Ransomware Group intelligence
Underground
InactiveTrack Underground with 26 published victims and 2 known leak locations in a single intelligence view.
Overview
Underground is tracked by Breach House as a ransomware group with 26 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 1h ago | 47glxkuxyayqrvugfumgsblrdagvrah7gttfscgzn56eyss5wg3uvmqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | undgrddapc4reaunnrdrmnagvdelqfvmgycuvilgwb5uxm25sxawaoqd.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Underground, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: underground executes malicious commands via PowerShell scripts injected into legitimate system paths.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: underground establishes persistence by adding malicious entries to Windows Registry Run Keys.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: underground disables antivirus tools by terminating security processes and clearing Windows Event Logs.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: underground deletes Volume Shadow Copies via vssadmin /delete shadows to prevent file recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: underground discovers remote hosts via SMB and HTTP service enumeration before deploying payloads.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: underground scans network shares using net share commands to identify victim file structures for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: underground moves laterally through SMB shares to encrypt additional systems within the victim network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: underground exfiltrates stolen data using encrypted channels before deploying ransomware on compromised hosts.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: underground encrypts victim files using a custom ransomware payload targeting Documents and System directories.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: underground prevents system recovery by stopping critical Windows services and terminating restore processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!readme!!!.txt
The Underground team welcomes you! We would like to inform that your network has been tested by us for vulnerabilities. Poor network security could cause your data to be lost forever. Your files are currently encrypted, they can be restored to their original state with a decryptor key that only we have. The key is in a single copy on our server. Attempting to recover data by your own efforts may result in data loss. It is important not to change their current state. Each file additionally has a unique cipher, which you can restore only with our help. We also examined your infrastructure and downloaded the most sensitive data. The list of hosts from which the information was downloaded: - 172.16.10.77 ([snip].local) - 172.16.10.51 ([snip].LOCAL) - 172.16.10.75 ([snip].local) - 172.16.10.85 ([snip].local) - 172.16.10.87 ([snip].local) - 10.10.10.30 Synology (access via OpenVPN [snip]:1194) ---------------------------------- -email communications with clients that contain confidential agreements -accounting and tax reports for each client -audit documents -companys and clients financial documents -clients passports/ID's and private information -documents contain privileged and confidential information -password-protected documents from a bank -payroll data -company financial and performance data -employees personal information (Tc Identification Numbers) The total amount of downloaded information more than 200 Gb If you do not contact us within 3 days, or we cannot reach an agreement, all data will be published on a site that no one can block. Confidential data can be helpful for your competitors, enemies and darknet market hackers from over the world. The consequences will be unpredictable and the process cannot be stopped. Information about data leaks is bound to get into the media. Your company's reputation will be damaged. We value and respect every business, including yours. Therefore, we suggest you avoid further negative consequences and return to your work as soon as possible. We guarantee a fair and confidential deal in the shortest possible time. You will not only receive a decryptor, but also a description of your network vulnerabilities and information security recommendations. If necessary, you will be provided with qualified data recovery assistance. You can trust us! Reputation is important to everyone. As a proof of our statements, we are ready to restore some files for free and demonstrate how our product works. Best regards, Underground team ! Contacts for communication via chat: login to your account (Tor Browser) http://undgrddapc4reaunnrdrmnagvdelqfvmgycuvilgwb5uxm25sxawaoqd.onion/ your login: [snip] your password: [snip] your ID: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (26)
Search, filter and paginate the victim timeline for Underground. Showing 1–26 of 26.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | SFA Engineering id21754 View details | Korea, Republic of | Manufacturing / Engineering | ||
|
Revenue: $1.7 Billion Type: Industry Size: 2,3 TBytes |
|||||
| Ransomware | GMORS Co., Ltd id20819 View details | Taiwan, Province of China | Manufacturing / Engineering | ||
|
Revenue: $100 million Type: Manufacturing Size: 302,7 GBytes |
|||||
| Ransomware | Afa Systems Ltd. id19191 View details | Canada | Services | ||
|
Revenue: $37.2 million Type: Industry Size: 1,1 TBytes |
|||||
| Ransomware | shengyusteel.com id19190 View details | Taiwan, Province of China | Manufacturing / Engineering | ||
|
Revenue: $431.6 million Type: Manufacturing Size: 353,9 GBytes |
|||||
| Ransomware | semex.com id19189 View details | Canada | Other | ||
|
Revenue: $170 million Type: Research Size: 214,2 GBytes |
|||||
| Ransomware | Simmtech Co., Ltd. id16104 View details | Korea, Republic of | IT | ||
|
Revenue:$ 760M - Country :South Korea |
|||||
| Ransomware | hcsgcorp.com id14983 View details | United States | Services | ||
|
Revenue:$1.7 Billion - Country :USA |
|||||
| Ransomware | Casio Computer Co., Ltd id14712 View details | Japan | IT | ||
|
Revenue:$1.858 billion - Country :Japan |
|||||
| Ransomware | ramservices.com id13246 View details | United States | Services | ||
|
Revenue:$162M - Country :USA |
|||||
| Ransomware | Ethypharm id13218 View details | France | Other | ||
|
Revenue:$ 670M - Country :France |
|||||
| Ransomware | A-Line Staffing Solutions id13053 View details | United States | Services | ||
|
Revenue:$96.1M - Country :USA |
|||||
| Ransomware | belcherpharma.com id12972 View details | United States | Healthcare / Pharma | ||
|
Revenue:$25.7M - Country :USA |
|||||
| Ransomware | CentralSecurities.com id12951 View details | United States | Other | ||
|
Revenue:$230M - Country :USA |
|||||
| Ransomware | www.belcherpharma.com id12602 View details | United States | Healthcare / Pharma | ||
|
Revenue:$25.7M - Country :USA |
|||||
| Ransomware | kc.co.kr id12261 View details | Korea, Republic of | Other | ||
|
Revenue:$650M - Country :South Korea |
|||||
| Ransomware | bulldogbag.com id12227 View details | Canada | Other | ||
|
Revenue:$20.6M - Country :Canada |
|||||
| Ransomware | frenckengroup.com id12226 View details | Singapore | Services | ||
|
Revenue:$50.0M - Country :Singapore |
|||||
| Ransomware | synology.com id12225 View details | Germany | Other | ||
|
Revenue:$183.6M - Country :Germany, Taiwan |
|||||
| Ransomware | tpa-group.sk id12224 View details | Slovakia | Services | ||
|
Revenue:tpa-group.com $281M; tpa-group.sk $15M - Country :Slovakia |
|||||
| Ransomware | Triathlon.group id12223 View details | Germany | Services | ||
|
Revenue:$176M - Country :Australia, Germa... |
|||||
| Ransomware | awwg.com id12222 View details | Spain | Other | ||
|
Revenue:€585M - Country :France, Spain, U... |
|||||
| Ransomware | KyungChang id12221 View details | Other | |||
|
Revenue:$650M - Country :South Korea |
|||||
| Ransomware | Y. Hata & Co., Ltd. id12220 View details | United States | Services | ||
|
Revenue:$268M - Country :USA |
|||||
| Ransomware | Skender Construction id12219 View details | United States | Construction / Real Estate | ||
|
Revenue:$318.3 Million - Country :USA |
|||||
| Ransomware | Creative Business Interiors id12218 View details | United States | Communication / Marketing | ||
|
Revenue:$27M - Country :USA |
|||||
| Ransomware | cochraneglobal.com id12217 View details | United Arab Emirates | Services | ||
|
Revenue:$270.8 Million - Country :United Arab Emir... |
|||||