Ransomware Group intelligence
Rook
InactiveTrack Rook with 9 published victims and 1 known leak locations in a single intelligence view.
Overview
Rook is tracked by Breach House as a ransomware group with 9 published victims.
Japan is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion |
Top Activity Sectors (4)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Rook, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: rook executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: rook disables security tools like antivirus software and monitoring agents to prevent detection and response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: rook deletes Volume Shadow Copies and backup directories via command-line tools to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: rook performs remote system discovery to identify additional hosts and network segments for targeted encryption.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: rook uses process discovery to identify critical system processes for targeting during lateral movement and evasion.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: rook exploits SMB/Windows Admin Shares to spread ransomware across networked systems within the victim environment.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: rook encrypts victim files using custom ransomware binaries, targeting documents and backups for maximum impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: rook calls system recovery inhibition commands to block automatic restoration attempts after encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
rook.txt
-----------Welcome. Again. -------------------- [+]Whats Happen?[+] Your files are encrypted,and currently unavailable. You can check it: all files on you computer has expansion robet. By the way,everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER). [+] What guarantees?[+] Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will not cooperate with us. Its not in our interests. To check the file capacity, please send 3 files not larger than 1M to us, and we will prove that we are capable of restoring. If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data,cause just we have the private key. In practise - time is much more valuable than money. If we find that a security vendor or law enforcement agency pretends to be you to negotiate with us, we will directly destroy the private key and no longer provide you with decryption services. You have 3 days to contact us for negotiation. Within 3 days, we will provide a 50% discount. If the discount service is not provided for more than 3 days, the files will be leaked to our onion network. Every more than 3 days will increase the number of leaked files. Please use the company email to contact us, otherwise we will not reply. [+] How to get access on website?[+] You have two ways: 1) [Recommended] Using a TOR browser! a) Download and install TOR browser from this site:https://torproject.org/ b) Open our website:gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion 2) Our mail box: a)[email protected] b)[email protected] c)If the mailbox fails or is taken over, please open Onion Network to check the new mailbox ------------------------------------------------------------------------------------------------ !!!DANGER!!! DONT try to change files by yourself, DONT use any third party software for restoring your data or antivirus solutions - its may entail damge of the private key and, as result, The Loss all data. !!!!!!! AGAIN: Its in your interests to get your files back. From our side, we (the best specialists) make everything for restoring, please should not interfere. !!!!!!! ONE MORE TIME: Security vendors and law enforcement agencies, please be aware that attacks on us will make us even stronger. !!!!!!!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (9)
Search, filter and paginate the victim timeline for Rook. Showing 1–9 of 9.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Abdi ibrahim id2408 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Evalueserve id2302 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DENSO id2301 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Data breach summary id2296 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rossell Techsys(Data will be given tomorrow) id2190 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KMG Prestige, Inc. (Data will be given tomorrow) id2189 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rosendahl Design Group id2175 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rossell Techsys id2174 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KMG Prestige, Inc. id2077 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||