Ransomware Group intelligence
Ddosecret
ActiveTrack Ddosecret with 319 published victims and 4 known leak locations in a single intelligence view.
Overview
Ddosecret is tracked by Breach House as a ransomware group with 319 published victims.
Russian Federation is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 28 93.3%
- Pending 2 6.7%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Web location | Up checked 3h ago | data.ddosecrets.org |
| Leak location 3 | Web location | Up checked 3h ago | ddosecrets.org |
| Leak location 2 | Web location | Down checked 3h ago | ddosecrets.com |
| Leak location 1 | Web location | Down checked 3h ago | https://data.ddosecrets.com/ |
Top Activity Sectors (15)
- Not identified 231
- Public Sector 18
- Communication / Marketing 14
- Services 11
- Finance / Legal / Insurance 10
- Energy 7
- Telecommunications 3
- Manufacturing / Engineering 3
- IT 3
- Education 3
- NGOs / Associations 3
- Retail / E-commerce 2
- Hospitality / Food & Beverage / Tourism 1
- Transportation / Travel / Logistics 1
- Construction / Real Estate 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Ddosecret, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ddosecret uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: ddosecret modifies Windows Registry Run keys to ensure ransomware execution upon system reboot.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ddosecret disables antivirus tools and security software to prevent detection and hinder system recovery efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: ddosecret deletes Volume Shadow Copies and backup files to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: ddosecret performs remote system discovery to map the victim network and identify high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: ddosecret scans network shares to identify victim file structures and target directories for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: ddosecret exploits SMB/Windows Admin Shares to move laterally between networked victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: ddosecret exfiltrates victim data via encrypted C2 channels before demanding payment for decryption keys.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: ddosecret encrypts victim files using custom ransomware binaries, locking data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ddosecret invokes system recovery inhibition commands to prevent automatic restoration from backups.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (319)
Search, filter and paginate the victim timeline for Ddosecret. Showing 301–319 of 319.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | ArianTel id9Msd4GUCEe6j View details | Other | — | |||
|
ArianTel is an Iranian telecommunications provider that offers mobile service and related communications services. Public profiles describe it as a mobile service operator and a provider of telecom offerings such as SIM cards and internet packages, with operations associated with Iran. Open-source reporting also links ArianTel to Iran’s broader communications and surveillance environment. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aqaba Company for Ports Operation & Management, Jordan idHJMPPSztR8Bx View details | Services | — | |||
|
Aqaba Company for Ports Operation & Management is a public company based in Aqaba, Jordan, in the maritime services sector, with headquarters in Aqaba and a reported workforce of 1,001-5,000 employees. It operates port activities and manages port facilities and services connected to the Port of Aqaba, supporting cargo handling and related maritime operations. The company is described as a governmental body for establishing, developing, maintaining, and operating port activities, and community-development materials note that the New Port is fully operational under its management. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Appin Uncensored idFRQqwqi9n6hq View details | Other | — | |||
|
Appin Uncensored appears to refer to Appin, an Indian company described as a cyber-espionage firm that provided hacking services to governments, private investigators, and corporate clients. Reuters and later summaries characterize it as an educational startup that evolved into a private hacking and intelligence operation serving high-end clients. Public reporting places the company in India, but available sources do not provide a clear consumer-facing product or ordinary commercial offerings for this listing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Andrew Tate's War Room videos idVRC3ImxbER18 View details | Other | — | |||
|
Andrew Tate's War Room videos refers to a collection of in-person meeting, dinner, and event recordings tied to Andrew Tate's War Room, an all-male networking group. Reporting and the indexed description characterize the group as a paid membership community that promotes self-discipline, motivation, confidence, and business or social networking, with participation fees reported at about $8,000 per year and coverage focused on its UK-linked activities. The material on the index concerns the videos themselves rather than a separate company service, so the listing is best understood as an Other-sector target associated with a media archive and private group activity. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Andrew Tate's The Real World (Hustler's University) id5fi6VXQ8QgSg View details | Education | — | |||
|
Andrew Tate's The Real World, formerly known as Hustler's University, is an online education platform in the Education sector that offers courses on e-commerce, drop shipping, stocks, crypto, and copywriting, taught by millionaire professors to over 155,000 members worldwide. The platform provides access to a network of 240,000 professionals, expert training, direct mentorship, and tested strategies for scaling businesses to 7+ figures. It operates as a global digital learning application focused on wealth creation methods, requiring about 2 hours of daily focus work to potentially earn between 1 million and 10 million dollars. The Real World was listed as a ransomware victim associated with the threat actor ddosecret, which breached the platform on November 25, 2024, exposing user data. |
||||||
| Ransomware | Andrew Tate staff chats iddH898lnsHOTs View details | Other | — | |||
|
Andrew Tate staff chats refers to chat logs and related internal communications from Andrew Tate’s subscription-based online course service, The Real World, formerly known as Hustler’s University. The platform operates in the education and training space and is associated with Andrew Tate’s online business activity. Public reporting describes the service as a paid membership offering that includes training and community chat channels, with the leaked material drawn from those staff and user chat environments. It is categorized in the Other sector and is associated with the United Kingdom. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Alliance Coal idNpmhXgw9RWP5 View details | Other | — | |||
|
Alliance Coal, commonly associated with Alliance Resource Partners, is a U.S. coal company headquartered in Tulsa, Oklahoma. It operates in the coal sector and describes itself as a leading producer in the Eastern United States, supplying utility, industrial, and steelmaking customers with coal. The company’s business centers on coal mining, production, and marketing, with additional energy-related assets in its broader portfolio. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ALET idHi1pXQsys7uJ View details | Other | — | |||
|
ALET LTD is a UK-registered company based in Pontypool, Torfaen, Wales, with its registered office at 14 Museum Court. Companies House lists it as an active private limited company, but the available filing record does not describe its products, services, or operating sector in detail. In this catalog context, ALET is therefore identified conservatively as a business entity from the United Kingdom without further operational specifics. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | AKP id4hALqNOjDUvb View details | Other | — | |||
|
AKP is a UK-based company in the Other sector with headquarters in Great Yarmouth, England, and it presents itself as a precision engineering business. Its public materials describe technical manufacturing services such as CNC milling and related engineering support for customers across the region and beyond. The company is associated online with AKP Ltd in Great Yarmouth, which advertises precision engineering capabilities and a long-standing industry presence. AKP was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Airman Teixeira Leaks idQZCJZdBCHHI5 View details | Other | — | |||
|
Airman Teixeira Leaks refers to the publicly circulated set of classified document images and transcripts attributed to U.S. Airman Jack Teixeira, who posted them to Discord channels. The material is associated with Teixeira, a member of the Massachusetts Air National Guard’s 102nd Intelligence Wing in the United States, and the listing itself does not describe a commercial company, product line, or public-facing service. As a threat-intelligence catalog entry, it is best understood as a leak-themed entity in the broader other sector rather than an operating business. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Agencia Nacional de Hidrocarburos idPLiOIvx7rtzi View details | Other | — | |||
|
Agencia Nacional de Hidrocarburos (ANH) is a Colombian public authority based in Bogotá that oversees the country’s hydrocarbons sector. Its mandate includes the integral administration of the nation’s hydrocarbon reserves and promoting the optimal, sustainable use of petroleum and gas resources. The agency also publishes sector information and operates public-facing services from its main office in the capital. In threat-intelligence listings, it was named as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Afghanistan Papiere id5IUn8KXtEJC8 View details | Other | — | |||
|
Afghanistan Papiere is an Afghanistan-based entity in the Other sector, and the name is commonly used in reference to Afghan papers or document collections rather than a clearly identified commercial brand. Public material tied to the phrase “Afghanistan Papiere” points to published or reported Afghanistan-related documents, indicating an information or document-oriented subject rather than a standard industrial or consumer offering. In a threat-intelligence catalog, the listing identifies the entity by name and sector only, without asserting operational details beyond available public context. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aerogas idMAkIpx7Xb2UA View details | Energy | — | |||
|
Aerogas is an energy-sector company associated with the supply of rare and specialty gases and chemicals. Public business profiles describe Aerogas GmbH as based in Mülheim an der Ruhr, Germany, and serving customers worldwide. Other corporate listings also link AEROGAS to gas-related engineering activity in the Moscow region, indicating the name may be used by more than one entity. In threat-intelligence context, Aerogas was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aerial Surveillance Footage idqHDEVQVSIrsX View details | Other | — | |||
|
Aerial Surveillance Footage is a name used for footage captured from aircraft, helicopters, or drones for aerial surveillance, including monitoring properties, events, public spaces, and law-enforcement operations. In commercial and public-safety settings, this type of service supports real-time observation, incident review, and broad-area situational awareness. The listing suggests an entity associated with this material in the Other sector and reflects a name tied to aerial video or surveillance operations rather than a narrowly defined industry profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ACPeds idTyjvzWWVgu4Z View details | Other | — | |||
|
ACPeds is a pediatric healthcare provider in the United States, operating in the broader medical services sector and serving children and families through pediatric care. Public reporting about similarly named pediatric practices indicates this type of organization offers outpatient clinical services and related child health support. In threat-intelligence indexing, ACPeds is treated as an Other-sector entity because the available records do not provide a more specific industry classification. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Achinsk City Government idNnORqNVT53Rd View details | Public Sector | — | |||
|
Achinsk City Government is the municipal administration for Achinsk, a city in Krasnoyarsk Krai, Russia, on the Chulym River west of Krasnoyarsk. As a public sector body, it provides local government services and administration for the city and its residents. In threat-intelligence contexts, municipal governments are tracked as targets because they support essential public services and civic operations. Achinsk City Government was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | 29 Leaks idqH9vKaAnQhiF View details | Other | — | |||
|
29 Leaks is a DDoSecrets collection associated with ransomware-leaked material from organizations in the Other sector, based on the United States. DDoSecrets describes its disclosures as data already published by ransomware actors, assembled from dark web leak sites and shared for transparency and research purposes. The index reflects a broader set of publicly surfaced corporate and institutional leaks rather than a single operational business profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aban Offshore ida15lJWGaoM4G View details | Other | — | |||
|
Aban Offshore Limited is an Indian offshore drilling contractor headquartered in Chennai, India, and one of the private sector’s largest players in offshore drilling. The company provides drilling and oilfield services to the oil and gas industry and operates assets such as jack-up rigs, semi-submersible rigs, drill ships, and related offshore production units. Aban Offshore was incorporated in 1986 and went public in 1988, and it describes itself as a global offshore drilling services provider. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Accent Capital idwC7jUI7UuTGg View details | Other | — | |||
|
Accent Capital is a private investment firm based in the Republic of Cyprus that says it invests in high-quality assets with growth potential tied to global economic and demographic trends. Its public website presents the company as an investment business focused on identifying opportunities with long-term value, while associated records show a separate Accent Capital Plc incorporated in 2019 to provide external funding support for the Accent Group. In catalog and threat-intelligence contexts, Accent Capital may therefore appear as a financial-services or investment-related entity rather than a broad operating company. It was listed as a ransomware victim associated with ddosecret. |
||||||