Ransomware Group intelligence
Secpo
InactiveTrack Secpo with 5 published victims and 1 known leak locations in a single intelligence view.
Overview
Secpo is tracked by Breach House as a ransomware group with 5 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onion |
Top Activity Sectors (3)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Secpo, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: secpo exploits valid local accounts harvested during initial access to persist and escalate privileges.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1059.001 PowerShell Execution
What they do: secpo executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: secpo leverages native API calls to interact with system functions for execution and evasion.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: secpo disables security tools like EDR and AV by modifying system processes or configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: secpo deletes Volume Shadow Copies and backup directories via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: secpo discovers running processes to identify critical services and disable them for impact.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: secpo uses SMB/Windows Admin Shares to spread laterally across networked manufacturing and logistics systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: secpo exfiltrates stolen operational data from manufacturing and finance sectors before deploying ransomware.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: secpo encrypts victim files using custom ransomware binaries targeting critical data stores.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: secpo invokes system recovery inhibition commands to lock down restoration mechanisms post-encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (5)
Search, filter and paginate the victim timeline for Secpo. Showing 1–5 of 5.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Color Communications LLC id28463 View details | United States | Manufacturing / Engineering | ||
|
The exposed dataset includes over 200,000 unique files containing sensitive information on more than 4,500 individuals and over 5,500 organizations... |
|||||
| Ransomware | JM Bozeman Enterprises id28134 View details | United States | Transportation / Travel / Logistics | ||
|
The exposed dataset includes over 100,000 unique files (192,993 with duplicates) containing sensitive information on more than 4,000 individuals and over 4,500 organizations |
|||||
| Ransomware | Indigo Group id28133 View details | Canada | Transportation / Travel / Logistics | ||
|
The exposed dataset includes over 897,000 unique files (1,707,433 with duplicates) containing sensitive information on more than 27,000 individuals and over 27,000 organizations |
|||||
| Ransomware | Richmond Plywood Corporation Limited id28132 View details | Canada | Manufacturing / Engineering | ||
|
The total volume of extracted data amounts to approximately 1.09TB (522,925 files total), with a filtered size of 230GB (161,200 files). The files contain references to more than 2,500 unique individuals and 4,000 organizations... |
|||||
| Ransomware | Mike Brandner Law id28131 View details | United States | Finance / Legal / Insurance | ||
|
The total volume of extracted data amounts to approximately 489 GB (459,391 files total). The files contain references to more than 4,000 unique individuals... |
|||||