Ransomware Group intelligence
L Group
ActiveTrack L Group with 43 published victims and 2 known leak locations in a single intelligence view.
Overview
L Group is tracked by Breach House as a ransomware group with 43 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 4h ago | 4zrjdyuq4sjogm2epwwoleegquavhwo3o7fakstnlgox6guqt3qpe4qd.onion |
| Leak location 2 | Web location | Down checked 4h ago | 4zrjdyuq4sjogm2epwwoleegquavhwo3o7fakstnlgox6guqt3qpe4qd.onion/posts |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue L Group, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1047 Windows Management Instrumentation Execution
What they do: L Group uses Windows Management Instrumentation to execute remote commands and maintain initial foothold.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: L Group executes malicious payloads through PowerShell scripts stored in temporary directories to stage ransomware.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: L Group modifies Windows Registry Run keys to ensure ransomware execution after reboot.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: L Group disables antivirus tools by terminating security processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: L Group deletes Volume Shadow Copy and backup directories using vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: L Group uses file and directory discovery via PowerShell to enumerate user documents and system folders before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: L Group moves laterally through SMB/Windows Admin Shares to compromise additional networked machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: L Group archives victim data using built-in utility commands before exfiltration for extortion leverage.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: L Group encrypts victim files using custom symmetric encryption routines targeting documents, images, and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: L Group inhibits system recovery by corrupting restore points and disabling backup service restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (43)
Search, filter and paginate the victim timeline for L Group. Showing 1–43 of 43.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | compendiumusa.net id32051 View details | United States | Other | ||
|
Compendiumusa.net is an entity cataloged within the threat-intelligence index under the ransomware victim listing type. Operating within the Other sector and associated with the United States, the entity represents a target profile documented for cybersecurity analysis and intelligence aggregation. Its inclusion reflects the assessment of compromised infrastructure or organizational exposure within the ransomware threat landscape. The listing explicitly associates Compendiumusa.net with L Group, a recognized threat actor group. This description provides neutral, factual catalog context for researchers, defenders, and intelligence consumers monitoring ransomware incidents and associated actor activity. |
|||||
| Ransomware | compendiumusa.net id32051 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | cedarridge.org id31960 View details | United States | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | uva.edu.br id31409 View details | Brazil | Education | ||
|
The Universidade Veiga de Almeida, uva.edu.br, is a higher education institution located in Brazil, offering various academic programs. As an educational entity, it plays a significant role in the country's education sector. Uva.edu.br was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | uva.edu.br id31409 View details | Brazil | Education | ||
|
[AI generated] Universidade Veiga de Almeida (UVA) is a private higher education institution based in Rio de Janeiro, Brazil. Founded in 1972, it offers undergraduate and postgraduate courses across various fields including law, health sciences, engineering, and business administration. Operating in the education sector, UVA serves thousands of students through multiple campuses in Rio de Janeiro, providing in-person and distance learning programs. |
|||||
| Ransomware | ausfec1.com.au id31410 View details | Australia | Finance / Legal / Insurance | ||
|
Ausfec1.com.au operates in the finance, legal, and insurance sector in Australia, offering various services to its clients. The company is based in Australia and provides financial and legal solutions. Ausfec1.com.au was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | ausfec1.com.au id31410 View details | Australia | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | rosekennedygreenway.org id31411 View details | United States | NGOs / Associations | ||
|
The Rose Kennedy Greenway is a non-profit organization in the United States, dedicated to maintaining and programming a 1.5-mile park in Boston. As a key part of the city's landscape, it offers various events, activities, and green spaces for public enjoyment. The organization operates within the NGOs and associations sector, focusing on community development and environmental conservation. It was listed as a ransomware victim associated with L Group |
|||||
| Ransomware | rosekennedygreenway.org id31411 View details | United States | NGOs / Associations | ||
|
[AI generated] The Rose Kennedy Greenway Conservancy is a nonprofit organization based in Boston, Massachusetts, USA. It manages and maintains the Rose Kennedy Greenway, a series of parks and open spaces built atop the underground Interstate 93 highway in downtown Boston. The conservancy oversees programming, public art installations, gardens, and community events along the corridor, operating within the nonprofit parks and urban green space management sector. |
|||||
| Ransomware | jean-petit.lu id31412 View details | Luxembourg | Retail / E-commerce | ||
|
Jean-petit.lu is a retail and e-commerce company based in Luxembourg, offering various products and services to customers. As an e-commerce platform, it provides online shopping experiences. Jean-petit.lu was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | jean-petit.lu id31412 View details | Luxembourg | Retail / E-commerce | ||
|
[AI generated] N/A |
|||||
| Ransomware | atp.chaco.gob.ar id31413 View details | Argentina | Public Sector | ||
|
atp.chaco.gob.ar is a government website in Argentina, specifically in the Chaco province, providing public services and information to citizens. The website is part of the public sector in Argentina, offering various online services and resources. atp.chaco.gob.ar was listed as a ransomware victim associated with L Group |
|||||
| Ransomware | atp.chaco.gob.ar id31413 View details | Argentina | Public Sector | ||
|
[AI generated] atp.chaco.gob.ar is the official web domain of the Administración Tributaria Provincial (ATP) of Chaco, a government agency located in Chaco Province, Argentina. It operates within the public sector, specifically in tax administration and revenue collection. The agency is responsible for managing provincial taxes, enforcing fiscal regulations, and providing taxpayer services to residents and businesses operating within the Chaco province. |
|||||
| Ransomware | l-a.com.vn id31414 View details | Viet Nam | Other | ||
|
l-a.com.vn is a company based in Vietnam, operating in the other sector. The company provides various offerings to its customers. l-a.com.vn was listed as a ransomware victim associated with L Group |
|||||
| Ransomware | l-a.com.vn id31414 View details | Viet Nam | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | automobile-mueller.info id31415 View details | Germany | Transportation / Travel / Logistics | ||
|
Automobile-mueller.info is a company operating in the transportation sector in Germany, providing services related to travel and logistics. The entity is involved in activities typical of the transportation industry, such as managing and coordinating the movement of goods and people. It was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | automobile-mueller.info id31415 View details | Germany | Transportation / Travel / Logistics | ||
|
[AI generated] N/A |
|||||
| Ransomware | laticrete.com.cn id31416 View details | China | — | ||
|
Laticrete.com.cn is a website of a company operating in the construction sector, specifically in the field of building materials and construction chemicals, located in China. The company provides a range of products and services to the construction industry. Laticrete.com.cn was listed as a ransomware victim associated with L Group |
|||||
| Ransomware | laticrete.com.cn id31416 View details | China | — | ||
|
[AI generated] LATICRETE China (laticrete.com.cn) is the Chinese subsidiary of LATICRETE International, a global manufacturer of construction materials. Operating in China's building materials industry, the company produces and distributes tile and stone installation systems, waterproofing solutions, flooring underlayments, and surface care products. It serves contractors, architects, and builders across residential and commercial construction sectors throughout mainland China. |
|||||
| Ransomware | mygoalseek.com id31417 View details | United States | IT | ||
|
Mygoalseek.com is a US-based company operating in the IT sector. The company likely provides services related to goal setting and achievement, given its name. Mygoalseek.com was listed as a ransomware victim associated with L Group |
|||||
| Ransomware | mygoalseek.com id31417 View details | United States | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | psec.com.ar id31418 View details | Argentina | Energy | ||
|
Psec.com.ar is an Argentine company operating in the energy sector, providing various services to its clients. As a key player in the country's energy industry, psec.com.ar is committed to delivering high-quality solutions. Psec.com.ar was listed as a ransomware victim associated with L Group |
|||||
| Ransomware | psec.com.ar id31418 View details | Argentina | Energy | ||
|
[AI generated] N/A |
|||||
| Ransomware | bouygues-es.fr id31419 View details | France | — | ||
|
Bouygues-es.fr is a French entity operating in the construction sector, providing various services in France. The company is part of the Bouygues group, a major player in the construction and civil engineering industry. Bouygues-es.fr was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | bouygues-es.fr id31419 View details | France | — | ||
|
[AI generated] Bouygues Energies & Services (bouygues-es.fr) is a French company operating in the energy and services sector. It is a subsidiary of the Bouygues Group and specializes in electrical engineering, facility management, energy efficiency, smart buildings, and industrial maintenance. The company operates primarily in France and internationally, serving public and private sector clients across infrastructure, construction, and multi-technical services. |
|||||
| Ransomware | ferretornillos.com id31420 View details | Mexico | — | ||
|
Ferretornillos.com is an e-commerce website based in Mexico, offering various products. The company operates in the retail sector, providing online shopping services to its customers. Ferretornillos.com was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | ferretornillos.com id31420 View details | Mexico | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | ratnasagar.com id31421 View details | India | Retail / E-commerce | ||
|
Ratnasagar.com is an e-commerce platform based in India, operating in the retail sector. It offers various products and services to its customers. Ratnasagar.com was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | ratnasagar.com id31421 View details | India | Retail / E-commerce | ||
|
[AI generated] Ratnasagar is an Indian educational publishing company based in India. It specializes in producing academic books, textbooks, and educational materials primarily for school-level students. The company serves the K-12 segment, offering curriculum-aligned content across various subjects. Operating in the education and publishing industry, Ratnasagar is known for distributing its materials through schools and educational institutions across India. |
|||||
| Ransomware | brdigital.net.br id31422 View details | Brazil | IT | ||
|
BRdigital.net.br is a Brazilian company operating in the IT sector, providing various services to its clients. As an IT company, it likely offers a range of technology-related solutions. BRdigital.net.br was listed as a ransomware victim associated with L Group. |
|||||
| Ransomware | brdigital.net.br id31422 View details | Brazil | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | daycohost.com id31423 View details | United States | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | venezolanadepinturas.com id31424 View details | Venezuela, Bolivarian Republic of | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | nokotapackers.com id31425 View details | United States | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | immobilia.hu id31426 View details | Hungary | — | ||
|
[AI generated] immobilia.hu is a Hungarian real estate platform operating in Hungary. The website serves as an online property marketplace where users can browse, list, and search for residential and commercial real estate, including apartments, houses, and land. It connects buyers, sellers, and renters within the Hungarian property market. The platform targets individuals and agencies looking to conduct real estate transactions across Hungary. |
|||||
| Ransomware | gslusa.com id31427 View details | United States | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | www.racheljulien.com id31428 View details | Canada | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | coastproduce.com id31429 View details | Australia | — | ||
|
[AI generated] Coast Produce Company is a wholesale produce distributor based in the United States, primarily operating in California. The company supplies fresh fruits and vegetables to retailers, restaurants, foodservice operators, and other commercial buyers. It operates within the agricultural distribution and food supply industry, serving clients across the West Coast and broader domestic markets with a focus on quality and reliable cold chain logistics. |
|||||
| Ransomware | zuckers.com id31430 View details | Germany | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | onsite-eng.ca id31431 View details | Canada | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | doclv.com id31432 View details | Latvia | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | www.upbrand.com id31433 View details | United States | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | cookieskids.com id31434 View details | United States | — | ||
|
[AI generated] Cookies Kids is a retail company based in the United States that specializes in children's clothing, footwear, and accessories. Operating primarily through its website and physical stores in New York, it offers affordable apparel for infants, toddlers, and teens. The company carries a wide range of brands and serves budget-conscious families. It has been a recognized name in children's retail for several decades. |
|||||