||
|
[AI generated] The Bucks County Opportunity Council, Inc. (BCOC) is a non-profit organization in Pennsylvania, USA. It is devoted to empowering low-income families to achieve economic self-sufficiency through their various programs. BCOC provides services like food assistance, adult education, financial coaching, and housing services, and designs community strategies to help foster economic stability in the region. |
|||||
| Ransomware | Young Adjustment Company id21175 View details | United States | Communication / Marketing | ||
|
[AI generated] Young Adjustment Company is one of the leading independent insurance claims adjusters in the US. Established in 1927, the company offers comprehensive public adjusting services to businesses, homeowners, and governmental entities. Their professionals assist clients through the entire insurance claim process, ensuring the highest possible settlement. They handle claims related to property damage, fire, water damage, and more. |
|||||
| Ransomware | The Tech Interactive id19660 View details | United States | IT | ||
|
The Tech Interactive is a world class science and technology center in the heart of the Silicon Valley that welcomes over 250,000 visitors a year.Since opening in 1998, The Tech Interactive (formerly the Tech Museum of Innovation) has welcomed more than 10 million visitors. |
|||||
| Ransomware | Marina Family Medical id16710 View details | Australia | Healthcare / Pharma | ||
|
[AI generated] Marina Family Medical is a healthcare provider that offers a variety of medical services. Their team of professionals specialize in family medicine, ensuring they can offer health and wellness care for patients of all ages. From preventative care and diagnostics to treatment of chronic diseases, Marina Family Medical is dedicated to fostering wellness and improving the health of their patients. It is their mission to deliver high-quality, affordable care and they strive to make their patients feel like part of their family. |
|||||
| Ransomware | National Atomic Energy Commission id16187 View details | Argentina | Energy | ||
|
[AI generated] The National Atomic Energy Commission (CNEA) is an Argentine government agency responsible for the development and regulation of nuclear energy. Established in 1950, it focuses on research, development, and the peaceful use of nuclear technology. CNEA oversees nuclear power plants, medical applications, and scientific research, playing a key role in Argentina's energy and technological advancements. |
|||||
| Ransomware | Kazyon id16028 View details | Russian Federation | Communication / Marketing | ||
|
[AI generated] Kazyon is a prominent discount supermarket chain based in Egypt. Founded in 2014, it focuses on providing affordable grocery options to consumers. Kazyon operates numerous stores across the country, emphasizing cost-effective pricing and accessibility. The company aims to offer a wide range of products, including fresh produce, packaged goods, and household items, catering to diverse customer needs. |
|||||
| Ransomware | The Egyptian Tax Authority (ETA) id15363 View details | Egypt | Public Sector | ||
|
[AI generated] The Egyptian Tax Authority (ETA) is the governmental body responsible for tax administration in Egypt. It oversees the implementation and collection of various taxes, including income tax, corporate tax, and value-added tax (VAT). The ETA aims to enhance compliance, improve tax revenue, and support economic development through efficient tax policies and systems. It also works to modernize tax procedures and provide taxpayer services. |
|||||
| Ransomware | First Baptist Medical Center id13067 View details | United States | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Insurance Agency Marketing Services id12582 View details | United States | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Anna Jaques Hospital id10477 View details | United States | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Tri-Way Manufacturing Technologies id9059 View details | Manufacturing / Engineering | |||
|
No additional victim description available. |
|||||
| Ransomware | Toscana Promozione id8950 View details | Italy | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | MD LOGISTICS id8949 View details | Transportation / Travel / Logistics | |||
|
No additional victim description available. |
|||||
| Ransomware | Maxco Supply id8948 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Taylor University id8452 View details | Education | |||
|
No additional victim description available. |
|||||
| Ransomware | Riverside Logistics id8451 View details | Transportation / Travel / Logistics | |||
|
No additional victim description available. |
|||||
| Ransomware | Estes Design & Manufacturing id8450 View details | Manufacturing / Engineering | |||
|
No additional victim description available. |
|||||
| Ransomware | Aiphone id8449 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Propper International id7312 View details | Communication / Marketing | |||
|
Founded in 1967, Propper is a manufacturer of clothing and gear for tactical, law enforcement, public safety, and military applications The company is headquartered in St. Louis, Missouri. |
|||||
| Ransomware | Meteksan Defence Industry id7311 View details | Education | |||
|
Meteksan Defence Industries, Inc. is a subsidiary of Bilkent Holding and Bilkent University of Ankara, Turkey. The Company employs 150 personnel, where more than 100 high degree engineers comprise the direct technological workforce. |
|||||
| Ransomware | Pharmerica.com & BrightSpring Health Services id6050 View details | United States | Healthcare / Pharma | ||
|
Headquartered in Louisville, Kentucky, PharMerica is one of the largest and fastest-growing institutional pharmacy companies in the United States. Our premier pharmacy services, with more than 180 long-term care pharmacies in almost every state, have a national scope but a local approach.Revenue: $3BBrightSpring Health Services is the leading provider of complementary home- and community-based health services for complex populations in need of specialized and/or chronic care. We focus on providing quality outcomes, through best-in-class service and technology capabilities.Revenue: $5.4B |
|||||
| Ransomware | Micro Star International id6042 View details | United States | Communication / Marketing | — | |
|
Micro-Star International AKA MSI designs, manufactures, and sells motherboards and graphics cards for customers in the United States, Canada, and internationally. MSI is headquartered in Taipei, Taiwan. MSI source code, including framework to develop bios, also we have private keys.We will publish stolen data when timer expires.Databases: wwrlt2, eais, CTMS, ERP.Revenue: $7BWebsite: msi.com |
|||||
| Ransomware | Guess who! id6033 View details | Other | — | ||
|
One huge trust have lost gigabytes of their's data and now playing with fire trying to hang time. Keep an eye on the stocks, don't lose your money. |
|||||
| Ransomware | midamericanglass.com id6013 View details | Manufacturing / Engineering | — | ||
|
Mid-American Glass is a regional distributor / fabricator of flat glass, insulating glass, and architectural metal. While flat glass distribution remains the strength of our company, our fabrication of insulating glass and architectural metal continues to drive our growth.Website www.midamericanglass.comRevenue $11.4M |
|||||
| Ransomware | Goldenbear.com & mjhallandcompany.com id5993 View details | Communication / Marketing | |||
|
GOLDENBEAR.COMGolden Bear is a leading provider of commercial property and casualty, professional liability, and residential earthquake insurance.Revenue: 20.8M$Eployees: 82Website: www.goldenbear.commjhallandcompany.comSince 1973, M.J. Hall and Company has earned a name for dependable Business Insurance, as well as one of California's most experienced general agents.Revenue: 11.1M$Eployees: 55Website:www.mjhallandcompany.com |
|||||
| Ransomware | Lpa-group.com id5990 View details | Communication / Marketing | — | ||
|
LPA is a leading UK manufacturer in the design and build of connectors, LED lighting and electrical systems. Founded in the 1800’s, the Company has a long product development history where high reliability, low maintenance and life cycle costs are an intrinsic part of our product design and build ethos. All companies are ISO 9001 certified.Revenue: UK£19.3m |
|||||
| Ransomware | Hawaii self storage id5965 View details | Services | |||
|
Hawaii Self Storage is a locally owned company, committed to service the people & businesses in Hawaii with exceptional storage services. Data 32GB: |
|||||
| Ransomware | Biman airlines id5966 View details | Bangladesh | Transportation / Travel / Logistics | ||
|
Biman Bangladesh Airlines (Bengali) is the national flag carrier airline of Bangladesh. The airline provides international passenger and cargo services to Asia and Europe, as well as major domestic routes inside Bangladesh. |
|||||