Ransomware Group intelligence
Raworld
InactiveTrack Raworld with 127 published victims and 2 known leak locations in a single intelligence view.
Overview
Raworld is tracked by Breach House as a ransomware group with 127 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 1h ago | pa32ymaeu62yo5th5mraikgw5fcvznnsiiwti42carjliarodltmqcqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion |
Top Activity Sectors (13)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Raworld, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: raworld executes PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: raworld leverages registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: raworld disables antivirus tools and modifies security software configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: raworld encodes victim files with symmetric encryption keys before deployment to hinder analysis.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: raworld deletes Volume Shadow Copies and backup directories via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: raworld performs remote system discovery to map network topology and identify high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: raworld queries system network connections to identify active services and potential lateral movement paths.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: raworld uses network share discovery to identify accessible SMB shares for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: raworld encrypts victim files using a custom ransomware algorithm to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: raworld displays ransom notes and defaces victim systems with malicious banners to pressure decryption.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (5)
▼Software Raworld has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README_Howtorecover.txt
# RA World
----
## Notification
Hello! "[snip]"!
We are RA World Ransomware!
Your data are stolen and encrypted when you read this letter.
We had copied more than 85 GB data to our server.
Don't worry, your data will not be published if you do what we want.
But if you don't pay, we will release the data after 30 days, contact your customers and regulators and destroy your system again and again.
## What do you need to do?
Contact us and discuss how to protect your files.
We can decrypt some files for free to prove that the decryption tool works properly.
## How contact us?
You can visit online chat room or use qTox to contact us.
[+] online chat room info:
RoomID:[snip]
Password:[snip]
Link:http://raworlddecssyq43oim3hxhc5oxvlbaxuj73xbz2pbbowso3l4kn27qd.onion
[+] qTox info:
Our qTox ID is: 1C2163487A1356EA767FD0F77A29553DF0541F977FA9958EC8CD7530E3BDBB3D8468BD7B0386
We don't have any other contacts.
If there is no contact within 3 days, we will make sample files public.
If there is no contact within 7 days, we will stop communicating and release data in batches.
You can get 50% discount and some time for negotiation if you contact us within 3 days.
## Sample files release link:
We select some files as samples that you can download and check it:
[+] https://gofile.io/d/[snip]
## RA World Office Site:
[Temporary address] http://66.78.40.205/raworld
[Permanent address] http://raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion
## Other Tips
You can download qTox from their official website:
[+] https://qtox.github.io
You can use Tor Browser to open .onion url.
Ger more information from Tor office website:
[+] https://www.torproject.org
Data breach warning.txt
# RA World ---- ## Notification Your data are stolen and encrypted when you read this letter. We have copied all data to our server. Don't worry, your data will not be made public if you do what I want. But if you don't pay, we will release the data, contact your customers and regulators and destroy your system again. We can decrypt some files to prove that the decrypt tool works correctly. ## What we want? Contact us, pay for ransom. If you pay, we will provide you the programs for decryption and we will delete your data where on our servers. If not, we will leak your datas and your company will appear in the shame list below. If not, we will email to your customers and report to supervisory authority. ## How contact us? We use qTox to contact, you can download qTox from office website: https://qtox.github.io Our qTox ID is: 358AC0F6C813DD4FD243524F040E2F77969278274BD8A8945B5041A249786E32CC784580F2EC We have no other contacts. If there is no contact within 3 days, you will appear on our website and we will make sample files public. If there is no contact within 7 days, we will stop communicating and release data in batches. The longer time, the higher ransom. ## RA World Office Site: [Permanent address] http://raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion [Temporary address] http://161.35.200.18 ## Sample files release link: Sample files: https://gofile.io/d/[snip] ## Unpay Victim Lists *** You'll be here too if you don't pay! *** *** More and more people will get your files! *** [snip] You can use Tor Browser to open .onion url. Ger more information from Tor office website: https://www.torproject.org
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (127)
Search, filter and paginate the victim timeline for Raworld. Showing 101–127 of 127.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ALAB laboratoria id9713 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Al****ia id9617 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Aceromex id9600 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Chung Hwa Chemical Industrial Works id9599 View details | Manufacturing / Engineering | |||
|
No additional victim description available. |
|||||
| Ransomware | SUMMIT VETERINARY PHARMACEUTICALS LIMITED id9598 View details | Healthcare / Pharma | |||
|
No additional victim description available. |
|||||
| Ransomware | Informist Media id9597 View details | Communication / Marketing | |||
|
No additional victim description available. |
|||||
| Ransomware | Yuxin Automobile Co.Ltd id9418 View details | Telecommunications | |||
|
No additional victim description available. |
|||||
| Ransomware | Aceromex (Unpay-Start Leaking) id9417 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | 24/7 Express Logistics (Unpay-Start Leaking) id8587 View details | Transportation / Travel / Logistics | |||
|
No additional victim description available. |
|||||
| Ransomware | 24/7 Express Logistics id8540 View details | Transportation / Travel / Logistics | |||
|
No additional victim description available. |
|||||
| Ransomware | Zurvita id8477 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Piex Group id8476 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Yuxin Automobile Co.Ltd (裕信汽車) id8475 View details | Telecommunications | |||
|
No additional victim description available. |
|||||
| Ransomware | I****n id8474 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | 24****r id8473 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | He****rk id8472 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Yuxin Automobile Co.Ltd(裕信汽車) id8413 View details | Telecommunications | |||
|
No additional victim description available. |
|||||
| Ransomware | Y****e id8349 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | 2****r id8348 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | I****n id8347 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | P****X id8053 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Z****ta id8052 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | De****int id7450 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Bl****ea id7422 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Target-9 id6969 View details | Retail / E-commerce | |||
|
No additional victim description available. |
|||||
| Ransomware | Target-8 id6921 View details | Retail / E-commerce | |||
|
No additional victim description available. |
|||||
| Ransomware | EyeGene id6359 View details | Other | |||
|
No additional victim description available. |
|||||