Ransomware Group intelligence
Emperador
ActiveTrack Emperador with 23 published victims and 1 known leak locations in a single intelligence view.
Overview
Emperador is tracked by Breach House as a ransomware group with 23 published victims.
Albania is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 4h ago | emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion |
Top Activity Sectors (6)
- Public Sector 2
- Education 2
- null 1
- Energy 1
- IT 1
- Manufacturing / Engineering 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Emperador, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: emporador executes PowerShell scripts to automate credential access and system reconnaissance.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: emporador persists via Registry Run Keys to ensure recurring execution after reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: emporador disables security tools by terminating or modifying antivirus and monitoring utilities.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: emporador deletes Volume Shadow Copies and backup directories to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: emporador performs remote system discovery to identify additional victims within the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: emporador discovers system network connections to locate exposed services for exploitation.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1083 File and Directory Discovery Discovery
What they do: emporador uses file and directory discovery to enumerate user data and system paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: emporador moves laterally through SMB/Windows Admin Shares to compromise additional hosts.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: emporador encrypts victim files using its ransomware payload to hold data hostage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: emporador inhibits system recovery by corrupting restore points and disabling backup services.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (23)
Search, filter and paginate the victim timeline for Emperador. Showing 1–23 of 23.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Judicial Branch of the Province of Jujuy id32591 View details | Argentina | Public Sector | ||
|
The Judicial Branch of the Province of Jujuy is a public-sector entity located in the Indian state of Jujuy, functioning within the judicial administration of the province. It provides core legal and judicial services, including civil and criminal case adjudication, legal oversight, and public legal representation for residents within its jurisdiction. As a Public Sector organization in AR, it operates within sensitive governmental infrastructure and delivers essential services to the community. This entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor emperador. The listing reflects the observed relationship between this judicial institution and the identified ransomware campaign without disclosing unverified incident details. |
|||||
| Ransomware | Judicial Branch of the Province of Jujuy id32591 View details | Argentina | Public Sector | ||
|
The official website of the Judicial Branch of Jujuy, Argentina. It provides court information, digital case management, mediation services, legal rulings, and judicial news for legal professionals and the public. Now i have your wordpress databases, login credentials to internal systems(thanks to marcos :)), as well as your email credentials Respond to us, pay the ransom.(Check your emails & check spam as well.) [Size: 4.2 GB | Sector: Government, Law] |
|||||
| Ransomware | Uniguacu id32268 View details | null | |||
|
Uniguacu is an entity cataloged as a ransomware victim within a threat-intelligence index. Publicly available information does not specify a distinct sector, operational offerings, or geographic location for Uniguacu, so its profile remains limited to its designation as a ransomware incident victim. The listing explicitly associates this entity with the threat actor emperador, linking it to activity attributed to that actor in cybersecurity threat records. No confirmed details regarding stolen data, ransom demands, breach scope, or specific incident outcomes are provided in available sources. This entry serves as a neutral reference point for threat analysts tracking ransomware victims and their associated actors. |
|||||
| Ransomware | Uniguacu id32268 View details | null | |||
|
full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! [Size: 151.0 MB | Sector: Education] |
|||||
| Ransomware | Uniguacu id32268 View details | Brazil | null | ||
|
full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! [Size: 151.0 MB | Sector: Education] |
|||||
| Ransomware | Hanwha Renewables id32227 View details | Korea, Republic of | Energy | ||
|
Hanwha Renewables is a South Korean energy-sector company specializing in renewable energy solutions, including solar, wind, and energy storage projects across regional markets. Operating within the critical infrastructure domain of energy, the entity provides clean power generation services and supports sustainable development initiatives. This listing identifies Hanwha Renewables specifically as a ransomware victim linked to the EMPERADOR threat actor. The entry reflects the cyber incident within the threat-intelligence index without disclosing unconfirmed technical details or operational impact specifics. |
|||||
| Ransomware | Hanwha Renewables id32227 View details | Korea, Republic of | Energy | ||
|
The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after your practices and contracts are leak. Good luck looking for financing/investment for these assets with the data leaked. [Size: 11.7 GB | Sector: Energy] |
|||||
| Ransomware | Ipro.com(revealdata.com) customer DB + full database backup id32202 View details | United States | IT | ||
|
revealdata.com operates within the information technology sector based in the United States. The entity serves as a catalog entry within this threat-intelligence index, specifically categorized as a ransomware victim. Its association is tied to the threat actor emperador, providing context for its inclusion in cybersecurity threat monitoring frameworks. This description maintains neutrality regarding incident specifics while documenting the verified listing relationship. The entry supports analytical workflows for threat intelligence professionals tracking ransomware-related entities and actor connections across sectors and geographies. |
|||||
| Ransomware | Ipro.com(revealdata.com) customer DB + full database backup id32202 View details | United States | IT | ||
|
Yes, this data has been posted before by ME under a different alias, yes the individual that posted the data on cracked.st is a fraud. I am posting this just for fun. Data contains: Customer identifiers, Contact & Location, Account metadata, Internal System IDS, Client relationships. The full database backup contains everything such as transcripts, cases, though it is from 2023. [Size: 79.5 MB | Sector: Government, Law] |
|||||
| Ransomware | Capitol Mechanics id32185 View details | United States | — | ||
|
Capitol Mechanics is a United States-based entity operating within the mechanical, industrial, or facility maintenance sector, providing mechanical services, equipment support, or related operational offerings to clients and infrastructure stakeholders. As cataloged in this threat-intelligence index, Capitol Mechanics is listed as a ransomware victim associated with the threat actor emperador. The listing type identifies the entity's relationship to this specific cyber incident without disclosing unconfirmed technical details, data exfiltration specifics, or operational impact. This entry serves to document the association for security researchers, defenders, and intelligence consumers tracking ransomware campaigns and their affected organizations across the United States. |
|||||
| Ransomware | Capitol Mechanics id32185 View details | United States | — | ||
|
Capitol Mechanics , fresh databases, important docs [Size: 120.9 MB | Sector: Finance, Transportation] |
|||||
| Ransomware | FRUCASTRO SL id32050 View details | Spain | Manufacturing / Engineering | ||
|
FRUCASTRO SL is a company operating within the Manufacturing and Engineering sector, headquartered in Spain (country code ES). The entity provides industrial and technical engineering services, aligning with sectors commonly targeted by sophisticated cyber threats. Within the threat-intelligence index, FRUCASTRO SL is formally listed as a ransomware victim associated with the emperador threat actor. This classification reflects the entity's documented exposure within the threat landscape, contributing to broader cybersecurity intelligence for monitoring and defense planning. The entry remains neutral, focusing solely on the association without speculating on unverified incident details. |
|||||
| Ransomware | FRUCASTRO SL id32050 View details | Spain | Manufacturing / Engineering | ||
|
Recent databases, important documents [Size: 540.1 MB | Sector: Manufacturing] |
|||||
| Ransomware | Vietnam Electricity(EVNHANOI) id31935 View details | Viet Nam | — | ||
|
Vietnam Electricity (EVN), legally known as Tập đoàn Điện lực Việt Nam, is the largest power company and the sole national electric utility in Vietnam. Fully owned and controlled by the Vietnamese government since its inception in 1994, EVN operates as a vertically integrated monopoly responsible for the nationwide generation, transmission, and distribution of electricity, as well as international power exchanges. The group oversees all major power plants and regional distribution subsidiaries, including EVNHANOI. Serving as a crucial pillar for Vietnam's macroeconomic stability and industrial expansion, EVN is currently undertaking extensive grid digitalization and spearheading the national transition from coal dependency toward clean and renewable energy integration. The data content exceeds 300GB, comprising 13.36 million rows of customer details, 6.99 million subscriptions, 2.26 million account records, and other miscellaneous data.The price is open to negotiation. Session:054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608 Tox:852E34CBEBA2D40FD21BAC9F9E588B5194DBA9F31CACF9ECE316403120BE18765D22A8A453C4 [Size: 300.0 GB | Sector: Government, Energy] |
|||||
| Ransomware | TEST id31962 View details | — | |||
|
Test [Size: 740.0 KB | Sector: Other] |
|||||
| Ransomware | NetExam id31924 View details | — | |||
|
NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. [Size: 18.1 MB | Sector: Education, Retail, Other] |
|||||
| Ransomware | Prefeitura Municipal de Arcos id31821 View details | Brazil | — | ||
|
We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin credentials have been exfiltrated. Critical systems have been encrypted. We have your data. You do not. You have 14 days to respond. No response = data published + permanent loss. Contact us through the provided channel. No third parties. No recovery attempts. [Size: 462.3 MB | Sector: Government] |
|||||
| Ransomware | Albania's Official National Teacher Training Portal id31782 View details | Albania | Education | ||
|
Albania's Official National Teacher Training Portal is a national online platform that provides training and educational resources to teachers in Albania. The portal operates within the education sector, offering various courses and materials to support teacher development and training. It is located in Albania and serves the country's educational community. Albania's Official National Teacher Training Portal was listed as a ransomware victim associated with emperador. |
|||||
| Ransomware | Albania's Official National Teacher Training Portal id31782 View details | Albania | Education | ||
|
Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: Education, Government] |
|||||
| Ransomware | Albania's official national teacher training portal. id31781 View details | Albania | Education | ||
|
Albania's official national teacher training portal operates in the education sector, providing training and resources to teachers across the country. Located in Albania, the portal offers various programs and materials to support teacher development and improve education quality. It was listed as a ransomware victim associated with emperador. |
|||||
| Ransomware | Albania's official national teacher training portal. id31781 View details | Albania | Education | ||
|
Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: Education, Government] |
|||||
| Ransomware | City Government of Baguio id31597 View details | Philippines | Public Sector | ||
|
Baguio.gov.ph is the official website of the city government of Baguio, Philippines, providing various public services and information to its citizens. As a key component of the public sector in the Philippines, the website offers a range of services and resources. Baguio.gov.ph was listed as a ransomware victim associated with emperador |
|||||
| Ransomware | City Government of Baguio id31597 View details | Philippines | Public Sector | ||
|
The City Government of Baguio stands as one of the wealthiest and most prominent local governments in the Philippines. This leak includes highly sensitive and confidential data, such as official contracts, legal permits, identification documents, financial statements, construction blueprints, project proposals, procurement records, and other classified administrative materials. [Size: 2.9 GB | Sector: Government, Finance, Construction] |
|||||