Ransomware Group intelligence
Noname
InactiveTrack Noname with 3 published victims and 1 known leak locations in a single intelligence view.
Overview
Noname is tracked by Breach House as a ransomware group with 3 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 4h ago | noname2j6zkgnt7ftxsjju5tfd3s45s4i3egq5bqtl72kgum4ldc6qyd.onion |
Top Activity Sectors (2)
Typical Attacks (7)
▼MITRE ATT&CK does not currently catalogue Noname, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: noname executes malicious commands via PowerShell scripts injected during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: noname disables antivirus tools and security monitoring mechanisms to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: noname deletes Volume Shadow Copies and backup directories to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: noname scans network shares to identify additional systems within the victim environment.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: noname exfiltrates sensitive victim data before deploying ransomware for double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: noname encrypts victim files using its own ransomware payload to hold data hostage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: noname runs system recovery inhibitors to block restoration attempts after encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW TO RECOVERY FILES.TXT
>>>> Your data are stolen and encrypted
>>>> What guarantees that we will not deceive you?
We are not a politically motivated group and we do not need anything other than your money.
If you pay, we will provide you the programs for decryption and we will delete your data.
If we do not give you decrypters, or we do not delete your data after payment, then nobody will pay us in
the future.
Therefore to us our reputation is very important. We attack the companies worldwide and there is no
dissatisfied victim after payment.
>>>> You need contact us and decrypt one file for free With DECRYPTION ID
e-mail : [email protected]
e-mail 2 : [email protected]
Please send all email adress for backup communication
>>>> Your personal WORKID : [snip]
>>>> For real time chat with us
For chat with us via qtox download https://tox.chat/download.html and add our QTOX ID
QTOX : F1D0F45DBC3F4CA784D5D0D0DD8ADCD31AB5645BE00293FE6302CD0381F6527AC647A61CB08D
>>>> For useful informations visit our blog
For detailed info our web site you can visit via torbrowser https://www.torproject.org/download/
Download and install torbrowser after paste url
http://noname2j6zkgnt7ftxsjju5tfd3s45s4i3egq5bqtl72kgum4ldc6qyd.onion
Decryption ID : [snip]
HOW TO RECOVER YOUR FILES.TXT
If you want take back your data Contact with us For you be sure your datas available you can sent us little sized 3 file we will decrpyt and sent you back. For Contact US Please sent us all emails sometimes some email provider block our emails e-mail : [email protected] Your WorkID : [WORKID] >>>> Warning! Do not DELETE or MODIFY any files, it can lead to recovery problems! For commmunicate with us via qtox download https://tox.chat/download.html and add our QTOX ID QTOX : A5F2F6058F70CE5953DC475EE6AF1F97FC6D487ABEBAE76915075E3A53525B1D863102EDD50E Our Web sites for special insturctions and informations You can access our web site via torbrowser : https://www.torproject.org/download/ http://nonamef5njcxkghbjequlibwe5d3t3li5tmyqdyarnrsryopvku76wqd.onion http://7tkffbh3qiumpfjfq77plcorjmfohmbj6nwq5je6herbpya6kmgoafid.onion
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (3)
Search, filter and paginate the victim timeline for Noname. Showing 1–3 of 3.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | nobleweb.com id10442 View details | United States | Communication / Marketing | ||
|
M Since 1992, The Noble Group has built a dedicated team of professionals all working together to revitalize neighborhoods, provide new homes for families and build a better future for our investors. 260GB lists with ssn numbers, residential addresses, date of birth, salary and tax information, contracts, and other confidential forms for employees budget, cash […] |
|||||
| Ransomware | selmi.com.br id10441 View details | Brazil | Communication / Marketing | ||
|
– Established in 1966; – Manufacturer of flour based products, such as dry pasta, traditional pasta, cookies, crackers, cakes and baking mixes; – Over 1,000 employees; – Two production sites; – Thirteen distribution centers across the country; – Owns a fleet of 37 vehicles and a partnership with carriers to ensure efficiency in delivery; – […] |
|||||
| Ransomware | onyx-fire.com id10440 View details | United States | Finance / Legal / Insurance | ||
|
Onyx-Fire Protection Services Inc is a company that operates in the Security and Investigations industry 800 GB Financial documents (balance sheets, budget, PL reports, expense reports, bank statements, statements of payables and receivables, various tax forms and reports, audits, cashflow, and many other important financial documents) Employees (sin numbers, residential addresses, date of birth, salary, […] |
|||||