Ransomware Group intelligence
Raworld
InactiveTrack Raworld with 127 published victims and 2 known leak locations in a single intelligence view.
Overview
Raworld is tracked by Breach House as a ransomware group with 127 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 1h ago | pa32ymaeu62yo5th5mraikgw5fcvznnsiiwti42carjliarodltmqcqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion |
Top Activity Sectors (13)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Raworld, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: raworld executes PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: raworld leverages registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: raworld disables antivirus tools and modifies security software configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: raworld encodes victim files with symmetric encryption keys before deployment to hinder analysis.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: raworld deletes Volume Shadow Copies and backup directories via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: raworld performs remote system discovery to map network topology and identify high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: raworld queries system network connections to identify active services and potential lateral movement paths.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: raworld uses network share discovery to identify accessible SMB shares for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: raworld encrypts victim files using a custom ransomware algorithm to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: raworld displays ransom notes and defaces victim systems with malicious banners to pressure decryption.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (5)
▼Software Raworld has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README_Howtorecover.txt
# RA World
----
## Notification
Hello! "[snip]"!
We are RA World Ransomware!
Your data are stolen and encrypted when you read this letter.
We had copied more than 85 GB data to our server.
Don't worry, your data will not be published if you do what we want.
But if you don't pay, we will release the data after 30 days, contact your customers and regulators and destroy your system again and again.
## What do you need to do?
Contact us and discuss how to protect your files.
We can decrypt some files for free to prove that the decryption tool works properly.
## How contact us?
You can visit online chat room or use qTox to contact us.
[+] online chat room info:
RoomID:[snip]
Password:[snip]
Link:http://raworlddecssyq43oim3hxhc5oxvlbaxuj73xbz2pbbowso3l4kn27qd.onion
[+] qTox info:
Our qTox ID is: 1C2163487A1356EA767FD0F77A29553DF0541F977FA9958EC8CD7530E3BDBB3D8468BD7B0386
We don't have any other contacts.
If there is no contact within 3 days, we will make sample files public.
If there is no contact within 7 days, we will stop communicating and release data in batches.
You can get 50% discount and some time for negotiation if you contact us within 3 days.
## Sample files release link:
We select some files as samples that you can download and check it:
[+] https://gofile.io/d/[snip]
## RA World Office Site:
[Temporary address] http://66.78.40.205/raworld
[Permanent address] http://raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion
## Other Tips
You can download qTox from their official website:
[+] https://qtox.github.io
You can use Tor Browser to open .onion url.
Ger more information from Tor office website:
[+] https://www.torproject.org
Data breach warning.txt
# RA World ---- ## Notification Your data are stolen and encrypted when you read this letter. We have copied all data to our server. Don't worry, your data will not be made public if you do what I want. But if you don't pay, we will release the data, contact your customers and regulators and destroy your system again. We can decrypt some files to prove that the decrypt tool works correctly. ## What we want? Contact us, pay for ransom. If you pay, we will provide you the programs for decryption and we will delete your data where on our servers. If not, we will leak your datas and your company will appear in the shame list below. If not, we will email to your customers and report to supervisory authority. ## How contact us? We use qTox to contact, you can download qTox from office website: https://qtox.github.io Our qTox ID is: 358AC0F6C813DD4FD243524F040E2F77969278274BD8A8945B5041A249786E32CC784580F2EC We have no other contacts. If there is no contact within 3 days, you will appear on our website and we will make sample files public. If there is no contact within 7 days, we will stop communicating and release data in batches. The longer time, the higher ransom. ## RA World Office Site: [Permanent address] http://raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion [Temporary address] http://161.35.200.18 ## Sample files release link: Sample files: https://gofile.io/d/[snip] ## Unpay Victim Lists *** You'll be here too if you don't pay! *** *** More and more people will get your files! *** [snip] You can use Tor Browser to open .onion url. Ger more information from Tor office website: https://www.torproject.org
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (127)
Search, filter and paginate the victim timeline for Raworld. Showing 1–100 of 127.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Watertown Public Schools id16422 View details | United States | Education | ||
|
[AI generated] Watertown Public Schools is a school district located in Watertown, Massachusetts. It serves a diverse community, offering education from pre-kindergarten through 12th grade. The district is committed to fostering an inclusive environment and emphasizes academic excellence, critical thinking, and social-emotional development. Schools include elementary, middle, and high schools, focusing on preparing students for future success. |
|||||
| Ransomware | STEG Stadtentwicklung id16421 View details | Germany | Communication / Marketing | ||
|
[AI generated] STEG Stadtentwicklung is a company focused on urban development and planning. It specializes in revitalizing urban areas, creating sustainable urban environments, and promoting community involvement in development projects. The company collaborates with municipalities, private investors, and stakeholders to design and implement projects that enhance urban life, ensuring economic, social, and environmental sustainability. |
|||||
| Ransomware | Ire-Omba SpA id16420 View details | Italy | Communication / Marketing | ||
|
[AI generated] Ire-Omba SpA is an Italian company specializing in the production and export of wooden products, particularly timber and finished wood components. With a focus on sustainability and quality, they source wood responsibly and serve various industries, including construction and furniture. The company is known for its expertise in processing and treating wood to meet diverse client specifications. |
|||||
| Ransomware | Gr****up id16276 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | De****ep id16275 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Ri****uk id16274 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | NE****IT id16273 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Wa****ls id16272 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | ST****ng id16271 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Compass Communications id15994 View details | New Zealand | Communication / Marketing | ||
|
[AI generated] Compass Communications is a telecommunications company based in New Zealand. It offers a range of services, including broadband internet, mobile phone plans, and home phone services. Known for competitive pricing and customer-focused service, Compass Communications caters to both residential and business customers, aiming to provide reliable connectivity solutions across the country. |
|||||
| Ransomware | NTrust id15862 View details | United States | Services | ||
|
[AI generated] NTrust is a global real estate and facilities management services company that specializes in lease administration, lease accounting, and technology solutions. They offer services such as transaction management, data abstraction, and portfolio management. NTrust leverages advanced software and analytics to optimize real estate operations, helping clients streamline processes and improve decision-making. |
|||||
| Ransomware | Co****ns id15861 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | NT****st id15791 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Contrack Facilities Management id15694 View details | United Arab Emirates | Services | ||
|
[AI generated] Contrack Facilities Management is a company specializing in comprehensive facilities management services. They provide solutions for property maintenance, operations, and support services. Their offerings often include building maintenance, cleaning, security, and energy management, tailored to enhance the efficiency and sustainability of client properties. They cater to various sectors, ensuring optimal facility performance. |
|||||
| Ransomware | Ventana Micro Systems id15693 View details | United States | IT | ||
|
[AI generated] Ventana Micro Systems is a technology company specializing in the development of high-performance RISC-V processors. The company focuses on delivering scalable and efficient computing solutions for data centers and edge computing applications. By leveraging the open RISC-V architecture, Ventana aims to provide innovative, customizable processors that balance performance, power efficiency, and flexibility. |
|||||
| Ransomware | Lu****ng id15692 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Me****or id15691 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Co****nt id15607 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Gulf Energy Maritime id15586 View details | United Arab Emirates | Energy | ||
|
[AI generated] Gulf Energy Maritime is a prominent maritime shipping company based in the United Arab Emirates. It specializes in the transportation of crude oil, petroleum products, and chemicals. The company operates a modern fleet of tankers, ensuring safe and efficient delivery while adhering to high environmental and safety standards. It plays a critical role in the global energy supply chain. |
|||||
| Ransomware | Ge****og id15376 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Gu****me id15375 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Orange County Pathology Medical Group id15272 View details | United States | Healthcare / Pharma | ||
|
[AI generated] Orange County Pathology Medical Group is a healthcare organization specializing in pathology services. Located in Orange County, California, the group provides diagnostic services and laboratory testing to support patient care. Their team of skilled pathologists works closely with healthcare providers to deliver accurate and timely results, contributing to effective patient diagnosis and treatment. |
|||||
| Ransomware | SK Gas id15271 View details | Korea, Republic of | Energy | ||
|
[AI generated] SK Gas is a South Korean company primarily involved in the liquefied petroleum gas (LPG) industry. It is a subsidiary of the SK Group, one of South Korea's largest conglomerates. SK Gas operates in the import, storage, and distribution of LPG, serving both domestic and international markets. The company also engages in energy-related services and infrastructure development, focusing on sustainable and innovative energy solutions. |
|||||
| Ransomware | BULLONERIE GALVIT id15077 View details | Italy | Manufacturing / Engineering | ||
|
[IA generated] BULLONERIE GALVIT is a company specializing in the production and distribution of fasteners and metal components. Known for its high-quality standards, the company offers a wide range of products including bolts, nuts, and screws, catering to various industries such as construction and manufacturing. Their focus on innovation and customer service has established them as a trusted name in the sector. |
|||||
| Ransomware | BU****IT id15010 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | TR****GB id14992 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Matouk Bassiouny id14979 View details | Egypt | Finance / Legal / Insurance | ||
|
Matouk Bassiouny is a prominent law firm based in Cairo, Egypt, known for its expertise in arbitration, corporate law, and dispute resolution. The firm serves a diverse clientele, including multinational corporations and local businesses, offering legal services across various sectors. With a strong regional presence, Matouk Bassiouny is recognized for its skilled legal team and client-focused approach. |
|||||
| Ransomware | Digital Engineering id14957 View details | Germany | IT | ||
|
Digital Engineering is a company specializing in innovative technology solutions and services. They focus on designing and developing digital systems that enhance business operations. Their offerings include software development, systems integration, and consulting services. With a team of skilled engineers, Digital Engineering aims to drive digital transformation and improve efficiency for their clients. |
|||||
| Ransomware | Prince Pipes id14916 View details | India | Communication / Marketing | ||
|
Prince Pipes and Fittings Limited is a leading Indian manufacturer of polymer pipes and fittings. Established in 1987, the company specializes in producing high-quality piping solutions for plumbing, irrigation, and sewage needs. With a strong distribution network across India, Prince Pipes offers a wide range of products, including CPVC, UPVC, and PPR pipes, emphasizing innovation and sustainability in its operations. |
|||||
| Ransomware | P+B Team Aircargo id14915 View details | Switzerland | Transportation / Travel / Logistics | ||
|
P+B Team Aircargo is a logistics company specializing in air freight services. They focus on providing efficient and reliable cargo solutions tailored to client needs. With expertise in handling various types of goods, they ensure timely and secure transportation. Their services often include customs clearance, tracking, and end-to-end logistics management, aiming to optimize the supply chain for businesses. |
|||||
| Ransomware | Pr****es id14850 View details | Communication / Marketing | |||
|
No additional victim description available. |
|||||
| Ransomware | Di**ng id14849 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | PB**ce id14848 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Ma****ny id13686 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Ascent Group id13591 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Kusum Group of Companies id13518 View details | India | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | TheLutheranFoundation id13517 View details | United States | NGOs / Associations | ||
|
No additional victim description available. |
|||||
| Ransomware | Melchers Singapore id13516 View details | Singapore | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | As****fs id13515 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | GWF Frankenwein id12247 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Reederei Jüngerhans id12246 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Gr****en id12245 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Me****ng id12244 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Po**** id12243 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Mainwein id12131 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | charlesparsons (Attack again) id12084 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Ma****in id12083 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | La****up id12082 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | UnivationTechnologies id11685 View details | United States | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | Autoglass id11684 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | charlesparsons id11683 View details | Australia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Po****sa id11682 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Gimex id11625 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Victor Fauconnier id11624 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Un****es id11623 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Al****ch id11622 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Se****bH id11621 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Gi****ex id11507 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Innomotive Systems Hainichen GmbH id11487 View details | Germany | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | KICO GROUP id11482 View details | Germany | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Sterling Plumbing Inc id11475 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | C&C Casa e Construção Ltda id11474 View details | Brazil | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | TUBEX Aluminium Tubes id11473 View details | Austria | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | SchwarzGrantz id11348 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Title Management Inc id11347 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Pascoe International id11346 View details | United Kingdom | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Bisco Industries id11324 View details | United States | Other | ||
|
biscoind.com is the website for bisco industries, a California-based distributor of electronic components, fasteners, and related assembly hardware. The company is headquartered in Anaheim, California, and serves industries including aerospace, communication, computer, and fabrication. Its website describes online pricing on thousands of parts and same-day shipment, reflecting a broad industrial supply offering. The listing identifies biscoind.com as a ransomware victim associated with raworld. |
|||||
| Ransomware | Bluelinea id11323 View details | France | Other | ||
|
Bluelinea.com is the website of Bluelinea, a French company based in Versailles that provides health services and teleassistance for elderly and disabled people. Its offerings include connected healthcare, remote assistance, and electronic surveillance systems designed to support safety, autonomy, and caregiving in homes and care facilities. Public company profiles also describe Bluelinea as operating in the healthcare sector with services for seniors and home support in France. In threat-intelligence listings, bluelinea.com was associated with a ransomware victim entry linked to raworld. |
|||||
| Ransomware | Deepnoid id11322 View details | Korea, Republic of | Other | ||
|
Deepnoid.com is the website of DEEPNOID, a South Korean company founded in 2008 and based in Seoul. It develops artificial intelligence solutions for healthcare, including diagnostic support, medical imaging data management, and AI tools that help automate reading and reporting workflows. The company also presents AI offerings for security, manufacturing, and broader digital transformation use cases. Deepnoid.com was listed as a ransomware victim associated with raworld. |
|||||
| Ransomware | Eastern Media International Corporation id11321 View details | Taiwan, Province of China | Communication / Marketing | ||
|
Eastern Media International Corporation is a Taiwan-based enterprise headquartered in Taipei and listed on the Taiwan Stock Exchange. Its business spans cargo handling and warehousing, trading, media and audio-visual advertising, retail of pet food and supplies, pet grooming, and leisure and tourism services. Company materials also describe it as part of the Eastern Group, with operations extending into communication technologies and related media activities. In threat-intelligence listings, Eastern Media International Corporation was reported as a ransomware victim associated with raworld. |
|||||
| Ransomware | Eyegene id11320 View details | United States | Other | ||
|
Eyegene is a biotechnology name associated with gene and cell therapy work, with publicly available company listings describing it as a clinical-stage biotech focused on innovative treatments and prevention. Available profiles place the company in the United States and describe its offerings in research-driven biopharmaceutical development. Separate NIH materials also use the eyeGENE name for a U.S. research network supporting rare inherited eye disease studies, so the name may refer to more than one entity. In this listing, Eyegene was identified as a ransomware victim associated with raworld. |
|||||
| Ransomware | Insurance Providers Group id11319 View details | United States | Finance / Legal / Insurance | ||
|
Insurance Providers Group is an independent insurance agency based in Champaign, Illinois, serving Central and Southern Illinois since 1996. The agency writes all lines of insurance, including commercial, property, casualty, health, group health, auto, and farm insurance, representing multiple insurance companies to offer diverse products. It provides risk management solutions and group benefits primarily to small to medium-sized businesses in the Finance and Insurance sector. Insurance Providers Group was listed as a ransomware victim associated with the threat actor raworld. |
|||||
| Ransomware | Thaire id11318 View details | Thailand | Other | ||
|
Thaire, or Thai Reinsurance Public Company Limited, is a Bangkok-based reinsurer in Thailand’s financial services sector. The company provides reinsurance coverage for non-life insurers and focuses on major property and casualty lines. Its business includes property, casualty, engineering, marine, and related risk-transfer services for local and selected foreign clients. The firm operates from Bangkok and serves insurance partners that use reinsurance to diversify risk. It was listed as a ransomware victim associated with raworld. |
|||||
| Ransomware | Decimal Point Analytics Pvt id11317 View details | India | Other | ||
|
Decimal Point Analytics is an India-based technology and financial research consulting company with a Mumbai headquarters and a U.S. office in New York. Its website describes the firm as delivering AI-driven data analytics, market research, and automation services for smarter decision-making. Company profiles also describe it as a global provider of research and analytics solutions, with offerings spanning data management and predictive insights. In threat-intelligence indexing, decimalpointanalytics.com was listed as a ransomware victim associated with raworld. |
|||||
| Ransomware | Wealth Enhancement Group id11316 View details | United States | Services | ||
|
WealthEnhancement.com is the website of Wealth Enhancement, a US-based financial services and wealth management firm headquartered in Plymouth, Minnesota, with offices across multiple states. The firm offers advisory services, including investment management, retirement income planning, tax services, estate planning, insurance consultancy, and related client support. Its website and public profiles describe a nationwide, independent advisory practice serving individuals and families through local advisor teams and specialist support. The company was listed as a ransomware victim associated with raworld. |
|||||
| Ransomware | Zurvita id11315 View details | United States | Other | ||
|
Zurvita.com belongs to Zurvita, a US health and wellness company headquartered in Irving, Texas. The company has sold direct-selling nutritional products, including energy and wellness drinks, protein shakes, cleanses, and related supplements. Public business profiles describe its market as wellness and fitness services, with a focus on consumer health products in the United States and other markets. Zurvita.com was listed as a ransomware victim associated with raworld. |
|||||
| Ransomware | Piex Group id11314 View details | France | Services | ||
|
Piex Group is a France-based company in Les Ulis, near Paris, with corporate records and company profiles placing it at 3 to 7 Avenue du Cap Horn. Public descriptions identify it as a specialist in exporting healthcare products, including medicines and related health and wellness goods. Its activity is also described in French business records as wholesale trade in health products, including human medicines, medical devices, dietary supplements, and personal care items. In this catalog, Piex Group was listed as a ransomware victim associated with raworld. |
|||||
| Ransomware | Yuxin Automobile Co.Ltd id11313 View details | Singapore | Telecommunications | ||
|
No additional victim description available. |
|||||
| Ransomware | 24/7 Express Logistics id11312 View details | United States | Transportation / Travel / Logistics | ||
|
No additional victim description available. |
|||||
| Ransomware | Aceromex id11311 View details | Mexico | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Chung Hwa Chemical Industrial Works id11310 View details | Taiwan, Province of China | Manufacturing / Engineering | ||
|
No additional victim description available. |
|||||
| Ransomware | SUMMIT VETERINARY PHARMACEUTICALS LIMITED id11309 View details | United Kingdom | Healthcare / Pharma | ||
|
No additional victim description available. |
|||||
| Ransomware | Informist Media id11308 View details | India | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | ALAB laboratoria id11307 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Di Martino Group id11306 View details | Italy | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Rockford Gastroenterology Associates id11305 View details | United States | Energy | ||
|
No additional victim description available. |
|||||
| Ransomware | HALLIDAYS GROUP LIMITED id11304 View details | United Kingdom | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Die Unfallkasse Thüringen id11303 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Wurzbacher id11302 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Ranzijn id11301 View details | Netherlands | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | SHORTERM GROUP id11300 View details | United Kingdom | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | In****GmbH id11299 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | KI****UP id11298 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | St****nc id11297 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Sc****tz id11296 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Di Martino Group id10228 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Rockford Gastroenterology Associates id10227 View details | United States | Energy | ||
|
No additional victim description available. |
|||||
| Ransomware | HALLIDAYS GROUP LIMITED id10226 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Die Unfallkasse Thüringen id10225 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | NIDEC GPM GmbH id10224 View details | Germany | Other | ||
|
No additional victim description available. |
|||||