Ransomware Group intelligence
Unsafe
ActiveTrack Unsafe with 31 published victims and 1 known leak locations in a single intelligence view.
Overview
Unsafe is tracked by Breach House as a ransomware group with 31 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | unsafeipw6wbkzzmj7yqp7bz6j7ivzynggmwxsm6u2wwfmfqrxqrrhyd.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Unsafe, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: unsafe executes malicious commands via PowerShell scripts to deploy payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: unsafe leverages registry run keys to maintain persistence by automatically launching malware on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: unsafe disables security tools like antivirus software and event log collectors to evade detection and persistence.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: unsafe manipulates boot sequences to enter safe mode and disable critical recovery services during attack phases.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: unsafe encodes victim data with symmetric encryption keys before exfiltration to protect stolen information.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: unsafe deletes Volume Shadow Copies and backup files via system commands to prevent recovery attempts.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: unsafe performs remote system discovery to map internal networks and identify additional targets for lateral movement.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: unsafe scans network shares using native tools to identify victim systems and data repositories for targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: unsafe encrypts victim files using custom ransomware binaries, applying impact encryption across targeted directories.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: unsafe invokes system recovery inhibition commands to block forensic analysis and system restoration processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (31)
Search, filter and paginate the victim timeline for Unsafe. Showing 1–31 of 31.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | amzur.com id32225 View details | Brazil | IT | ||
|
amzur.com operates within the IT sector and is associated with the country Brazil. The entity functions as an IT services provider, though specific operational details remain limited in available threat-intelligence records. This listing type categorizes amzur.com as a ransomware victim, with the associated threat actor or source designated as unsafe. The entry reflects the entity's presence within the threat-intelligence index based on this association. The final assessment neutrally states that amzur.com was listed as a ransomware victim associated with unsafe. |
|||||
| Ransomware | amzur.com id32225 View details | Brazil | IT | ||
|
Revenue: $73.4 million |
|||||
| Ransomware | Presentations.AI id31532 View details | United States | IT | ||
|
Presentations.AI is an artificial intelligence-powered platform based in the US, operating in the IT sector, offering AI-driven presentation tools. The company provides innovative solutions to enhance presentation design and delivery. Presentations.AI was listed as a ransomware victim associated with unsafe |
|||||
| Ransomware | Presentations.AI id31532 View details | United States | IT | ||
|
Revenue: $5 million |
|||||
| Ransomware | DECK APP TECHNOLOGIES PTE. LTD id31505 View details | India | IT | ||
|
Deck.in is an Indian company operating in the IT sector, providing various services. The company is based in India and offers its services to clients. Deck.in was listed as a ransomware victim associated with unsafe |
|||||
| Ransomware | DECK APP TECHNOLOGIES PTE. LTD id31505 View details | India | IT | ||
|
Revenue: $5 million |
|||||
| Ransomware | Constellation HomeBuilder Systems id31495 View details | United States | Construction / Real Estate | ||
|
Constellation HomeBuilder Systems is a leading provider of software solutions for the construction and real estate industries in the US. The company offers a range of products and services designed to help home builders and developers manage their businesses more efficiently. Constellation HomeBuilder Systems was listed as a ransomware victim associated with unsafe |
|||||
| Ransomware | Constellation HomeBuilder Systems id31495 View details | United States | Construction / Real Estate | ||
|
Revenue: $138.1M |
|||||
| Ransomware | Jiva Health id30835 View details | India | Healthcare / Pharma | ||
|
Jiva Health is a healthcare company based in India, operating in the healthcare and pharmaceutical sector. The company provides various healthcare services and offerings to its customers. Jiva Health was listed as a ransomware victim associated with unsafe. |
|||||
| Ransomware | Jiva Health id30835 View details | India | Healthcare / Pharma | ||
|
Revenue: 9 million |
|||||
| Ransomware | CCR Solutions id30693 View details | Brazil | IT | ||
|
CCR Solutions is an IT company based in Brazil, providing various IT services. The company operates in the IT sector, offering solutions to its clients. CCR Solutions was listed as a ransomware victim associated with unsafe |
|||||
| Ransomware | CCR Solutions id30693 View details | Brazil | IT | ||
|
Revenue: 41 million |
|||||
| Ransomware | CCR Solutions id30693 View details | Canada | IT | ||
|
Revenue: 41 million |
|||||
| Ransomware | Deutsche Bank id30252 View details | Germany | Finance / Legal / Insurance | ||
|
Deutsche Bank is a leading global banking and financial services company headquartered in Frankfurt, Germany. It provides a wide range of financial services, including corporate and investment banking, private banking, and asset management. The company operates in several countries and is a major player in the European finance sector. Deutsche Bank was listed as a ransomware victim associated with unsafe |
|||||
| Ransomware | Deutsche Bank id30252 View details | Germany | Finance / Legal / Insurance | ||
|
Revenue: 30 billion |
|||||
| Ransomware | straightperformance.de id30102 View details | Germany | IT | ||
|
Straightperformance.de is a company based in Germany, operating in the IT sector. The company likely provides various IT services, given its sector. Straightperformance.de was listed as a ransomware victim associated with unsafe. |
|||||
| Ransomware | straightperformance.de id30102 View details | Germany | IT | ||
|
Revenue: 2 million |
|||||
| Ransomware | SPARTAN Light Metal Products id10424 View details | United States | Manufacturing / Engineering | — | |
|
country: US - revenue: 311.00M |
|||||
| Ransomware | Hartl European Transport Company id10423 View details | Switzerland | Transportation / Travel / Logistics | — | |
|
country: CH - revenue: 46.00M |
|||||
| Ransomware | American International College id10422 View details | United States | Education | — | |
|
country: US - revenue: 135.00M |
|||||
| Ransomware | TAG Aviation id6802 View details | Transportation / Travel / Logistics | — | ||
|
country: CH - revenue: 326.60M |
|||||
| Ransomware | SPARTAN Light Metal Products Inc id6144 View details | United States | Manufacturing / Engineering | — | |
|
country: US - revenue: 311.00M |
|||||
| Ransomware | Invenergy id6123 View details | Energy | — | ||
|
country: US - revenue: 10 |
|||||
| Ransomware | G.R. Sponaugle id4946 View details | Other | — | ||
|
country: US - revenue: 22.00M |
|||||
| Ransomware | Horwitz Horwitz & Associates id4945 View details | Finance / Legal / Insurance | — | ||
|
country: US - revenue: 8.00M |
|||||
| Ransomware | Wings Etc id4944 View details | Other | — | ||
|
country: US - revenue: 145.00M |
|||||
| Ransomware | Dooly County School System id4943 View details | Education | — | ||
|
country: US - revenue: 20.00M |
|||||
| Ransomware | Whatcom County Library System id4942 View details | Public Sector | — | ||
|
country: US - revenue: 7.00M |
|||||
| Ransomware | The Chedi Muscat id4941 View details | Other | — | ||
|
country: OM - revenue: 28.00M |
|||||
| Ransomware | Barakat Travel Co id4940 View details | Transportation / Travel / Logistics | — | ||
|
country: LB - revenue: 5.00M |
|||||
| Ransomware | Ucar id4939 View details | France | Other | — | |
|
country: FR - revenue: 33.00M |
|||||