Ransomware Group intelligence
Eclipse
ActiveTrack Eclipse with 12 published victims and 2 known leak locations in a single intelligence view.
Overview
Eclipse is tracked by Breach House as a ransomware group with 12 published victims.
Singapore is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 4h ago | yecdjimqiaekprxza6wkqecma4bwt757qiyfjngsaxg7rkjv4xukpwad.onion |
| Leak location 1 | Onion service | Down checked 4h ago | eclipse4g5kxfwsvpu4qx5sdcnrji6gxl5gt67bucjlgt35g7akvjoid.onion |
Top Activity Sectors (4)
Typical Attacks (7)
▼MITRE ATT&CK does not currently catalogue Eclipse, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Eclipse executes malicious payloads via PowerShell scripts to deploy ransomware and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Eclipse disables security tools like antivirus software to prevent system recovery and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Eclipse deletes Volume Shadow Copies and backup files via vssadmin to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Eclipse uses file and directory discovery to locate sensitive data and backup locations for targeting.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1560.001 Archive via Utility Collection
What they do: Eclipse archives victim data using utility tools prior to encryption to facilitate potential exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Eclipse encrypts victim files using strong symmetric encryption to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Eclipse inhibits system recovery by corrupting critical services and disabling restore mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (12)
Search, filter and paginate the victim timeline for Eclipse. Showing 1–12 of 12.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | part1.simplexengg.in id32419 View details | India | Manufacturing / Engineering | ||
|
part1.simplexengg.in operates within the Manufacturing and Engineering sector based in India. The entity's domain name suggests specialized engineering services, though specific operational details remain limited in public threat-intelligence records. It is formally cataloged within this threat-intelligence index under the classification ransomware victim, with the associated threat actor identified as Eclipse. This listing reflects observed cybersecurity intelligence linking the organization to malicious activity attributed to Eclipse, providing context for defenders monitoring industrial-sector risks. The entry emphasizes neutral documentation of the victim classification, sector relevance, geographic location, and attacker association without asserting unverified breach specifics. |
|||||
| Ransomware | part1.simplexengg.in id32419 View details | India | Manufacturing / Engineering | ||
|
[AI generated] N/A |
|||||
| Ransomware | Royal Plaza On Scotts id32416 View details | Singapore | Retail / E-commerce | ||
|
royalplaza.com.sg operates within the Singapore retail and e-commerce sector, providing online commerce services and digital marketplace functionalities for consumers and business partners. As cataloged in this threat-intelligence index under the ransomware victim listing type, the entity is associated with the threat actor Eclipse. This classification reflects the cybersecurity context in which the organization was impacted, highlighting vulnerabilities within retail and e-commerce infrastructure targeted by coordinated cyber threats. The entry serves to document the incident within broader cyber threat intelligence frameworks for monitoring and risk assessment purposes. |
|||||
| Ransomware | Royal Plaza On Scotts id32416 View details | Singapore | Retail / E-commerce | ||
|
Royal Plaza on Scotts Hotel is a five-star independent hotel located in the heart of Singapore's Orchard Road, offering spacious and modern accommodations. With a legacy of over 50 years, it has been recognized as Asia Pacific's Best Independent Hotel, providing guests with a comfortable stay and award-winning halal-certified dining at its renowned Carousel restaurant. The hotel caters to both leisure and business travelers, featuring facilities for meetings, events, and weddings. Guests can enjoy exclusive offers and loyalty rewards through the I Prefer Hotel Rewards Programme. |
|||||
| Ransomware | ETNA Software id32217 View details | Italy | IT | ||
|
etnasoft.com operates within the IT sector and provides technology-focused services, solutions, or infrastructure relevant to enterprise digital environments. As documented in this threat-intelligence index, the entity is classified as a ransomware victim linked to the Eclipse threat actor. The listing reflects observed cybersecurity event data tied to Eclipse's activity within the IT domain. This entry serves to catalog the entity's association with the specified threat actor for monitoring and analysis purposes. No additional incident specifics, such as data breach details or financial impact, are included per strict factual reporting guidelines. |
|||||
| Ransomware | ETNA Software id32217 View details | Italy | IT | ||
|
ETNA Software is a company that provides white-label online trading solutions for brokers and FinTech firms, including mobile and web trading platforms. Their products are designed to help retail broker-dealers launch trading capabilities efficiently and cost-effectively. |
|||||
| Ransomware | Simplex Engineering id32166 View details | India | Manufacturing / Engineering | ||
|
www.simplexengg.in is an entity operating within the Indian manufacturing and engineering sector, providing specialized technical and engineering services. It is cataloged in the threat-intelligence index under the classification of ransomware victim, with the associated threat actor identified as Eclipse. The entity's inclusion reflects its documented exposure within cybersecurity threat landscapes affecting industrial and engineering organizations in India. This listing serves to contextualize the incident within sector-specific risk profiles and actor attribution frameworks. The record neutrally documents its association with Eclipse as a ransomware victim without elaborating on unverified technical or operational details. |
|||||
| Ransomware | Simplex Engineering id32166 View details | India | Manufacturing / Engineering | ||
|
Simplex Engineering & Foundry Works Pvt. Ltd. specializes in the design, fabrication, machining, and assembly of industrial equipment and components. With over seventy years of experience, the company has successfully completed numerous turnkey projects for both private and public sector organizations. Additionally, Simplex offers refurbishment services for industrial equipment and steel procurement through its Steel Service Center. Their esteemed clientele includes some of the largest engineering companies in India. |
|||||
| Ransomware | Crystal Pharmatech id32021 View details | United States | Healthcare / Pharma | ||
|
www.crystalpharmatech.com operates within the United States healthcare and pharmaceutical sectors, providing specialized technology solutions aligned with industry requirements. The entity is cataloged in the threat-intelligence index under the designation ransomware victim, associated with the threat actor Eclipse. This listing reflects cybersecurity intelligence compiled regarding organizational exposure within critical healthcare infrastructure. The description maintains a neutral, encyclopedic tone consistent with threat-intelligence documentation standards, focusing on verified associations without speculating on incident details. All references adhere to factual constraints regarding confirmed threats and disclosed information. |
|||||
| Ransomware | Crystal Pharmatech id32021 View details | United States | Healthcare / Pharma | ||
|
Crystal Pharmatech is a technology-driven contract research organization (CRO) that focuses on materials science and engineering for drug development. Established in 2010 and have R&D centers located in Suzhou (China), New Jersey, San Francisco (USA), and Toronto (Canada). Also its key differentiator is integrated and specialized services, including API solid-state research, crystallization, preformulation, formulation development and manufacturing, clinical supply. |
|||||
| Ransomware | Moscord id31775 View details | Singapore | IT | ||
|
Moscord.com is an IT company based in Singapore, offering various IT services. The company operates in the IT sector, providing solutions to its clients. Moscord.com was listed as a ransomware victim associated with Eclipse |
|||||
| Ransomware | Moscord id31775 View details | Singapore | IT | ||
|
Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to aggregate and present their products. The company aims to enhance business operations for its clients by providing innovative solutions in procurement, logistics, and eCommerce. Targeting maritime and oil & gas sectors, Moscord serves a global clientele through its extensive network of ports and offices across multiple countries. With a focus on improving user experience and operational efficiency, Moscord leverages advanced technology and industry expertise to facilitate seamless transactions. |
|||||