Ransomware Group intelligence
Noescape
InactiveTrack Noescape with 126 published victims and 2 known leak locations in a single intelligence view.
Overview
Noescape is tracked by Breach House as a ransomware group with 126 published victims.
United Kingdom is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 3h ago | noescaperjh3gg6oy7rck57fiefyuzmj7kmvojxgvlmwd5pdzizrb7ad.onion |
| Leak location 1 | Onion service | Down checked 3h ago | noescapemsqxvizdxyl7f7rmg5cdjwp33pg2wpmiaaibilb4btwzttad.onion |
Top Activity Sectors (17)
- Communication / Marketing 33
- Manufacturing / Engineering 13
- Services 11
- Education 10
- Healthcare / Pharma 9
- Public Sector 8
- Construction / Real Estate 7
- Finance / Legal / Insurance 7
- Energy 7
- IT 5
- Telecommunications 4
- Transportation / Travel / Logistics 3
- Agriculture / Food 3
- Retail / E-commerce 2
- Hospitality / Food & Beverage / Tourism 2
- Not identified 1
- NGOs / Associations 1
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Noescape, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: noescape executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: noescape leverages registry run keys to maintain persistence across reboots after initial infection.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: noescape disables antivirus and monitoring tools by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.002 Software Packing Stealth
What they do: noescape packs its malware binaries to evade static detection by security solutions scanning file signatures.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1070.004 File Deletion Stealth
What they do: noescape deletes Volume Shadow Copies and backup directories via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: noescape scans network shares using native tools to identify victim hosts for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: noescape archives stolen data using utility tools prior to exfiltration for extortion demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: noescape encrypts victim files using custom ransomware binaries, targeting communication and marketing data for maximum disruption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_RECOVER_FILES.txt
--------------------------------------------------------------------------------
>>>>>>>>>>>>>>>>>> H O W T O R E C O V E R F I L E S <<<<<<<<<<<<<<<<<<
--------------------------------------------------------------------------------
$$\ $$\ $$$$$$$$\
$$$\ $$ | $$ _____|
$$$$\ $$ | $$$$$$\ $$ | $$$$$$$\ $$$$$$$\ $$$$$$\ $$$$$$\ $$$$$$\
$$ $$\$$ |$$ __$$\ $$$$$\ $$ _____|$$ _____| \____$$\ $$ __$$\ $$ __$$\
$$ \$$$$ |$$ / $$ |$$ __| \$$$$$$\ $$ / $$$$$$$ |$$ / $$ |$$$$$$$$ |
$$ |\$$$ |$$ | $$ |$$ | \____$$\ $$ | $$ __$$ |$$ | $$ |$$ ____|
$$ | \$$ |\$$$$$$ |$$$$$$$$\ $$$$$$$ |\$$$$$$$\ \$$$$$$$ |$$$$$$$ |\$$$$$$$\
\__| \__| \______/ \________|\_______/ \_______| \_______|$$ ____/ \_______|
$$ |
$$ |
\__|
WHAT HAPPEND?
Your network has been hacked and infected by NoEscape .DHFGGEDADE
All your company documents, databases and other important files have been encrypted
Your confidential documents, personal data and sensitive info has been downloaded
WHAT'S NEXT?
You have to pay to get a our special recovery tool for all your files
And avoid publishing all the downloaded info for sale in darknet
WHAT IF I DON'T PAY?
All your files will remain encrypted forever
There is no other way to recover yours files, except for our special recovery tool
All the downloaded info will publishing for sale in darknet
Your colleagues, competitors, lawyers, media and whole world will see it
I WILL TO PAY. WHAT SHOULD I DO?
You need to contact us:
1. Download and install TOR browser https://www.torproject.org/
2. Open link in TOR browser noescaperjh3gg6oy7rck57fiefyuzmj7kmvojxgvlmwd5pdzizrb7ad.onion
3. Enter your personal ID and follow the instructions
Your personal ID:
[snip]
-------------------------------------------------------------------------------------------------
WHAT GUARANTEES DO WE GIVE?
We are not a politically company and we are not interested in your private affairs
We are a commercial company, and we are only interested in money
We value our reputation and keep our promise
WHAT SHOULD I NOT DO?
! Don't try modify or recover encrypted files at yourself !
! Only we can restore your files, the rest lie to you !
HOW_TO_RECOVER_FILES_no_personal_id.txt
--------------------------------------------------------------------------------
>>>>>>>>>>>>>>>>>> H O W T O R E C O V E R F I L E S <<<<<<<<<<<<<<<<<<
--------------------------------------------------------------------------------
$$\ $$\ $$$$$$$$\
$$$\ $$ | $$ _____|
$$$$\ $$ | $$$$$$\ $$ | $$$$$$$\ $$$$$$$\ $$$$$$\ $$$$$$\ $$$$$$\
$$ $$\$$ |$$ __$$\ $$$$$\ $$ _____|$$ _____| \____$$\ $$ __$$\ $$ __$$\
$$ \$$$$ |$$ / $$ |$$ __| \$$$$$$\ $$ / $$$$$$$ |$$ / $$ |$$$$$$$$ |
$$ |\$$$ |$$ | $$ |$$ | \____$$\ $$ | $$ __$$ |$$ | $$ |$$ ____|
$$ | \$$ |\$$$$$$ |$$$$$$$$\ $$$$$$$ |\$$$$$$$\ \$$$$$$$ |$$$$$$$ |\$$$$$$$\
\__| \__| \______/ \________|\_______/ \_______| \_______|$$ ____/ \_______|
$$ |
$$ |
\__|
WHAT HAPPEND?
Your network has been hacked and infected by NoEscape.
All your company documents, databases and other important files have been encrypted.
Your confidential documents, personal data and sensitive info has been downloaded to our servers.
WHAT'S NEXT?
You need to contact us:
1. Download and install TOR browser https://www.torproject.org/
2. Open link in TOR browser noescaperjh3gg6oy7rck57fiefyuzmj7kmvojxgvlmwd5pdzizrb7ad.onion/[snip]
3. Follow the instructions
If you don't contact us soon we will publish the news of your company being hacked on our leak blog.
And then we will publish all the data that we have downloaded from your servers.
BLOG TO LEAK: noescapemsqxvizdxyl7f7rmg5cdjwp33pg2wpmiaaibilb4btwzttad.onion
DO NOT MODIFY OR ATTEMPT TO RECOVER ENCRYPTED FILES YOURSELF.
YOU CAN DAMAGE THE FILES AND THEN NO ONE CAN RESTORE THEM.
ONLY WE CAN RECOVER YOUR FILES WITH OUR DEDICATED TOOL.
HOW_TO_RECOVER_FILES_no_personal_id2.txt
> WHAT HAPPEND?
Important files on your network have been ENCRYPTED and now have the extension {ext}.
To recover your files, you need to follow the instructions below.
> SENSITIVE DATA
Sensitive data from your network has been DOWNLOADED.
If you DON'T WANT to your sensitive data PUBLISHED on our leak blog, you must act quickly.
LEAK BLOG: noescapemsqxvizdxyl7f7rmg5cdjwp33pg2wpmiaaibilb4btwzttad.onion
Data includes:
- Personal data of employees, resume, DL, SSN.
- Complete network map, including credentials for local and remote services.
- Private financial information including: customer data, accounts, budgets, annual reports, bank statements.
- Production documentation, including: datagrams, diagrams, drawings.
- And much more...
Sample DOWNLOADED FILES are available in your user panel.
> CAUTION
DO NOT MODIFY ENCRYPTED FILES BY YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, THIS WILL RESULT IN PERMANENT DATA LOSS.
> WHAT SHOULD I DO NEXT?
You need to contact us:
1. Download and install TOR browser: https://www.torproject.org/
2. Go to your user panel: bwjbbpbcihglahwxxusmyy2nxqdc4oqy4rvyhayn4dxhqzji4qi7taid.onion/[snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (126)
Search, filter and paginate the victim timeline for Noescape. Showing 101–126 of 126.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Lower Yukon School District id8106 View details | Education | |||
|
The ten villages that comprise the Lower Yukon School District are spread across 22,000 square miles. The Yukon River, one of the largest rivers in North America, winds through our yards on its way to the Bering Sea.The ... |
|||||
| Ransomware | Avertronics Inc id8075 View details | Communication / Marketing | |||
|
Avertronics INC offers the processing of connecting elements, connecting wire modules, wireless application modules, system products, and related technology for the electronic, electrical, mechanic, photonics and health ... |
|||||
| Ransomware | Republican Vilnius Psychiatric Hospital id8074 View details | Lithuania | Healthcare / Pharma | ||
|
Republican Vilnius Psychiatric Hospital (RVPL) is the largest and widest range of mental health care institution in Lithuania. More than 600 employees work in the hospital, and professional assistance is provided to more... |
|||||
| Ransomware | Kreacta id8073 View details | Manufacturing / Engineering | |||
|
Kreacta are specialized in technical consultancy and2D/3D mechanical design of special and automatic machines, equipment, complete production lines, and installations for industrial production in general.We provide high-... |
|||||
| Ransomware | Grupo SCA - Business Information id8020 View details | Spain | Services | ||
|
Grupo SCA is a national consulting company specializing in solutions and consulting, operating on the market for more than twenty years. Our management team has been trained by multinational firms in the sector and our e... |
|||||
| Ransomware | Newton IT Solutions id7997 View details | United Kingdom | Services | ||
|
Newton IT Solutions is a managed services provider providing innovative business technology solutions. We pride ourselves on having our advanced, wholly owned and private infrastructure in the cloud, allowing our clients... |
|||||
| Ransomware | Garac - Business Information id7984 View details | Services | |||
|
GARAC prepares young people for the technological and commercial challenges of tomorrow and gives them the opportunity to earn a degree with access to jobs in the automotive, motorcycle, heavy duty vehicle and transporta... |
|||||
| Ransomware | Fushimitsu Gumi Co., Ltd id7983 View details | Manufacturing / Engineering | |||
|
In May 1954, the founder founded Fushimitsu Gumi, a civil engineering business, in the peaceful city of Hiroshima. In April 1956, the company was reorganized into Fushimitsu Gumi Co., Ltd. Since then, we have worked dili... |
|||||
| Ransomware | Ville de Chevilly-Larue id7942 View details | France | Finance / Legal / Insurance | ||
|
Ville de Chevilly-Larue.The network has been successfully encrypted and compromised, the data we will release if the company does not enter into dialogue with us includes: banking, finance, budget, passports, contracts, ... |
|||||
| Ransomware | BEIJER REF id7941 View details | Spain | Manufacturing / Engineering | ||
|
Beijer Ref is the European leader in distribution and production of industrial and commercial refrigeration equipment, and components and air conditioning systems. It employs 21-50 people and has $10M-$25M of revenue. Th... |
|||||
| Ransomware | Addison Electronique id7940 View details | Finance / Legal / Insurance | |||
|
Addison Electronique is a family business founded in 1961 specializing in electronic components.The company was successfully encrypted and compromised. We have data such as passports, credit cards, insurance, agreements,... |
|||||
| Ransomware | Rampi Srl id7441 View details | Communication / Marketing | |||
|
Rampi produces and markets professional detergents suitable for both laundries and domestic use. We have over 100 GB of data stolen from the company's servers which include:Banking, commission data from 2016 to March 202... |
|||||
| Ransomware | Corinium Carpets id7404 View details | United Kingdom | Communication / Marketing | ||
|
Located in Cheltenham, Gloucestershire and established in 1976, Corinium Carpets is a family run carpet company committed to providing first class customer care and high quality flooring services. We have passports, driv... |
|||||
| Ransomware | Acomen id7352 View details | France | Healthcare / Pharma | ||
|
Acomen is a company that operates in the Health, Wellness and Fitness industry. It employs 21-50 people and has $5M-$10M of revenue. |
|||||
| Ransomware | Girardini Holding Srl id7351 View details | Italy | Manufacturing / Engineering | ||
|
We are an Italian company, existing since the early 1940s, specialized in the design and construction of moulds, cold stamping and powder coating of technical sheet metal components. We have over 100 GB of data stolen fr... |
|||||
| Ransomware | Jordan Airmotive Ltd id7290 View details | Jordan | Communication / Marketing | ||
|
Jordan Airmotive provides additional services: 1. Contract Evaluation Jordan Airmotive team will evaluate the most suitable contract type for your engine repair, whether it is NTE, FFP, Time & Material or otherwise. We ... |
|||||
| Ransomware | Burton & South Derbyshire College id7289 View details | United Kingdom | Education | ||
|
A school of science was founded in 1872 and by 1879 had moved to the Burton Institute in Union Street. By 1931 it was known as the Technical Institute. In 1948 it became Burton technical College following the combination... |
|||||
| Ransomware | Innodis Group id7247 View details | Mauritius | Agriculture / Food | ||
|
Innodis Ltd, a public listed company founded in 1973, averages an annual turnover of almost MUR 4 billion. We are presently one of the largest groups involved in food and non-food production and distribution in Mauritius... |
|||||
| Ransomware | Protactics id7244 View details | Colombia | Communication / Marketing | ||
|
Protactics is a Colombian company that provides security and defense solutions for companies and governments in Latin America. We have data such as passports, ID cards/certificates/agreements/contracts/confidential docum... |
|||||
| Ransomware | Credit Team id7006 View details | Finance / Legal / Insurance | |||
|
Provider of subsidized finance and credit brokerage intended to increase liquidity and company growth. The company's services include obtaining non-repayable grants, tax bonuses and subsidized loans for micro SMEs, start... |
|||||
| Ransomware | Cyril Johnston Hire id6959 View details | United Kingdom | Agriculture / Food | ||
|
Cyril Johnston Hire commenced trading in April 1988. The original concept was the provision of Agricultural equipment Rental to support the companies burgeoning Agricultural customer base. This concept, Cyril Johnston Hi... |
|||||
| Ransomware | Promotion Fulfillment Center id6957 View details | Communication / Marketing | |||
|
Founded in 1974, Promotion Fulfillment Center provides product fulfillment and promotional services. They offer rebates, sweepstakes/contests, loyalty programs and more. The company is headquartered in Camanche, Iowa. |
|||||
| Ransomware | University of Hawaii id6956 View details | United States | Education | ||
|
University of Hawaii, founded in 1907 and headquartered in Honolulu, Hawaii, offers degrees in both undergraduate and graduate-level curriculum. The University programs include undergraduate and graduate degree programs ... |
|||||
| Ransomware | Centre Hospitalier Régional de Namur id6850 View details | Belgium | Healthcare / Pharma | ||
|
Centre Hospitalier Régional de Namur is a company that operates in the Hospital & Health Care industry. It employs 1,001-2,000 people and has $100M-$250M of revenue. The company is headquartered in Namur, Wallonia, Belgi... |
|||||
| Ransomware | Doesburg Components id6830 View details | Netherlands | Manufacturing / Engineering | ||
|
If the company does not contact and cooperate by the end of the time counter, then we will leak all their important files and documents, including secret tax documents. |
|||||
| Ransomware | CASTEC Inc id6829 View details | Services | |||
|
If the company is not going to cooperate, then soon everyone will be able to see valuable company data in the data leak, such as tax documents and much more. |
|||||