Ransomware Group intelligence
AuditTeam
ActiveTrack AuditTeam with 34 published victims and 2 known leak locations in a single intelligence view.
Overview
AuditTeam is tracked by Breach House as a ransomware group with 34 published victims.
Russian Federation is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 11 45.8%
- Pending 13 54.2%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 3h ago | cjg2avmzoly7k6mw7xobnyre354jxro4qegkoazhsmigdk2j3aziexyd.onion |
| Leak location 1 | Onion service | Up checked 3h ago | 6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion |
Top Activity Sectors (7)
Typical Attacks (11)
▼MITRE ATT&CK does not currently catalogue AuditTeam, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: AuditTeam executes PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: AuditTeam leverages native API calls to interact with Windows services and evade detection.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: AuditTeam modifies Registry Run Keys to ensure persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: AuditTeam disables antivirus tools and security software to prevent system recovery attempts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: AuditTeam encrypts victim files using encoded data streams to maximize impact.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: AuditTeam performs file deletion to remove evidence and disable backup mechanisms.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: AuditTeam uses process discovery to identify critical system processes for targeted disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: AuditTeam exploits SMB/Windows Admin Shares for lateral movement across networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: AuditTeam exfiltrates sensitive data via C2 channels to increase ransom demands.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: AuditTeam encrypts critical data files for impact, holding encrypted content as leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: AuditTeam invokes Inhibit System Recovery techniques to block volume shadow copy restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[rand].README.txt
==================================================================== [ AUDIT LOG: SEVERE INFRASTRUCTURE COMPROMISE VERIFIED ] ==================================================================== ATTN: Executive Management and Legal Compliance Teams This notice serves as absolute cryptographic proof that your network defenses have been fully bypassed. We have acquired extensive archives of your corporate data, internal communications, and protected records. Your failure to implement adequate security controls is now a severe liability for your board of directors and stakeholders. [ CURRENT STATUS ] Your entity is currently operating within a private Remediation Window on our DATA EXPOSURE LOGS. You have two options: OPTION A (REMEDIATION): Access our secure portal, initiate contact, and pay the Audit & Consulting fee. We will permanently purge the acquired data and provide a report on your vulnerabilities. Your reputation and compliance status remain intact. OPTION B (PUBLIC TRANSPARENCY): Ignore this notice. Once the countdown expires, we will release the entire data archive to the public internet. We will also directly notify your clients, partners, and regulatory oversight bodies of your negligence. Prepare for massive statutory fines and lawsuits. 1. Download and install the Tor Browser: https://www.torproject.org/ 2. Open the Tor Browser and enter the following address: http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion 3. Use your Audit ID to contact us: [snip] The decision belongs to your executive board. Disclosure is imminent. ====================================================================
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (34)
Search, filter and paginate the victim timeline for AuditTeam. Showing 1–34 of 34.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | ki***jp id32745 View details | Japan | — | pending | ||
|
ki***jp is cataloged as a ransomware victim entity operating within the Japanese market (country: JP). The entity represents an organization subject to threat activity documented within this threat-intelligence index. AuditTeam is identified as the associated threat actor or source linked to this listing. The description focuses on the entity's classification and contextual attributes rather than speculative incident details. This entry serves to inform stakeholders of the ransomware victim status and associated threat intelligence provenance without disclosing unconfirmed specifics. |
||||||
| Ransomware | my***ru id32746 View details | Russian Federation | — | pending | ||
|
my***ru is cataloged as a ransomware victim entity based in Russia. The entity operates within a sector not explicitly detailed in available intelligence, though its classification reflects its involvement in a threat-intelligence index under the associated actor AuditTeam. This listing type identifies its role within cybersecurity incident tracking, emphasizing its connection to AuditTeam as the attributed threat actor. The description remains neutral and avoids speculative claims regarding breach specifics, data exposure, or operational details. my***ru was officially listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | mo***al id32724 View details | Germany | — | pending | ||
|
mo***al is cataloged as a ransomware victim within the threat-intelligence index, associated with the AuditTeam threat actor and identified as operating from Germany. The entity represents an organization impacted by ransomware activity, with sector context and operational offerings documented for analytical reference. This listing type captures the victim status and links it to the specified threat actor for threat-response intelligence. The entry provides neutral, factual context for security professionals monitoring cyber incidents across European jurisdictions. mo***al was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | dg***kr id32717 View details | Korea, Republic of | IT | pending | ||
|
dg***kr is an entity cataloged as a ransomware victim within the IT sector, based in Korea (KR). The name suggests operational focus within information technology infrastructure, though specific technical details of any incident remain unconfirmed in available intelligence. This listing type identifies the entity as affected by ransomware activity, with AuditTeam cited as the associated threat actor or source in the threat-intelligence index. The description avoids speculation regarding data exfiltration, ransom demands, or breach confirmation, adhering to strict factual boundaries. It neutrally records that dg***kr was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | go***et id32718 View details | Korea, Republic of | — | pending | ||
|
go***et is cataloged as a ransomware victim entity operating within the cybersecurity and technology sector, with associated geographic origin noted as Korea. The entity reflects incidents documented within the threat-intelligence index under AuditTeam as the identified threat actor or source attribution. This listing type categorizes go***et within ransomware victim records, providing context for security analysts tracking adversary activity and affected organizations across regional threat landscapes. The description remains neutral and avoids speculative claims regarding specific attack mechanisms, data handling, or confirmed breach details. go***et was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | kr***rg id32719 View details | Argentina | — | pending | ||
|
kr***rg is cataloged as a ransomware victim entity operating within the AR sector, representing a location-based organization subject to threat intelligence indexing. The entity is associated with AuditTeam as the identified threat actor or source, contextualizing its inclusion within a specialized threat-intelligence framework. This listing type documents the entity's status without disclosing unverified incident details, maintaining strict neutrality regarding operational specifics or confirmed breach parameters. The entry serves to inform security professionals and analysts monitoring ransomware activity across regional sectors. |
||||||
| Ransomware | bu***en id32688 View details | Russian Federation | — | pending | ||
|
bu***en is cataloged as a ransomware victim entity operating within the RU region and associated with the AuditTeam threat actor. The entity name suggests involvement in cybersecurity auditing or monitoring contexts, though specific sector details, operational offerings, or confirmed incident specifics remain unverified in available intelligence. This listing type identifies bu***en as a ransomware victim linked to AuditTeam within the threat-intelligence index framework. No details regarding stolen data, ransom demands, or confirmed breach evidence are provided here to maintain factual neutrality. The entry reflects the entity's classification and association without asserting unverified incident outcomes. |
||||||
| Ransomware | Wi***IT id32676 View details | Ukraine | IT | pending | ||
|
Wi***IT operates within the information technology sector and is identified as a ransomware victim within the threat-intelligence index. The entity is associated with AuditTeam, a threat actor or source identified in the cataloging context, with operational context tied to Ukraine. The listing type specifically denotes ransomware victimization, reflecting the nature of the threat interaction recorded for this entity. This description provides neutral, factual overview based solely on the provided entity attributes: sector, geographic origin, and threat association. Wi***IT was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | pa***op id32673 View details | Russian Federation | — | pending | ||
|
pa***op is cataloged as a ransomware victim within the threat-intelligence index, associated with the AuditTeam threat actor and identified as operating from Russia. The entity represents an organization that experienced a ransomware-related security event, with its sector and specific offerings contextualized within the intelligence record. This listing type documents the relationship between the victim entity, the AuditTeam source attribution, and the geographic origin country. The entry provides a neutral overview for threat-intelligence analysis without disclosing unverified incident details. It was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | mansurovogroup id32566 View details | Russian Federation | Retail / E-commerce | leaked | ||
|
mansurovogroup is an entity operating within the Retail and E-commerce sector, based in Russia. The group provides commercial services aligned with retail operations and digital commerce activities, serving customers and partners within its geographic and industry context. This listing type identifies mansurovogroup as a ransomware victim, with the associated threat actor or source designated as AuditTeam. The record reflects the entity's inclusion in a threat-intelligence index due to this association, presented neutrally without speculation regarding specific attack details, data handling, or confirmed breach elements. This description maintains an authoritative and encyclopedic tone for catalog use. |
||||||
| Ransomware | mansurovogroup id32566 View details | Russian Federation | Retail / E-commerce | leaked | ||
|
mansurovogroup is an integrated agricultural enterprise based in Kursk Oblast, Russia. It operates across four main segments: grain cultivation and seed production, cattle farming (beef and dairy), sheep farming (wool and meat), and horse breeding at a stud farm with a 200-year history. The company emphasizes agricultural innovation and was an early adopter of precision farming technologies. |
||||||
| Ransomware | PIT.local id32567 View details | Colombia | Other | leaked | ||
|
PIT.local is a domain identifier associated with a ransomware victim entity operating within the Other sector and linked to the country of Colombia (CO). The domain serves as a reference point within a threat-intelligence index catalog, documenting its classification and contextual attributes for cybersecurity professionals. This listing type categorizes PIT.local as a ransomware victim, with the associated threat actor or source identified as AuditTeam. The entry provides structured intelligence for monitoring, risk assessment, and defensive strategy development across threat landscapes. PIT.local was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | PIT.local id32567 View details | Colombia | Other | leaked | ||
|
unknown |
||||||
| Ransomware | PI***al id32190 View details | Colombia | Other | leaked | ||
|
PI***al is cataloged as a ransomware victim operating within the Other sector and situated in the country CO. The entity is documented within a threat-intelligence index, reflecting its classification alongside AuditTeam as the associated threat actor or source. This listing type identifies PI***al specifically as a ransomware victim, providing structured context for analysts tracking cyber incidents and threat actor relationships. The description remains neutral and factual, focusing on the entity's sector, geographic location, operational category, and verified association without speculating on unconfirmed breach details, data impacts, or recovery specifics. PI***al serves as a reference point for threat-intelligence monitoring and sector-specific ransomware analysis. |
||||||
| Ransomware | Demidov Steel Group id32148 View details | Russian Federation | Manufacturing / Engineering | leaked | ||
|
Demidov Steel Group operates within the manufacturing and engineering sector, with operations and identity associated with Russia. The entity provides steel-related products and engineering services, reflecting its industrial positioning in production, materials, and technical solutions. This listing type identifies Demidov Steel Group as a ransomware victim within the threat-intelligence index, linked to the AuditTeam threat actor or source. The description avoids inventing confirmed breach details such as stolen data, ransom terms, or specific incident metrics, maintaining factual neutrality. It serves as authoritative catalog copy documenting the association between the organization, its sector context, and the cybersecurity intelligence classification. |
||||||
| Ransomware | Demidov Steel Group id32148 View details | Russian Federation | Manufacturing / Engineering | leaked | ||
|
Demidov Steel Group (ГК Демидов) is a Russian metal products manufacturer and trader, website: demidovsteel.ru. The company owns its own plants (Ryazan, Davlekanovo, Novocherkassk, and others), sells wholesale and retail, and supplies 4,000+ products including steel pipes, structural shapes, sheet metal, and rebar, along with processing services such as cutting and galvanizing, plus delivery. Its network covers Moscow and more than a dozen other cities. The company has been in business for over 20 years and serves construction and industrial clients. |
||||||
| Ransomware | ma***up id32130 View details | Russian Federation | IT | leaked | ||
|
ma***up is cataloged as a ransomware victim within the IT sector, operating from Russia. The entity represents a cybersecurity incident classification where AuditTeam is identified as the associated threat actor or source. This listing type denotes the status of the organization or entity as a victim of ransomware activity, providing context for threat-intelligence indexing and analytical tracking. The description remains neutral and factual, focusing on the entity's classification, sector, geographic origin, and linkage to AuditTeam without elaborating on unconfirmed incident details. ma***up was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | De***up id31812 View details | Russian Federation | — | leaked | ||
|
No additional victim description available. |
||||||
| Ransomware | I-SYS id30016 View details | Russian Federation | Other | leaked | ||
|
I-SYS is an entity based in Russia, operating in the other sector. The company likely provides specialized services or products, given its sector classification. I-SYS was listed as a ransomware victim associated with AuditTeam. |
||||||
| Ransomware | I-SYS id30016 View details | Russian Federation | Other | leaked | ||
|
I-SYS is a Russian software development and business automation company with 25 years of experience, offering custom development, digital transformation consulting, and DevOps services, with core products including the DocTrix electronic document management platform and the AI assistant Матрёшка, serving over half of Russia's TOP-100 enterprises. |
||||||
| Ransomware | I-***YS id29864 View details | Russian Federation | Other | leaked | ||
|
No additional victim description available. |
||||||
| Ransomware | Paid Victim 111CEAA5AD9DA2F1 id29624 View details | Russian Federation | Other | leaked | ||
|
[AI generated] N/A |
||||||
| Ransomware | ca***lm id29563 View details | Russian Federation | Healthcare / Pharma | pending | ||
|
No additional victim description available. |
||||||
| Ransomware | Paid Victim B35411691DDC2265 id29421 View details | Russian Federation | Other | pending | ||
|
[AI generated] N/A |
||||||
| Ransomware | On***de id29454 View details | Russian Federation | Other | pending | ||
|
No additional victim description available. |
||||||
| Ransomware | Mopas Online Supermarket id29328 View details | Türkiye | Agriculture / Food | — | ||
|
mopas.com.tr is a prominent Turkish retail chain and e-commerce platform primarily serving the Marmara region, offering an extensive online shopping experience that covers everything from fresh produce, halal meat, and dairy to household cleaning supplies and personal care products, all backed by a robust local delivery network that ensures fast, same-day service for residents in cities like Istanbul and Kocaeli. |
||||||
| Ransomware | Trésor Public id29221 View details | Senegal | Public Sector | leaked | ||
|
DGCPT (Direction Générale de la Comptabilité Publique et du Trésor) is Senegal's public treasury authority under the Ministry of Finance, responsible for public accounting, government fund management, cash flow, and public debt operations. |
||||||
| Ransomware | Mo***et id29160 View details | Other | — | |||
|
No additional victim description available. |
||||||
| Ransomware | Tr***ic id29009 View details | Senegal | Other | — | ||
|
No additional victim description available. |
||||||
| Ransomware | Kawasaki Motors Philippines Corporation id27991 View details | Philippines | Manufacturing / Engineering | — | ||
|
Kawasaki Motors Philippines Corporation (KMPC), located in Muntinlupa, Metro Manila, is a leading manufacturer and distributor of Kawasaki motorcycles in the Philippines, operating for over 40 years. As an affiliate of Kawasaki Heavy Industries, Ltd. (KHI), it produces commuter bikes, tricycles, and underbones, with an annual capacity of 250,000 units, making it one of the largest plants in Kawasaki's global network. |
||||||
| Ransomware | joycity id27990 View details | Korea, Republic of | IT | leaked | ||
|
Joycity is a prominent South Korean game developer and publisher founded in 1994 and listed on the KOSDAQ. Renowned for its innovation and global reach, the company originally pioneered the hip-hop-themed sports genre with its self-developed FreeStyle series, which became a cultural milestone for players across Asia. In the mobile era, Joycity successfully pivoted to the Strategy (SLG) genre, producing high-revenue titles like Gunship Battle: Total Warfare and Pirates of the Caribbean: Tides of War, with international markets consistently accounting for over 70% of its total revenue. Currently, Joycity is actively expanding into Web3 technologies and major cross-platform projects. Its blockbuster collaboration with Capcom and Aniplex, Resident Evil Survival Unit, has already surpassed 5 million global downloads as of early 2026, demonstrating the company’s robust R&D and operational expertise in managing world-class intellectual properties. |
||||||
| Ransomware | Paid Victim CCD233FEE92FFA2D id27989 View details | Hong Kong | Other | pending | ||
|
[AI generated] N/A |
||||||
| Ransomware | Paid Victim A98A624456DA525F id27988 View details | Thailand | Other | — | ||
|
[AI generated] N/A |
||||||
| Ransomware | Paid Victim D3C1388C1B73BCA2 id27987 View details | China | Other | — | ||
|
[AI generated] N/A |
||||||