Ransomware Group intelligence
Radar
InactiveTrack Radar with 24 published victims and 2 known leak locations in a single intelligence view.
Overview
Radar is tracked by Breach House as a ransomware group with 24 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 5h ago | 3bnusfu2lgk5at43ceu7cdok5yv4gfbono2jv57ho74ucjvc7czirfid.onion |
| Leak location 2 | Onion service | Down checked 5h ago | 4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion |
Top Activity Sectors (10)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Radar, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: radar executes PowerShell scripts to stage ransomware payloads and disable security tools on compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: radar persists via registry run keys to ensure ransomware execution survives reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: radar disables antivirus and monitoring tools by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: radar encodes victim files with symmetric encryption keys before deployment to hinder decryption.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: radar deletes Volume Shadow Copies and backup directories via command-line tools to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: radar performs remote system discovery to map network topology and identify high-value targets in construction sectors.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: radar uses network share discovery to identify accessible SMB shares across victim infrastructure for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: radar encrypts victim files using custom ransomware binaries targeting communication and marketing data sectors.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Victims (24)
Search, filter and paginate the victim timeline for Radar. Showing 1–24 of 24.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Bentley Capital Ventures id28466 View details | United States | Finance / Legal / Insurance | — | |
|
https://www.linkedin.com/company/bentley-capital-ventures We started Bentley Capital Ventures in 2012 to facilitate small business owners across the country in the process of obtaining capital. We know a simple trip to the local bank doesnt always provide the results many are looking for and as business owners ourselves we know how challenging it can be to obtain capital when you dont fit within the guidelines of the traditional banking world. At Bentley Capital we use the relationships we have built over the last 25 years in both the consumer and commercial banking markets to provide our clients with the very best options available for their specific situation. Whether you have perfect or less than perfect credit our goal will always be to provide you with options that promote growth and properity for your business. |
|||||
| Ransomware | TUAN LE Construction Company Limited id24337 View details | Viet Nam | Construction / Real Estate | — | |
|
Files Marked Confidential download - https://upload.disroot.org/r/SBnd9KFH#Qjphic5O+R3JHDSY7tW+9iZ/WkjIgplsCqMrx7v29ws= |
|||||
| Ransomware | Kingcan Holdings Limited , Fuzhen Group id23567 View details | China | Communication / Marketing | — | |
|
https://web.archive.org/web/20210624183642/http://www.kingcan.net/ Fuzhen Group Founded in 1993, with quality as the cornerstone, specializes in the production of various types of fully open three-piece tinplate beverage cans, food, fruits and vegetables cans and two-piece aluminum products beverage cans and other metal packaging containers, and also provides professional one-stop food and beverage filling and filling foundry business. Fuzhen Group currently has five production bases in Fujian, Shandong, Hubei, Guangdong and Henan, which can produce more than 54 kinds of cans, with an annual production capacity of 2.5 billion three-piece tinplate tinplate cans and 2.5 billion two-piece aluminum cans, of which three tinplate tin cans account for more than 15% of China's three-piece tinplate market, and is the best in mainland China's tinplate industry! The production is not only highly automated, but also introduces six-color printing presses, high-frequency welding machines and high-speed tank lines with a capacity of 1,000 cans imported by world-renowned manufacturers such as the United Kingdom, Switzerland and Germany. In addition to one-stop production advantages, more to save the transmission costs between the production lines, production integration and production management control degree is also more effective, with perfect one-stop service and strict quality management, to win the long-term trust of customers. The main operating position in the Group - Fujian Fuzhen Metal Packaging Co., Ltd. was certified by IS09000 quality system in 1996, and is a pioneer in China's tank manufacturing industry certification. Fuzhen Group has always adhered to the business philosophy of "integrity and pragmatism, sustainable management", and aims to "quality first, customer first, international standards", and has provided customers with high-quality metal packaging materials with large shipments and stable quality over the years, and the quality of products has been recognized by the client. In addition to the domestic demand market in mainland China, Fuzhen cans are more marketed globally, including the United States and Canada, Japan, India, Pakistan, Yemen and other places; customers throughout the two sides of the well-known beverage and food manufacturers. |
|||||
| Ransomware | Fouad Alghanim & Sons Group of Companies Holding W.L.L. id23534 View details | Kuwait | Services | — | |
|
The full company name associated with the website falghanim.com is Alghanim International General Trading & Contracting Co. WLL. This company is an associate of the Fouad Alghanim & Sons Group of Companies, a separate entity from the similarly named Alghanim Industries (which uses the website alghanim.com). Files Marked Confidential - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/falghanim.com%20KUWAIT/Files%20Marked%20Confidential.txt . Contact us to remove the files from our servers! |
|||||
| Ransomware | OpenEyes Technologies Inc. id23488 View details | United States | IT | — | |
|
Confidential data from two companies OpenEyes Technologies Inc. and OpenEyes Software Solutions Pvt. Ltd (OPC) Corporate office, Suite #405, 4th Floor, Iscon Atria 1, Gotri Road, Vadodara – 390021, Gujarat – India . OpenEyes Technologies Inc. Headquarter · 1629 K Street, NW Suite 300. Washington, DC 20006 · +1.202.349.5858. Email address. [email protected] ; ODC (India) |
|||||
| Ransomware | Capital Reinforcing LTD. id23277 View details | United Kingdom | Manufacturing / Engineering | — | |
|
Steel fabricator in Birkenhead, Englandю Address: Capital House, 1 Bromborough Pool Business Park, Prices Way, Bromborough CH62 4LP, United Kingdom. Phone: +44 151 644 1559 |
|||||
| Ransomware | ROBERT G. DASHIELL, JR., P.E., INC. id23276 View details | United States | Communication / Marketing | — | |
|
Robert G Dashiell Jr PE Inc is a reputable engineering firm based in Norfolk, VA, specializing in providing professional engineering services. Around ~500GB of confidential data. The leak of internal company documents contains a huge variety of personal documents and information of clients, employees private data, private contacts, confidential contracts, confidential projects, orders, IDs, SSN, email conversations. Bank documents: statements, balances, Tax bills, signatures, checks. Video - https://streamable.com/4wn1jk , screenshots - https://imgur.com/a/Er9J1Kp, all contacts - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/RGELECTRIC_part2/dataRobert%20G%20Dashiel/contacts.csv |
|||||
| Ransomware | Epia Financial Services id23275 View details | United Kingdom | Finance / Legal / Insurance | — | |
|
+264816013040. Mail. [email protected]. Home. No 17 Eulenweg Street, Hochland Park, Windhoek ,Namibia. RELATABLE PARTNERS. NAMRA · NAMFISA. NBWPF. CIFNAMIBIA |
|||||
| Ransomware | My Florida Case Management Services, LLC id23219 View details | United States | Services | — | |
|
My Florida Case Management Services, LLC, a professional case management company located in Doral, FL. It could also be a general reference to the state of Florida's case management services, such as the Medicaid Mental Health Targeted Case Management program provided through the Florida Agency for Health Care Administration (AHCA) for individuals with serious mental illnesses or emotional disturbances. Additionally, it may refer to court-based case management, such as the Family Court Case Management process. |
|||||
| Ransomware | MC INVERSIONES INMOBILIARIAS Construction company in Peru id23190 View details | Peru | Construction / Real Estate | — | |
|
MC INVERSIONES INMOBILIARIAS Construction company in Peru. A lot of confidential information. |
|||||
| Ransomware | TK HOLDINGS GROUP id23189 View details | Congo, The Democratic Republic of the | NGOs / Associations | — | |
|
https://www.linkedin.com/in/altanko - Alexandre TANKO - Président Directeur Général TK HOLDINGS GROUP Limited. Bureau de liaison chargé des activités de support des entreprises du groupe implantées en République Démocratique du Congo. - TK TIMBER CONGO S.A.S.U. - TRANSLOG AFRICA S.A.S.U. - CONGO MINERAL RESOURCES COMPANY S.A.S. - CONGO MINERAL EXPLORATION COMPANY S.A.S. |
|||||
| Ransomware | Sold Real Estate, Sold RE PTY LTD id23172 View details | Australia | Construction / Real Estate | — | |
|
Sold Real Estate and UrbanX PTY LTD share an Active Directory network infrastructure. Part of files - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/TRUCCHIS_PART_OF_FILES/part of files urbanx.io filelist.txt |
|||||
| Ransomware | UrbanX PTY LTD id23171 View details | Australia | Construction / Real Estate | — | |
|
UrbanX PTY LTD. It is an Australian company that provides a platform to support real estate agents in building their own brands, with services including branding, marketing, and IT. Email [email protected], Email Phone 1300 513 888. Contact UrbanX.io by emailing [email protected] or calling +61 402214900. The CEO, Dan Argent, can also be reached at [email protected] or [email protected]. The company's general phone number is +61 7 3613 3888. Part of files - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/TRUCCHIS_PART_OF_FILES/part of files urbanx.io filelist.txt |
|||||
| Ransomware | One Agency Eastlakes id23170 View details | Australia | Communication / Marketing | — | |
|
One Agency Eastlakes Real Estate Agency in Swansea,NSW 2281 offers specialist property services to buy, sell and rent real estate. One Agency Eastlakes and UrbanX PTY LTD share an Active Directory network infrastructure. Part of files - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/TRUCCHIS_PART_OF_FILES/part of files urbanx.io filelist.txt |
|||||
| Ransomware | Chek Tan and Company, LLP id22911 View details | United States | Services | — | |
|
Chek Tan and Company offers accounting, audits, management consulting, IRS representation, and tax management services. San Francisco, California, United States. |
|||||
| Ransomware | Capital Reinforcing LTD id22746 View details | United Kingdom | Manufacturing / Engineering | — | |
|
Steel fabricator in Birkenhead, Englandю Address: Capital House, 1 Bromborough Pool Business Park, Prices Way, Bromborough CH62 4LP, United Kingdom. Phone: +44 151 644 1559 |
|||||
| Ransomware | R F Owens Co, Inc./ Trucchi's Supermarkets Distribution Center id22389 View details | United States | Retail / E-commerce | — | |
|
https://www.bloomberg.com/profile/company/0078232D:US , R F OWENS CO INC , 1062 BROADWAY, RAYNHAM MAO2767-7944 |
|||||
| Ransomware | Volumex Lease id22384 View details | Belgium | Other | — | |
|
Volumex, specialist in leasing vans, trucks, tractors & trailers. Industrielaan 53, 3730 Hoeselt, Belgium. +32 2 899 8 899 , [email protected], Volumex HQ Industrielaan 53, 3730 Hoeselt. Luik, Volumex Lease, Rue Arsène Falla 40, 4621 Fléron. Beringen, Volumex Lease Schemkensstraat 8, 3583 Beringen. JULIEN HÖHNE | Volumex Lease, Industrielaan 53, 3730 Hoeselt | Rue Arsène Falla 40, 4621 Fléron | Schemkensstraat 8, 3583 Beringen, email: [email protected] tel: 02 899 8 899 |
|||||
| Ransomware | Trucchi's Supermarkets, Inc. id22383 View details | United States | Retail / E-commerce | — | |
|
[AI generated] Trucchi's Supermarkets, Inc. is a chain of family-owned supermarkets based in Taunton, Massachusetts, USA. It was established by William M. Trucchi Sr. in 1928. Currently, the company operates six full-service supermarkets in Massachusetts. Trucchi's places emphasis on providing value to customers by offering fresh quality products and personal customer service. They also offer custom cake designs through their bakery department. |
|||||
| Ransomware | Compagnie des Guides de Chamonix id22299 View details | France | Other | ||
|
Chamonix Office +33 (0)4 50 53 00 88, Maison de la montagne, 190 place de l'église, 74400 Chamonix Argentière Office +33 (0)4 50 54 17 94 , 24 Route du village, 74400 Argentière |
|||||
| Ransomware | Namibia | Epia Financial Services | Windhoek id22298 View details | Namibia | Energy | ||
|
+264816013040. Mail. [email protected]. Home. No 17 Eulenweg Street, Hochland Park, Windhoek ,Namibia. RELATABLE PARTNERS. NAMRA · NAMFISA. NBWPF. CIFNAMIBIA |
|||||
| Ransomware | Menten Truck Service N.V., Hoeselt, Belgium id22297 View details | Belgium | Other | ||
|
Menten Truck Service. Industrielaan 1084 3730 Hoeselt Tel +32 89 41 12 22. Fax +32 89 41 24 29. Email [email protected] |
|||||
| Ransomware | RG ELECTRIC COMPANY INC id22269 View details | United States | Communication / Marketing | ||
|
R. G. Electric Company, Incorporated, a Virginia-based electrical contractor founded in 1980. Around ~500GB of confidential data. The leak of internal company documents contains a huge variety of personal documents and information of clients, employees private data, private contacts, confidential contracts, confidential projects, orders, IDs, SSN, email conversations. Bank documents: statements, balances, Tax bills, signatures, checks. Video - https://streamable.com/4wn1jk , screenshots - https://imgur.com/a/Er9J1Kp, all contacts - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/RGELECTRIC_part2/dataRobert%20G%20Dashiel/contacts.csv |
|||||
| Ransomware | ROBERT G. DASHIELL, JR., P.E., INC id22268 View details | United States | Communication / Marketing | ||
|
Robert G Dashiell Jr PE Inc is a reputable engineering firm based in Norfolk, VA, specializing in providing professional engineering services. Around ~500GB of confidential data. The leak of internal company documents contains a huge variety of personal documents and information of clients, employees private data, private contacts, confidential contracts, confidential projects, orders, IDs, SSN, email conversations. Bank documents: statements, balances, Tax bills, signatures, checks. Video - https://streamable.com/4wn1jk , screenshots - https://imgur.com/a/Er9J1Kp, all contacts - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/RGELECTRIC_part2/dataRobert%20G%20Dashiel/contacts.csv |
|||||