Ransomware Group intelligence
Titan
ActiveTrack Titan with 30 published victims and 3 known leak locations in a single intelligence view.
Overview
Titan is tracked by Breach House as a ransomware group with 30 published victims.
Italy is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 51m ago | x4bccxlsmjsxlnnf3ocvndlshgfkagzytpqmsjnlfykceumnw6i4hkqd.onion |
| Leak location 3 | Web location | Up checked 51m ago | x4bccxlsmjsxlnnf3ocvndlshgfkagzytpqmsjnlfykceumnw6i4hkqd.onion/awaiting |
| Leak location 1 | Web location | Up checked 52m ago | titanblog.org |
Top Activity Sectors (9)
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Titan, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Titan executes malicious payloads through PowerShell scripts to deploy ransomware binaries across compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: Titan modifies Windows Registry Run keys to establish persistence by injecting startup entries.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Titan leverages registry run keys and startup folders to maintain persistence after reboot cycles.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Titan disables security tools by terminating antivirus processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Titan clears Windows Event Logs using PowerShell to erase forensic evidence of intrusion and attack timeline.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Titan deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Titan uses file and directory discovery via PowerShell to enumerate critical system folders and identify encryption targets.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Titan moves laterally through SMB/Windows Admin Shares using stolen credentials to access additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Titan archives stolen data via utility commands before exfiltration to maintain leverage for ransom demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Titan encrypts victim files using custom symmetric encryption routines targeting documents, databases, and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Titan stops critical Windows services like backup and monitoring utilities using net stop commands to disrupt defenses.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Titan inhibits system recovery by corrupting restore points and disabling backup service restoration mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (30)
Search, filter and paginate the victim timeline for Titan. Showing 1–30 of 30.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Termotecnica Industriale S.r.l. id31837 View details | Italy | — | ||
|
[AI generated] Termotecnica Industriale S.r.l. is an Italian company operating in the industrial thermal engineering sector. Based in Italy, it specializes in the design and manufacturing of heating systems, thermal equipment, and industrial burners. The company serves various industrial clients requiring customized thermal solutions for production processes. It operates primarily in the energy and industrial plant engineering market within Italy and potentially broader European markets. |
|||||
| Ransomware | CTP S.r.l. id31839 View details | Italy | — | ||
|
[AI generated] CTP S.r.l. is an Italian company operating in the printing and publishing technology sector. Based in Italy, it specializes in the development and supply of software and systems for editorial production, prepress, and content management. The company serves media, publishing, and printing industries, providing workflow automation solutions that help customers manage and streamline the production of newspapers, magazines, and other printed or digital content. |
|||||
| Ransomware | Alto Calore Servizi SPA id31840 View details | Italy | — | ||
|
[AI generated] Alto Calore Servizi SPA is an Italian public utility company operating in the Campania region of southern Italy. It is primarily engaged in the management and distribution of drinking water and sewage services. The company serves numerous municipalities in the provinces of Avellino and Benevento, handling water supply infrastructure, treatment, and distribution to residential and industrial customers. |
|||||
| Ransomware | Tedesco & Partners STP srl id31841 View details | Italy | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | POEMA S.r.l. id31842 View details | Italy | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | CONDOR SPA id31851 View details | Italy | — | ||
|
[AI generated] CONDOR SPA is a Chilean airline operating in South America. Founded in 1979, it provides domestic passenger and cargo air transport services within Chile, connecting major cities and remote regions including Patagonia and Easter Island. The company plays a key role in regional connectivity, serving routes that are difficult to access by land. It operates under civil aviation regulations in Chile. |
|||||
| Ransomware | Elbor S.p.A. id31852 View details | Italy | — | ||
|
[AI generated] Elbor S.p.A. is an Italian company operating in the distribution and wholesale sector. Based in Italy, it specializes in the commercialization of industrial and technical products, serving businesses across various sectors. The company functions as a trading and supply chain intermediary, providing goods and services to industrial clients. Specific details about its scale, founding date, and full product portfolio are limited in widely available sources. |
|||||
| Ransomware | TECNOLOGICA S.r.l. id31855 View details | Italy | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | ELCON MEGARAD S.p.A id31860 View details | Italy | — | ||
|
[AI generated] ELCON MEGARAD S.p.A. is an Italian company specializing in the design and manufacture of radiation-crosslinked materials and heat-shrinkable products. Operating in the electrical and industrial sectors, it produces cable accessories, insulation components, and protective solutions used in energy, rail, and telecommunications applications. Headquartered in Italy, the company serves both domestic and international markets with engineered polymer-based products. |
|||||
| Ransomware | PERTINENT HEALTHCARE BUSINESS SOLUTIONS PRIVATE LIMITED id30725 View details | India | Healthcare / Pharma | ||
|
Pertinent Healthcare Business Solutions Private Limited is a privately held company based in India, operating in the healthcare and pharmaceutical sector. The company provides various business solutions to healthcare organizations. It was listed as a ransomware victim associated with titan |
|||||
| Ransomware | PERTINENT HEALTHCARE BUSINESS SOLUTIONS PRIVATE LIMITED id30725 View details | India | Healthcare / Pharma | ||
|
[AI generated] N/A |
|||||
| Ransomware | DataOstrov s.r.o. id30529 View details | Czechia | IT | ||
|
DataOstrov s.r.o. is an IT company based in the Czech Republic, providing various IT services. The company operates in the IT sector, offering solutions to its clients. DataOstrov s.r.o. was listed as a ransomware victim associated with titan |
|||||
| Ransomware | DataOstrov s.r.o. id30529 View details | Czechia | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | Ozmit s.r.o. id30530 View details | Czechia | Other | ||
|
Ozmit s.r.o. is a company based in the Czech Republic, operating in the other sector. The company's specific offerings are not well-documented, but it is known to be part of the diverse range of businesses in the Czech Republic. Ozmit s.r.o. was listed as a ransomware victim associated with titan. |
|||||
| Ransomware | Ozmit s.r.o. id30530 View details | Czechia | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Cooperate consulting CZ s.r.o. id30531 View details | Czechia | Finance / Legal / Insurance | ||
|
Cooperate consulting CZ s.r.o. is a consulting firm based in the Czech Republic, operating in the finance, legal, and insurance sectors. The company provides various services to its clients, likely including advisory and consulting services. Cooperate consulting CZ s.r.o. was listed as a ransomware victim associated with titan. |
|||||
| Ransomware | Cooperate consulting CZ s.r.o. id30531 View details | Czechia | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | Cooperate service CZ s.r.o. id30500 View details | Czechia | Retail / E-commerce | ||
|
Ghz-shop.cz is an e-commerce company based in the Czech Republic, operating in the retail sector. The company provides online shopping services to its customers. Ghz-shop.cz was listed as a ransomware victim associated with titan |
|||||
| Ransomware | Cooperate service CZ s.r.o. id30500 View details | Czechia | Retail / E-commerce | ||
|
[AI generated] N/A |
|||||
| Ransomware | Eureka Construction INC id30501 View details | United States | Construction / Real Estate | ||
|
Eurekaconst.com is a US-based company operating in the construction and real estate sector, providing various services to its clients. The company is involved in construction projects and real estate development in the United States. Eurekaconst.com was listed as a ransomware victim associated with titan |
|||||
| Ransomware | Eureka Construction INC id30501 View details | United States | Construction / Real Estate | ||
|
[AI generated] N/A |
|||||
| Ransomware | SIRILAK SEAFOOD (PW) LTD. id29384 View details | Sri Lanka | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Apex Maritime Co., Inc. id29385 View details | Korea, Republic of | Transportation / Travel / Logistics | ||
|
[AI generated] Apex Maritime Co., Inc. is a freight forwarding and logistics company headquartered in the Philippines. It provides international freight forwarding, customs brokerage, cargo consolidation, and supply chain management services. The company operates across air and ocean freight sectors, serving importers and exporters. It is part of the broader Apex Group, with a global network of offices supporting trade routes across Asia, Europe, and the Americas. |
|||||
| Ransomware | Mezta Corporativo, S.A. de C.V. id29247 View details | Mexico | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Abp Autoricambi Srl id29248 View details | Italy | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | DFI AMERICA, LLC id29249 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] DFI AMERICA, LLC is a U.S.-based company operating in the financial services and investment industry. It functions as an American subsidiary or affiliate of a broader financial group, providing investment advisory, asset management, and related financial services. The company operates within the United States and serves institutional and corporate clients, supporting capital markets and financial consulting activities in North America. |
|||||
| Ransomware | CRIT Tunisie id29250 View details | Tunisia | Services | ||
|
[AI generated] CRIT Tunisie is a subsidiary of the French group CRIT, operating in the human resources and temporary staffing industry. Based in Tunisia, the company provides workforce solutions including temporary employment, permanent recruitment, and outsourcing services. It serves various sectors such as industry, logistics, and services, helping businesses manage their staffing needs efficiently while connecting job seekers with employment opportunities across the country. |
|||||
| Ransomware | Groupe CRIT SA id29251 View details | France | Construction / Real Estate | ||
|
[AI generated] Groupe CRIT SA is a French multinational staffing and recruitment company headquartered in Paris, France. Founded in 1962, it operates in the human resources and temporary employment industry, providing workforce solutions including temporary staffing, permanent recruitment, and outsourcing services. The group serves various sectors such as industry, transport, logistics, and construction, operating across France and internationally in several European and African markets. |
|||||
| Ransomware | ETM-ELECTROMATIC, INC. id29252 View details | United States | Public Sector | ||
|
[AI generated] ETM-Electromatic, Inc. is a U.S.-based company specializing in the design and manufacture of electronic and electromagnetic equipment. The company operates in the defense and industrial electronics sector, producing products such as traveling wave tubes and related microwave power modules used in radar, electronic warfare, and communications systems. It serves government, military, and commercial clients primarily within the United States. |
|||||
| Ransomware | Quahe Woo & Palmer LLC id29253 View details | Singapore | Other | ||
|
[AI generated] N/A |
|||||