Ransomware Group intelligence
Secp0
InactiveTrack Secp0 with 11 published victims and 4 known leak locations in a single intelligence view.
Overview
Secp0 is tracked by Breach House as a ransomware group with 11 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onion |
| Leak location 4 | Web location | Down checked 1h ago | secp0-support.cfd |
| Leak location 3 | Web location | Down checked 1h ago | secp0-news.ws |
| Leak location 2 | Web location | Down checked 1h ago | secp0-leaks.com |
Top Activity Sectors (5)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Secp0, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: secp0 executes malicious commands via PowerShell scripts to stage ransomware payloads and disable recovery mechanisms.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: secp0 leverages native API calls to interact with Windows services and evade host-based detection tools.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: secp0 adds malicious registry run keys to ensure ransomware reactivation after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: secp0 disables security tools by modifying Windows Defender settings and clearing event logs to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: secp0 encrypts victim files using encoded payloads stored in system directories to ensure payload integrity during execution.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: secp0 deletes Volume Shadow Copies and backup directories via command-line tools to prevent data restoration.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: secp0 performs remote system discovery using Nmap scans to identify unpatched servers in US and Canadian victim environments.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: secp0 spreads laterally through SMB/Windows Admin Shares to compromise additional machines within targeted networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: secp0 encrypts critical manufacturing and engineering data with custom ransomware binaries to maximize operational disruption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: secp0 halts critical manufacturing and telecommunications services by terminating processes and disabling system recovery features.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (11)
Search, filter and paginate the victim timeline for Secp0. Showing 1–11 of 11.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Color Communications LLC id31135 View details | United States | Manufacturing / Engineering | ||
|
ccicolor.com is a company operating in the manufacturing and engineering sector, based in the United States. The company likely provides various services and products related to its sector. ccicolor.com was listed as a ransomware victim associated with secp0 |
|||||
| Ransomware | Color Communications LLC id31135 View details | United States | Manufacturing / Engineering | ||
|
The exposed dataset includes over 200,000 unique files containing sensitive information on more than 4,500 individuals and over 5,500 organizations... |
|||||
| Ransomware | JM Bozeman Enterprises id31136 View details | United States | Other | ||
|
jmbozeman.com is an entity based in the United States, operating in the other sector. The specific offerings of jmbozeman.com are not well-documented, but it is known to be a US-based organization. jmbozeman.com was listed as a ransomware victim associated with secp0 |
|||||
| Ransomware | JM Bozeman Enterprises id31136 View details | United States | Other | ||
|
The exposed dataset includes over 100,000 unique files (192,993 with duplicates) containing sensitive information on more than 4,000 individuals and over 4,500 organizations |
|||||
| Ransomware | Indigo Group id31137 View details | Canada | Transportation / Travel / Logistics | ||
|
Indigo Group is a Canadian company operating in the transportation sector, providing logistics and travel services. The company is based in Canada and offers various services to its clients. Indigo Group was listed as a ransomware victim associated with secp0. |
|||||
| Ransomware | Indigo Group id31137 View details | Canada | Transportation / Travel / Logistics | ||
|
The exposed dataset includes over 897,000 unique files (1,707,433 with duplicates) containing sensitive information on more than 27,000 individuals and over 27,000 organizations |
|||||
| Ransomware | Richmond Plywood Corporation Limited id31138 View details | Canada | Manufacturing / Engineering | ||
|
Richply.com is a company based in Canada, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Richply.com was listed as a ransomware victim associated with secp0 |
|||||
| Ransomware | Richmond Plywood Corporation Limited id31138 View details | Canada | Manufacturing / Engineering | ||
|
The total volume of extracted data amounts to approximately 1.09TB (522,925 files total), with a filtered size of 230GB (161,200 files). The files contain references to more than 2,500 unique individuals and 4,000 organizations... |
|||||
| Ransomware | Mike Brandner Law id31139 View details | United States | Communication / Marketing | ||
|
Mikebrandner.com is a US-based company operating in the communication and marketing sector, providing various services to its clients. The company is involved in creating and implementing marketing strategies for its customers. Mikebrandner.com was listed as a ransomware victim associated with secp0 |
|||||
| Ransomware | Mike Brandner Law id31139 View details | United States | Communication / Marketing | ||
|
The total volume of extracted data amounts to approximately 489 GB (459,391 files total). The files contain references to more than 4,000 unique individuals... |
|||||
| Ransomware | Terralogic id18387 View details | United States | Telecommunications | ||
|
Due to Terralogic's unwillingness to cooperate, we are publishing evidence of the breach of their network... |
|||||