Ransomware Group intelligence
Revil
InactiveTrack Revil with 96 published victims and 3 known leak locations in a single intelligence view.
Overview
Revil is tracked by Breach House as a ransomware group with 96 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 1h ago | blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion |
Top Activity Sectors (17)
- Not identified 36
- Services 12
- Healthcare / Pharma 8
- Communication / Marketing 6
- Manufacturing / Engineering 5
- Finance / Legal / Insurance 4
- Public Sector 4
- Agriculture / Food 4
- IT 4
- Education 3
- Telecommunications 2
- Transportation / Travel / Logistics 2
- Retail / E-commerce 2
- Energy 1
- Construction / Real Estate 1
- Hospitality / Food & Beverage / Tourism 1
- NGOs / Associations 1
Typical Attacks (35)
▼How Revil typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via REvil.
-
T1189 Drive-by Compromise Initial Access
What they do: REvil has infected victim machines through compromised websites and exploit kits.
What that means: Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
-
T1566.001 Spearphishing Attachment Initial Access
What they do: REvil has been distributed via malicious e-mail attachments including MS Word Documents.
What that means: Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: REvil can use WMI to monitor for and kill specific processes listed in its configuration file.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: REvil has used PowerShell to delete volume shadow copies and download files.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: REvil can use the Windows command line to delete volume shadow copies and disable recovery.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1059.005 Visual Basic Execution
What they do: REvil has used obfuscated VBA macros for execution.
What that means: Adversaries may abuse Visual Basic (VB) for execution.
-
T1106 Native API Execution
What they do: REvil can use Native API for execution and to retrieve active services.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1204.002 Malicious File Execution
What they do: REvil has been executed via malicious MS Word e-mail attachments.
What that means: An adversary may rely upon a user opening a malicious file in order to gain execution.
-
What they do: REvil can modify the Registry to save encryption parameters and system information.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: REvil can inject itself into running processes on a compromised host.
What that means: Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.
What that means: Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.
-
What they do: REvil can launch an instance of itself with administrative rights using runas.
What that means: Adversaries may create a new process with an existing token to escalate privileges and bypass access controls.
-
T1027.011 Fileless Storage Stealth
What they do: REvil can save encryption parameters and system information in the Registry.
What that means: Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: REvil has used encrypted strings and configuration files.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: REvil can mimic the names of known executables.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: REvil can mark its binary code for deletion after reboot.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: REvil can decode encrypted strings to enable execution of commands and payloads.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1480.002 Mutual Exclusion Stealth
What they do: REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host.
What that means: Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: REvil can connect to and disable the Symantec server on the victim's network.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: REvil can force a reboot in safe mode with networking.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1007 System Service Discovery Discovery
What they do: REvil can enumerate active services.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: REvil can query the Registry to get random file extensions to append to encrypted files.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1069.002 Domain Groups Discovery
What they do: REvil can identify the domain membership of a compromised host.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: REvil has the ability to identify specific files and directories that are not to be encrypted.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1614.001 System Language Discovery Discovery
What they do: REvil can check the system language using GetUserDefaultUILanguage and GetSystemDefaultUILanguage.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1680 Local Storage Discovery Discovery
What they do: REvil can identify system drive information on a compromised host.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1071.001 Web Protocols Command and Control
What they do: REvil has used HTTP and HTTPS in communication with C2.
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: REvil can download a copy of itself from an attacker controlled IP address to the victim machine.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: REvil has encrypted C2 communications with the ECIES algorithm.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: REvil can exfiltrate host and malware information to C2 servers.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1485 Data Destruction Impact
What they do: REvil has the capability to destroy files and folders.
What that means: Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
-
T1486 Data Encrypted for Impact Impact
What they do: REvil can encrypt files on victim systems and demands a ransom to decrypt the files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: REvil has the capability to stop services and kill processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (7)
▼Software Revil has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
revil2.txt
---=== Welcome. Again. ===---
We strongly encourage You to pay your attention to this message and read it to the end.
All Your files are encrypted, and currently unavailable, now all files on your system has extension {EXT}
Before that, all of your most important personal and business
files were backed up to our secure offline storage.
We took them for temporary storage - but we don't need your
files and we are not personally interested in your business.
Our encryption algorithm is the most technically difficult and max resistant to burglary.
Only OUR specialists can decrypted your files without loss(!)
Any attempts to decrypt files on your own lead to damage them beyond repair(!)
Best way to you will be consent to negotiations and mutual agreement between us.
To connect us you need to download TOR browser and follow the link to begin
negotiations.(You can find full instructions below.)
We are waiting You and ready to listen all
your offers and discuss them.
If You will ignore this letter - we will have to sell
closed auction all yours private files, photoes, business correspondence,
documents and business files + with our analysis of your work
activity (weakness of your business, financial violations and the opportunity
to profit from this information). It will offset our financial losses.
Or we'll just put all your files in the public domain, where everyone can download
and use them as they wish.
* For TOR Browser
http://dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion/
We are known as "Sodinokibi (REvil) Ransomware". For example, this article:
https://www.coveware.com/blog/2019/7/15/ransomware-amounts-rise-3x-in-q2-as-ryuk-amp-sodinokibi-spread
You have a guarantee that your files will be returned 100 %.
And remember, this is only business, nothing personal..
We have a concept of business honor, and we can promise something if we come to a mutual agreement:
1. We guarantee to decrypt all your files in the shortest possible time
2. We will delete all your files and forget about your company.
3. We will show your weaknesses in your networks.
.-= INSTRUCTIONS TO CONNECT =-.
How to get access on website?
You have two ways:
1) [Recommended] Using a TOR browser!
a) Download and install TOR browser from this site: https://torproject.org/
b) Open our website: http://aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion/{UID}
2) If TOR blocked in your country, try to use VPN! But you can use our secondary website. For this:
a) Open your any browser (Chrome, Firefox, Opera, IE, Edge)
b) Open our secondary website: http://decoder.re/{UID}
Warning: secondary website can be blocked, thats why first variant much better and more available.
When you open our website, put the following data in the input form:
Key:
[snip]
----------------------------------------------------------------------------------
!!! DANGER !!!
DONT try to change files by yourself,
DONT use any third party software for restoring your data or antivirus solutions -
its may entail damge of the private key and, as result, The Loss all your data!
revil3.txt
---=== Welcome. Again. ===--- >> Whats Happen Your files are encrypted, and currently unavailable. You can check it: all files on your system has extension lgzcfcr. By the way, everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER). >> What guarantees Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will not cooperate with us. Its not in our interests. To check the ability of returning files, You should go to our website. There you can decrypt one file for free. That is our guarantee. If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause just we have the private key. In practice - time is much more valuable than money. >> Sensitive Data Sensitive data on your network was DOWNLOADED. If you DON'T WANT your sensitive data to be PUBLISHED in our blog - you have to act quickly. You should check our blog, using Tor Browser, your data could already be published http://blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd.onion Data includes: - Employees personal data. - Complete network map including credentials for local and remote services. - Private financial information including: clients data, bills, budgets, annual reports, bank statements. - Manufacturing documents including: datagrams, schemas, drawings in solidworks format - And more... >> How to get access to the website Using a TOR browser 1) Download and install TOR browser from this site: https://torproject.org/ 2) Open our website: http://landxxeaf2hoyl2jvcwuazypt6imcsbmhb7kx3x33yhparvtmkatpaad.onion 3) When you open our website, put the following data in the input form: [snip] ----------------------------------------------------------------------------------------- DANGER DON'T try to change files by yourself, DON'T use any third party software for restoring your data or antivirus solutions - its may entail damage of the private key and, as result, The Loss all data. ONE MORE TIME: Its in your interests to get your files back. From our side, we (the best specialists) make everything for restoring, but please should not interfere.
revil1.txt
---=== Welcome. Again. ===---
[+] Whats Happen? [+]
Your files are encrypted, and currently unavailable. You can check it: all files on your system has extension {EXT}.
By the way, everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER).
[+] What guarantees? [+]
Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will not cooperate with us. Its not in our interests.
To check the ability of returning files, You should go to our website. There you can decrypt one file for free. That is our guarantee.
If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause just we have the private key. In practice - time is much more valuable than money.
[+] How to get access on website? [+]
You have two ways:
1) [Recommended] Using a TOR browser!
a) Download and install TOR browser from this site: https://torproject.org/
b) Open our website: http://aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion/{UID}
2) If TOR blocked in your country, try to use VPN! But you can use our secondary website. For this:
a) Open your any browser (Chrome, Firefox, Opera, IE, Edge)
b) Open our secondary website: http://decryptor.cc/{UID}
Warning: secondary website can be blocked, thats why first variant much better and more available.
When you open our website, put the following data in the input form:
Key:
[snip]
-----------------------------------------------------------------------------------------
!!! DANGER !!!
DONT try to change files by yourself, DONT use any third party software for restoring your data or antivirus solutions - its may entail damage of the private key and, as result, The Loss all data.
!!! !!! !!!
ONE MORE TIME: Its in your interests to get your files back. From our side, we (the best specialists) make everything for restoring, but please should not interfere.
!!! !!! !!!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (96)
Search, filter and paginate the victim timeline for Revil. Showing 1–96 of 96.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | kusd.edu id4684 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sunknowledge Services Inc id4683 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | medibank.com.au id4529 View details | Australia | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Midea Group id4065 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Doosan Group id3899 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OptiProERP is a leading global provider of industry-specific ERP solutions for manufacture id3860 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ludwig Freytag Group id3419 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unicity International id3360 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stratford University id3252 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Asfaltproductienijmegen id3225 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CYMZ id3224 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.oil-india.com id3223 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Visotec Group www.visotec.com id3221 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PTT Exploration and Production - 720GB id1615 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ECKERD PERU S.A, INKAFARMA, MIFARMA id1587 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Join us on RAMP id1575 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ronmor Holdings id1498 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Fimmick CRM Hong Kong (www.fimmick.com) id1487 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Fimmick CRM Honk Kong (www.fimmick.com) id1485 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Spiezle Architectural Group Inc. id1380 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ohiograting.com id1355 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Apex America id875 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Allen, Dyer, Doppelt, & Gilchrist, P.A. id874 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Betenbough Homes id873 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CEC Vibration Products id872 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ENPOL LLC id871 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Iaffaldano, Shaw & Young LLP id870 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | angstrom automotive group id869 View details | United States | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | Agile Property Holdings id868 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Möbelstadt Sommerlad id867 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gosiger id866 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | neroindustry.com id865 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | kuk.de / KREBS + KIEFER / 500GB id864 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KASEYA ATTACK INFO id863 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Daylesford - BHoldings - Bamford - The Wild Rabbit id862 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hx5, LLC id861 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | inocean.no / 2000 GB id860 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Primo Water id859 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | lstaff.com / atworksprofessional / atworks.com id858 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | South Carolina Legal Services breach id857 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ensingerplastics.com id856 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kaseya clients id662 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | University Medical Center id659 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Fujifilm id643 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | JBS (meat processor) id641 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sol Oriens id615 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brazil's Tribunal de Justiça do Estado do Rio Grande do Sul id608 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Apple MacBook via supplier Quanta Computer id607 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Asteelflash id594 View details | France | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | Pierre Fabre id593 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Acer id588 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gyrodata Incorporated id584 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Standley Systems (vendor to Healthcare Sector) id565 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Dairy Farm Group id561 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Transform Hospital Group LTD id536 View details | United Kingdom | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Managed[.]com (Web Hosting Provider for Columbus County, NC, Griffin Hospital in CT, Arizona Judicial Branch, and Jackson County, OR, among others) id525 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Beacon Health Solutions id489 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Banco Estado (Public Bank) id476 View details | Chile | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Haberdashers’ Monmouth Schools id475 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ma Labs id464 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brown-Forman Corp (alcohol manufacturer) id453 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Valley Health Systems id456 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | National Western Life (insurance) id458 View details | United States | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Telecom Argentina id443 View details | Argentina | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Cooke County Sheriff's Office id439 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Actuaries and Associates (retirement specialist) id434 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | ADIF (Spanish railway manager) id435 View details | Spain | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||
| Ransomware | AAA Ambulance Service id437 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Lion (Beverage giant) id405 View details | Australia | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | Symbiotic LLC id394 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Goodman Mintz LLP id395 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | ZEGG Hotels & Store id396 View details | Switzerland | Retail / E-commerce | — | |
|
No additional victim description available. |
|||||
| Ransomware | Crozer-Keystone Health System (Delaware County, PA) id397 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Telkom id381 View details | South Africa | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sri Lanka Telecom id377 View details | Sri Lanka | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Insport (sports store) id376 View details | Australia | Retail / E-commerce | — | |
|
No additional victim description available. |
|||||
| Ransomware | Elexon id375 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Harvest Food Distributors (San Diego) id363 View details | United States | Agriculture / Food | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sherwood Food Distributors (Detroit) id364 View details | United States | Agriculture / Food | — | |
|
No additional victim description available. |
|||||
| Ransomware | National Association of Eating Disorders id350 View details | United States | NGOs / Associations | — | |
|
No additional victim description available. |
|||||
| Ransomware | SeaChange International (supplier of video delivery software) id351 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Town of Jupiter id346 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | 10x Genomics id341 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brooks International (business management consultant) id334 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Geidi (IT serves) id335 View details | Australia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Mountain View Los Altos Union High School District id322 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Gedia Automotive Group id320 View details | Germany | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | Tillamook County id317 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Artech Information Systems id314 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Travelex id312 View details | United Kingdom | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||
| Ransomware | LogicalNet (MSP) Schenectady, NY id309 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Synoptek id308 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | CyrusOne id304 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Englewood Complete Technology Services id298 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Alphabroder id289 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Percsoft and the Digital Dental Record id283 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||