Ransomware Group intelligence
Ralord
InactiveTrack Ralord with 20 published victims and 4 known leak locations in a single intelligence view.
Overview
Ralord is tracked by Breach House as a ransomware group with 20 published victims.
Brazil is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 17m ago | ralordt7gywtkkkkq2suldao6mpibsb7cpjvdfezpzwgltyj2laiuuid.onion |
| Leak location 2 | Onion service | Down checked 17m ago | ralord3htj7v2dkavss2hjzviviwgsf4anfdnihn5qcjl6eb5if3cuqd.onion |
| Leak location 1 | Onion service | Down checked 17m ago | ralordqe33mpufkpsr6zkdatktlu3t2uei4ught3sitxgtzfmqmbsuyd.onion |
| Leak location 4 | Onion service | Down checked 17m ago | novazzitmugtbjwuttc5hhsemkmvwh3iyt27oeeunu5mkw62qpfeykid.onion |
Top Activity Sectors (8)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Ralord, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ralord executes PowerShell scripts to run payload deployment and system reconnaissance commands.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: ralord uses registry run keys to ensure malware execution after victim reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ralord disables antivirus and monitoring tools to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.010 Command Obfuscation Stealth
What they do: ralord obfuscates command strings and payload binaries to evade static detection.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1070.004 File Deletion Stealth
What they do: ralord deletes Volume Shadow Copies and backup artifacts to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: ralord accesses LSASS memory to steal credentials for lateral movement and evasion.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: ralord uses network share discovery to locate victim file shares and staging directories for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: ralord moves laterally through SMB/Windows Admin Shares to compromise additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: ralord encrypts critical business files and shared directories using its ransomware payload.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ralord calls system recovery inhibitors to block restore processes and persistence mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-XeBY311RpMRQ.txt
----------------------------------------------------------------------------- RALord ransomware ----------------------------------------------------------------------------- -> Hello , without any problems , if you see this Readme its mean you under controll by RLord ransomware , the data has been stolen and everything done , but -> you can recover the files by contact us and pay the ransom , the data taken from this device or network have crenditals and your systeminfo too , without talk about files -> also , we will provide report with hack operation and how to fix errors and up your security ----------------- >>> contact us here : -> qtoxID: 0C8E5B45C57AE244E9C904C5BC74F73306937469D9CEA22541CA69AC162B8D42A20F4C0382AC ----------------- >>> important notes : -> please do not touch the files becouse we can't decrypt it if you touch it -> please contact us today becouse the leak operation should start -> in nigotable please make sure to accept our rules, its easy ----------------- >>> our websites : -> mirror 1 : ralord3htj7v2dkavss2hjzviviwgsf4anfdnihn5qcjl6eb5if3cuqd.onion -> mirror 2 : ralordqe33mpufkpsr6zkdatktlu3t2uei4ught3sitxgtzfmqmbsuyd.onion -> mirror 3 : ralordt7gywtkkkkq2suldao6mpibsb7cpjvdfezpzwgltyj2laiuuid.onion -> to enter this URLs you need to download tor : https://www.torproject.org/download/ ----------------------------------------------------------------------------- RALord ransomware -----------------------------------------------------------------------------
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (20)
Search, filter and paginate the victim timeline for Ralord. Showing 1–20 of 20.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | DIALLOG company id19579 View details | Canada | Telecommunications | ||
|
Diallog Telecommunications is a Canadian-owned and operated telecom company based in Toronto, established in 1998. Originally founded as ... |
|||||
| Ransomware | HELUKABEL company id19325 View details | Germany | Manufacturing / Engineering | ||
|
The website www.helukabel.de is the official online presence of HELUKABEL GmbH, a German-based global leader in the manufacturing ... |
|||||
| Ransomware | rawafid company id19321 View details | Saudi Arabia | Manufacturing / Engineering | ||
|
Established in 2008 and headquartered in Riyadh, Rawafid Industrial specializes in water infrastructure projects, including seawater and brackish water desalination, wastewater treatment... |
|||||
| Ransomware | agromate company id19286 View details | Malaysia | Agriculture / Food | ||
|
Agromate.com.my is the official website of Agromate Holdings Sdn Bhd, a leading Malaysian agricultural company specializing in fertilizer... |
|||||
| Ransomware | bettininformatica - suporteon company id19256 View details | Brazil | IT | ||
|
BThe website bettininformatica.com.br belongs to Bettin Soluções em Informática, a technology company based in Marília, São Paulo, Brazil. They offer services such as computer maintenance... |
|||||
| Ransomware | Bio-Clima Service id19203 View details | Italy | Hospitality / Food & Beverage / Tourism | ||
|
Bio-Clima Service Srl, an Italian company based in Bernareggio, Lombardy, specializing in the technical assistance, maintenance, and... |
|||||
| Ransomware | ARRCO LSM id19177 View details | Norway | Communication / Marketing | ||
|
ARRCO – Lights Sound Magic is a professional event technology company based in Hamar, Norway. They specialize in providing comprehensive solutions for events, including sound,... |
|||||
| Ransomware | NewHotel cloud company id19166 View details | Spain | IT | ||
|
Newhotel Cloud is a comprehensive, cloud-based Property Management System (PMS) developed by Newhotel Software to streamline hotel operations of... |
|||||
| Ransomware | Al-Hejailan Group id19152 View details | Saudi Arabia | Manufacturing / Engineering | ||
|
Established in 1980, the Al-Hejailan Group began as an engineering and contracting firm and has since evolved into a diversified holding company. Headquartered in Riyadh, with regional offices across the GCC... |
|||||
| Ransomware | hasbco Company id19085 View details | United States | Retail / E-commerce | ||
|
Hasbco is a company that operates in the Grocery Retail industry. It employs 5to9 people and has 1Mto5M of revenue. The company... |
|||||
| Ransomware | hasbco id19084 View details | Retail / E-commerce | |||
|
hasbco is a retail and e-commerce company operating in Canada, with a business model centered on selling consumer goods through both digital and store-based channels. In this sector, companies typically manage online merchandising, order fulfillment, customer service, and in-store retail operations to support omnichannel shopping. Public retail reporting on comparable Canadian chains shows how e-commerce and physical storefronts can be split or coordinated as part of a broader digital-first strategy. hasbco was listed as a ransomware victim associated with ralord. |
|||||
| Ransomware | Tomio Ingeniería id18844 View details | Argentina | Manufacturing / Engineering | ||
|
Tomio Ingeniería S.A. is an Argentine company specializing in engineering and industrial services. Founded in 1946, it offers a range of services including... |
|||||
| Ransomware | Élan Sportif Nantes id18843 View details | France | Education | ||
|
The domain ec-nantes.fr is associated with École Centrale de Nantes, which is a prestigious engineering school located in Nantes, France. It is one of the prominent institutions in the French higher education system... |
|||||
| Ransomware | Ihara company id18842 View details | Brazil | Agriculture / Food | ||
|
IHARA is a Brazilian company specializing in the development and manufacturing of agricultural chemical products aimed at crop protection. Established in 1965, IHARA offers ... |
|||||
| Ransomware | Pere Claver grup id18841 View details | Spain | Communication / Marketing | ||
|
Pere Claver Grup is a private, non-profit organization established in 1948 in Barcelona, Spain. With a team of over 800 professionals ... |
|||||
| Ransomware | Formosa Chang id18838 View details | Taiwan, Province of China | Hospitality / Food & Beverage / Tourism | ||
|
Formosa Chang is a well-known Taiwanese restaurant chain, primarily famous for its traditional Taiwanese-style braised pork rice ... |
|||||
| Ransomware | pereclaver.org id18769 View details | Spain | Communication / Marketing | ||
|
Pere Claver Grup is a private, non-profit organization established in 1948 in Barcelona, Spain. With a team of over 800 professionals ... |
|||||
| Ransomware | ihara.com.br id18748 View details | Brazil | Agriculture / Food | ||
|
IHARA is a Brazilian company specializing in the development and manufacturing of agricultural chemical products aimed at crop protection. Established in 1965, IHARA offers ... |
|||||
| Ransomware | tomioingenieria.com.ar id18712 View details | Argentina | Manufacturing / Engineering | ||
|
Tomio Ingeniería S.A. is an Argentine company specializing in engineering and industrial services. Founded in 1946, it offers a range of services including... |
|||||
| Ransomware | ec-nantes.fr id18711 View details | France | Education | ||
|
The domain ec-nantes.fr is associated with École Centrale de Nantes, which is a prestigious engineering school located in Nantes, France. It is one of the prominent institutions in the French higher education system... |
|||||