Ransomware Group intelligence
Redact
ActiveTrack Redact with 4 published victims and 4 known leak locations in a single intelligence view.
Overview
Redact is tracked by Breach House as a ransomware group with 4 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 11d ago | neclc36yt4yaa5lv54kh4qbhvjcvuv6nnaurqowkellytpvj3afh4aid.onion |
| Leak location 1 | Onion service | Up checked 11d ago | ursba4dbibo27dtwtgy3l2pc3ekut7helebvmy7ny3b2s3mbzph4qdad.onion |
| Leak location 3 | Web location | Unknown | neclc36yt4yaa5lv54kh4qbhvjcvuv6nnaurqowkellytpvj3afh4aid.onion/companies |
| Leak location 4 | Web location | Down checked 11d ago | ursba4dbibo27dtwtgy3l2pc3ekut7helebvmy7ny3b2s3mbzph4qdad |
Top Activity Sectors (2)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Redact, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Redact executes PowerShell scripts to deploy ransomware payloads and disable Windows Defender.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Redact executes ransomware binaries through Windows Service installation for persistence.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Redact disables security tools by terminating antivirus processes and modifying Windows event logging.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Redact deletes Volume Shadow Copy snapshots via vssadmin /delete shadows to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Redact uses file and directory discovery to enumerate critical patient records and financial databases before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1486 Data Encrypted for Impact Impact
What they do: Redact encrypts healthcare imaging files and financial ledgers using AES-256 with custom ransomware keys.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Redact inhibits system recovery by corrupting backup directories and disabling restore points.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Redact performs internal defacement by replacing pharmacy manifests and legal contracts with ransom notes.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (4)
Search, filter and paginate the victim timeline for Redact. Showing 1–4 of 4.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Hologic id30052 View details | United States | Healthcare / Pharma | ||
|
Hologic is a leading healthcare and pharmaceutical company based in the United States, specializing in medical imaging, diagnostics, and surgical products. The company offers a wide range of medical technologies and services to healthcare providers. Hologic was listed as a ransomware victim associated with Redact. |
|||||
| Ransomware | Hologic id30052 View details | United States | Healthcare / Pharma | ||
|
Sector: Medical Supplies | Revenue: $4B USD |
|||||
| Ransomware | FCCI Insurance Group id30053 View details | United States | Finance / Legal / Insurance | ||
|
FCCI Group is a US-based company operating in the finance, legal, and insurance sectors, providing various financial services to its clients. The company is headquartered in the United States and offers a range of insurance and financial products. FCCI Group was listed as a ransomware victim associated with Redact. |
|||||
| Ransomware | FCCI Insurance Group id30053 View details | United States | Finance / Legal / Insurance | ||
|
Sector: Insurance |
|||||