Ransomware Group intelligence
Ransomhub
InactiveTrack Ransomhub with 843 published victims and 3 known leak locations in a single intelligence view.
Overview
Ransomhub is tracked by Breach House as a ransomware group with 843 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 26m ago | fpwwt67hm3mkt6hdavkfyqi42oo3vkaggvjj4kxdr2ivsbzyka5yr2qd.onion |
| Leak location 2 | Onion service | Down checked 26m ago | ransomgxjnwmu5ceqwo2jrjssxpoicolmgismfpnslaixg3pgpe5qcad.onion |
| Leak location 1 | Onion service | Down checked 26m ago | ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion |
Top Activity Sectors (17)
- Not identified 194
- Communication / Marketing 194
- Services 123
- Healthcare / Pharma 50
- Manufacturing / Engineering 40
- Finance / Legal / Insurance 39
- Construction / Real Estate 37
- IT 36
- Education 28
- Energy 23
- Public Sector 19
- Retail / E-commerce 18
- Hospitality / Food & Beverage / Tourism 13
- Transportation / Travel / Logistics 12
- Agriculture / Food 11
- Telecommunications 3
- NGOs / Associations 2
Typical Attacks (21)
▼How Ransomhub typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via RansomHub.
-
T1059.001 PowerShell Execution
What they do: RansomHub can use PowerShell to delete volume shadow copies.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: RansomHub can use `cmd.exe` to execute multiple commands on infected hosts.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: RansomHub has an encrypted configuration file.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: RansomHub has the ability to self-delete.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: RansomHub can use a provided passphrase to decrypt its configuration file.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1480 Execution Guardrails Stealth
What they do: RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
What they do: RansomHub can sleep for a set number of minutes before beginning execution.
What that means: Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: RansomHub can delete events from the Security, System, and Application logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1688 Safe Mode Boot Defense Impairment
What they do: RansomHub can reboot targeted systems into Safe Mode prior to encryption.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1018 Remote System Discovery Discovery
What they do: RansomHub can enumerate all accessible machines from the infected system.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: RansomHub can retrieve information about virtual machines.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: RansomHub has the ability to only encrypt specific files.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: RansomHub has the ability to target specific network shares for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1090 Proxy Command and Control
What they do: RansomHub can use a proxy to connect to remote SFTP servers.
What that means: Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
-
T1486 Data Encrypted for Impact Impact
What they do: RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: RansomHub has the ability to terminate specified services.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: RansomHub has used `vssadmin.exe` to delete volume shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (25)
▼Software Ransomhub has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_[id]_4.txt
We are the RansomHub. Your company Servers are locked and Data has been taken to our servers. This is serious. Good news: - your server system and data will be restored by our Decryption Tool; - for now, your data is secured and safely stored on our server; - nobody in the world is aware about the data leak from your company except you and RansomHub team; FAQs: Who we are? - Normal Browser Links: https://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/ - Tor Browser Links: http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/ Want to go to authorities for protection? - Seeking their help will only make the situation worse,They will try to prevent you from negotiating with us, because the negotiations will make them look incompetent,After the incident report is handed over to the government department, you will be fined <This will be a huge amount,Read more about the GDRP legislation:https://en.wikipedia.org/wiki/General_Data_Protection_Regulation>,The government uses your fine to reward them.And you will not get anything, and except you and your company, the rest of the people will forget what happened!!!!! Think you can handle it without us by decrypting your servers and data using some IT Solution from third-party "specialists"? - they will only make significant damage to all of your data; every encrypted file will be corrupted forever. Only our Decryption Tool will make decryption guaranteed; Don't go to recovery companies, they are essentially just middlemen who will make money off you and cheat you. - We are well aware of cases where recovery companies tell you that the ransom price is xxx dollars, but in fact they secretly negotiate with us for xxx dollars, so they earn xxx dollars from you. If you approached us directly without intermediaries you would pay 5 times less, that is xxx dollars. Think your partner IT Recovery Company will do files restoration? - no they will not do restoration, only take 3-4 weeks for nothing; besides all of your data is on our servers and we can publish it at any time; as well as send the info about the data breach from your company servers to your key partners and clients, competitors, media and youtubers, etc. Those actions from our side towards your company will have irreversible negative consequences for your business reputation. You don't care in any case, because you just don't want to pay? - We will make you business stop forever by using all of our experience to make your partners, clients, employees and whoever cooperates with your company change their minds by having no choice but to stay away from your company. As a result, in midterm you will have to close your business. So lets get straight to the point. What do we offer in exchange on your payment: - decryption and restoration of all your systems and data within 24 hours with guarantee; - never inform anyone about the data breach out from your company; - after data decryption and system restoration, we will delete all of your data from our servers forever; - provide valuable advising on your company IT protection so no one can attack your again. Now, in order to start negotiations, you need to do the following: - install and run 'Tor Browser' from https://www.torproject.org/download/ - use 'Tor Browser' open http://dd4djzr2ywfcox3zfvpkpyh3b657hsdwpwv5cfkmdfde2lr3fpz6spad.onion/ - enter your Client ID: There will be no bad news for your company after successful negotiations for both sides. But there will be plenty of those bad news if case of failed negotiations, so don't think about how to avoid it. Just focus on negotiations, payment and decryption to make all of your problems solved by our specialists within 1 day after payment received: servers and data restored, everything will work good as new. ************************************************
readme_[id]_3.txt
We are the RansomHub. Your company Servers are locked and Data has been taken to our servers. This is serious. Good news: - your server system and data will be restored by our Decryption Tool; - for now, your data is secured and safely stored on our server; - nobody in the world is aware about the data leak from your company except you and RansomHub team; FAQs: Who we are? - Normal Browser Links: https://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/ - Tor Browser Links: http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/ Want to go to authorities for protection? - Seeking their help will only make the situation worse,They will try to prevent you from negotiating with us, because the negotiations will make them look incompetent,After the incident report is handed over to the government department, you will be fined <This will be a huge amount,Read more about the GDRP legislation:https://en.wikipedia.org/wiki/General_Data_Protection_Regulation>,The government uses your fine to reward them.And you will not get anything, and except you and your company, the rest of the people will forget what happened!!!!! Think you can handle it without us by decrypting your servers and data using some IT Solution from third-party "specialists"? - they will only make significant damage to all of your data; every encrypted file will be corrupted forever. Only our Decryption Tool will make decryption guaranteed; Think your partner IT Recovery Company will do files restoration? - no they will not do restoration, only take 3-4 weeks for nothing; besides all of your data is on our servers and we can publish it at any time; as well as send the info about the data breach from your company servers to your key partners and clients, competitors, media and youtubers, etc. Those actions from our side towards your company will have irreversible negative consequences for your business reputation. You don't care in any case, because you just don't want to pay? - We will make you business stop forever by using all of our experience to make your partners, clients, employees and whoever cooperates with your company change their minds by having no choice but to stay away from your company. As a result, in midterm you will have to close your business. So lets get straight to the point. What do we offer in exchange on your payment: - decryption and restoration of all your systems and data within 24 hours with guarantee; - never inform anyone about the data breach out from your company; - after data decryption and system restoration, we will delete all of your data from your servers forever; - provide valuable advising on your company IT protection so no one can attack your again. Now, in order to start negotiations, you need to do the following: - install and run 'Tor Browser' from https://www.torproject.org/download/ - use 'Tor Browser' open http://pod4gkypkd6kykwoht3kioehhpoh4k75ybdfoe6q7hqbphrd77b32jqd.onion/ - enter your Client ID: [snip] There will be no bad news for your company after successful negotiations for both sides. But there will be plenty of those bad news if case of failed negotiations, so don't think about how to avoid it. Just focus on negotiations, payment and decryption to make all of your problems solved by our specialists within 1 day after payment received: servers and data restored, everything will work good as new. ************************************************
readme_[id]_2.txt
Hello!
Visit our Blog:
Tor Browser Links:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/
Links for normal browser:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/
>>> Your data is stolen and encrypted.
If you don't pay the ransom, the data will be published on our TOR darknet sites. Keep in mind that once your data appears on our leak site, it could be bought by your competitors at any second, so don't hesitate for a long time. The sooner you pay the ransom, the sooner your company will be safe.
>>> If you have an external or cloud backup; what happens if you don’t agree with us?
All countries have their own PDPL (Personal Data Protection Law) regulations. In the event that you do not agree with us, information pertaining to your companies and the data of your company’s customers will be published on the internet, and the respective country’s personal data usage authority will be informed. Moreover, confidential data related to your company will be shared with potential competitors through email and social media. You can be sure that you will incur damages far exceeding the amount we are requesting from you should you decide not to agree with us.
>>> How to contact with us?
- Install and run 'Tor Browser' from https://www.torproject.org/download/
- Go to http://cki3klxqycazagx3r5prae3nmfvxmwa34beknr3il4uf76vxd76akqid.onion/
- Log in using the Client ID: [snip]
>>> WARNING
DO NOT MODIFY ENCRYPTED FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
This link (TOR) is your private blog link. Right now it is only available to you but in 72 hours if you don't get in touch it will be published on our platform and will be seen by thousands of journalists: ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/[snip]/
readme_[id].txt
Hello!
Visit our Blog:
Tor Browser Links:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/
Links for normal browser:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/
>>> Your data is stolen and encrypted.
If you don't pay the ransom, the data will be published on our TOR darknet sites. Keep in mind that once your data appears on our leak site, it could be bought by your competitors at any second, so don't hesitate for a long time. The sooner you pay the ransom, the sooner your company will be safe.
>>> If you have an external or cloud backup; what happens if you don’t agree with us?
All countries have their own PDPL (Personal Data Protection Law) regulations. In the event that you do not agree with us, information pertaining to your companies and the data of your company’s customers will be published on the internet, and the respective country’s personal data usage authority will be informed. Moreover, confidential data related to your company will be shared with potential competitors through email and social media. You can be sure that you will incur damages far exceeding the amount we are requesting from you should you decide not to agree with us.
>>> How to contact with us?
- Install and run 'Tor Browser' from https://www.torproject.org/download/
- Go to http://davtdavm734bl4hkr3sr4dvfzpdzuzei2zrcor4vte4a3xuok2rxcmyd.onion/
- Log in using the Client ID: [snip]
>>> WARNING
DO NOT MODIFY ENCRYPTED FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (843)
Search, filter and paginate the victim timeline for Ransomhub. Showing 601–700 of 843.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | www.isnart.it id13850 View details | Italy | Transportation / Travel / Logistics | ||
|
ISNART (Istituto Nazionale Ricerche Turistiche) is an Italian institute specializing in tourism research. It provides insights, data, and analysis to support the tourism industry, helping businesses and policymakers make informed decisions. ISNART focuses on promoting sustainable tourism, enhancing service quality, and fostering innovation within the sector through its comprehensive studies and initiatives. |
|||||
| Ransomware | www.atwoodcherny.com id13849 View details | United States | Finance / Legal / Insurance | ||
|
Atwood & Cherny is a reputable law firm based in Boston, specializing in family law and divorce litigation. The firm is known for its personalized approach, offering services in areas such as asset division, child custody, and prenuptial agreements. With a team of experienced attorneys, Atwood & Cherny is dedicated to providing compassionate and effective legal solutions to its clients. |
|||||
| Ransomware | police.praca.gov.pl id13827 View details | Poland | Communication / Marketing | ||
|
"police.praca.gov.pl" is a Polish government website dedicated to employment services in the Police district. It provides resources for job seekers and employers, including job listings, training opportunities, and labor market information. The site aims to facilitate employment, support career development, and promote workforce initiatives within the region. |
|||||
| Ransomware | bedford.k12.oh.us id13792 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | naturalcuriosities.com id13785 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Jeffersoncountyclerk.org id13783 View details | United States | Public Sector | ||
|
No additional victim description available. |
|||||
| Ransomware | alliuminteriors.co.nz id13779 View details | New Zealand | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | lmgroup.com id13762 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | dhcgrp.com id13750 View details | United States | Healthcare / Pharma | ||
|
Dynasty Healthcare Management is a healthcare services company operating skilled nursing communities that specialize in a wide range of services including physical, occupational and speech therapy, as well as specialized care for diabetes, stroke and Alzheimer’s among many other medical conditions. |
|||||
| Ransomware | pierrediamonds.com.au id13746 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | golfoy.com id13745 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | inv-dar.com id13744 View details | Saudi Arabia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | rationalenterprise.com id13742 View details | United States | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | modernceramics.com id13740 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | hudsoncivil.com.au id13729 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.jgsummit.com.ph id13728 View details | Philippines | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | amplicon.com id13726 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | kempe.com.au id13724 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | infotexim.pe id13723 View details | Peru | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.sobha.com id13706 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | hlbpr.com id13683 View details | Communication / Marketing | |||
|
No additional victim description available. |
|||||
| Ransomware | www.normandydiesel.fr id13672 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.bahia-principe.com id13671 View details | Spain | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | retaildatallc.com id13670 View details | United States | Retail / E-commerce | ||
|
No additional victim description available. |
|||||
| Ransomware | mcdowallaffleck.com.au id13656 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | effinghamschools.com id13655 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | wgma.org id13642 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | biggreenegg.com id13641 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | nydj.com id13640 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.pharm-int.com id13639 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | verwarmingheyndrickx.be id13618 View details | Belgium | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | welevelup.com id13608 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | udch.in.th id13606 View details | Thailand | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | labor-koblenz.de id13599 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.neurologicalinstitute.com id13582 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | www.whittakersystem.com id13581 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.castelligroup.com id13580 View details | Italy | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | ach.co.th id13561 View details | Thailand | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | bpjaguar.com id13560 View details | Mexico | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | oficina.oficinadasfinancas.com.br id13559 View details | Brazil | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | mrhme.org id13555 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | panitchlaw.com id13550 View details | United States | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | cminsulation.com id13549 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | baytoti.com id13548 View details | Saudi Arabia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | sigmacontrol.eu id13493 View details | Netherlands | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.byzan.com id13488 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.garudafood.com id13456 View details | Indonesia | Agriculture / Food | ||
|
No additional victim description available. |
|||||
| Ransomware | www.kumagaigumi.co.jp id13452 View details | Japan | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.glowfm.nl id13426 View details | Netherlands | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.erma-rtmo.it id13418 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | metalfrio.com.br id13417 View details | Brazil | Manufacturing / Engineering | ||
|
No additional victim description available. |
|||||
| Ransomware | www.newcastlewa.gov id13416 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | pgd.pl id13415 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.hlbpr.com id13405 View details | Communication / Marketing | |||
|
No additional victim description available. |
|||||
| Ransomware | ceopag.com.br / ceofood.com.br id13378 View details | Brazil | Agriculture / Food | ||
|
No additional victim description available. |
|||||
| Ransomware | www.benchinternational.com id13376 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | www.cameronhodges.com id13375 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.baiminstitute.org id13366 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | eni.com&mellitahog.ly id13340 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.zepter.de id13329 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.riteaid.com id13328 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.lynchaluminum.com id13316 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.eurostrand.de id13315 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.netavent.dk id13314 View details | Denmark | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.bfcsolutions.com id13310 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | baiminstitute.org id13280 View details | United States | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | hcri.edu id13258 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | midamea.comAuction id13248 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | aedifica.com id13245 View details | Canada | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.swcs-inc.com id13243 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | www.daesangamerica.com id13237 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.finecopneumatica.com id13236 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.hauptmann.at id13235 View details | Austria | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.sfmedical.de id13231 View details | Germany | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | floridahealth.gov id13224 View details | United States | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | www.nttdata.ro id13223 View details | Romania | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Spandex.com id13198 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | midamea.com id13197 View details | Korea, Republic of | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | equinocioplay.com.br id13190 View details | Brazil | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.cipl.org.in id13189 View details | India | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.mangimifusco.it id13184 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.cloudeurope.it id13183 View details | Italy | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | coca-cola.com - Myanmar office id13182 View details | Myanmar | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | daniellegroup.com id13181 View details | United Kingdom | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | www.harrisranchbeef.com id13146 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | multi-wing.com id13141 View details | Denmark | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | bitzsoftwares.com.br id13140 View details | Brazil | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | www.sicoob.com.br id13139 View details | Brazil | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.gbricambi.it [UPDATE] id13088 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.clevo.com.twDisclose id13087 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.invisio.com id13074 View details | Denmark | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.gbricambi.it id13059 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.racalacoustics.com [UPDATE] id13052 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.liderit.es id13051 View details | Spain | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | parlorenzo.com id13042 View details | Spain | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.domainatcleveland.com id13041 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.racalacoustics.com id13006 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.clevo.com.tw<UPDATED> id12971 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | www.novabitsrl.it id12964 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | smicusa.com id12963 View details | United States | Other | ||
|
No additional victim description available. |
|||||