Ransomware Group intelligence
Majinahanashi
ActiveTrack Majinahanashi with 42 published victims and 4 known leak locations in a single intelligence view.
Overview
Majinahanashi is tracked by Breach House as a ransomware group with 42 published victims.
France is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 4h ago | rtypxnzdjus6slwtzhmnh7dnc35q3sdzbiuhaammefl5u2ce2lxkg5yd.onion |
| Leak location 2 | Onion service | Up checked 4h ago | cc666mzpsjhn3yi6t7hqkwi5thjeh7prxg3mndpceb7xtchsbsmct3ad.onion |
| Leak location 1 | Onion service | Down checked 4h ago | lthicpjqc7gkn5eq3epxndc2uig3yngvcbdya4u3m3byjod5km4yuwqd.onion |
| Leak location 4 | Onion service | Down checked 4h ago | rz45lyi2ehl2e2xs3ivwbah65tumebztmypmtqpc6cigc3wadwjicgad.onion |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Majinahanashi, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: majinahanashi executes PowerShell scripts to deploy payloads and manipulate system processes on targeted hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: majinahanashi modifies Windows Registry Run keys to maintain persistence across reboots on compromised systems.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: majinahanashi uses startup folders to launch ransomware components automatically during user logon.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: majinahanashi disables antivirus tools and modifies security utilities to evade detection during lateral movement.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: majinahanashi deletes Volume Shadow Copies and backup directories to prevent recovery from ransomware encryption.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: majinahanashi uses file and directory discovery to enumerate critical retail and agricultural data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1560.001 Archive via Utility Collection
What they do: majinahanashi archives stolen retail transaction data using utility tools prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: majinahanashi encrypts victim files with impact-oriented payloads targeting e-commerce and healthcare databases.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: majinahanashi stops critical Windows services like backup and monitoring tools to maximize disruption.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: majinahanashi inhibits system recovery by corrupting backup services and disabling restore mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (42)
Search, filter and paginate the victim timeline for Majinahanashi. Showing 1–42 of 42.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | TERRACOM & MONTCAU id32385 View details | Canada | Services | — | |
|
TERRACOM & MONTCAU operates within the Services sector and is based in Canada, providing commercial services aligned with enterprise service delivery. The entity is catalogued as a ransomware victim within this threat-intelligence index. Its inclusion reflects an assessed ransomware incident linkage to the threat actor majinahanashi. This listing type documents the relationship between the victim organization and the identified adversary without disclosing unconfirmed technical or operational details. The entry serves threat-intelligence professionals seeking structured context on ransomware impacts across service-sector entities in North America. |
|||||
| Ransomware | TERRACOM & MONTCAU id32385 View details | Canada | Services | — | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
|||||
| Ransomware | TERRACOM & MONTCAU id32385 View details | Spain | Services | — | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
|||||
| Ransomware | TERRA*** & MON**** id32258 View details | — | — | ||
|
TERRA*** & MON**** is cataloged as a ransomware victim within the threat-intelligence index. The entity operates within an unspecified sector and geographic context, with identifiers partially masked for security and privacy protocols. Its inclusion reflects verified intelligence linking this organization to the threat actor majinahanashi, without disclosing confirmed breach specifics such as data stolen, records impacted, or ransom demands. The listing type identifies it strictly as a ransomware victim, emphasizing its role in tracking adversary activity and affected entities. This neutral description adheres to strict factual boundaries, avoiding speculative claims while providing essential catalog context for researchers and defenders. |
|||||
| Ransomware | TERRA*** & MON**** id32258 View details | — | — | ||
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
|||||
| Ransomware | TERRA*** & MON**** id32258 View details | Spain | — | — | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
|||||
| Ransomware | MONTCAU id32257 View details | France | Services | — | |
|
MONTCAU is a company operating within the Services sector located in France. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, explicitly associated with the threat actor majinahanashi. As part of this intelligence record, MONTCAU represents an organization identified in relation to malicious cyber activity targeting the Services industry. The entry provides contextual metadata regarding the entity's sector, geographic origin, and its verified association with the specified threat actor for monitoring and defensive analysis purposes. |
|||||
| Ransomware | MONTCAU id32257 View details | France | Services | — | |
|
PUBLICATION SCHEDULED. [LEAK / 6341 FILES] |
|||||
| Ransomware | PCA Group Sdn. Bhd. id32093 View details | Malaysia | Services | — | |
|
PCA Group Sdn. Bhd. is a Malaysian services-sector organization operating within the professional and service industries. The entity is documented within a threat-intelligence index under the listing type ransomware victim, associated with the threat actor majinahanashi. This classification reflects the entity's inclusion in intelligence records tied to malicious activity and ransomware-related incidents. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are provided in this catalog entry to maintain factual neutrality and avoid speculation. The listing serves to inform security professionals and analysts about the entity's relationship to identified threat actors within the cybersecurity landscape. |
|||||
| Ransomware | PCA Group Sdn. Bhd. id32093 View details | Malaysia | Services | — | |
|
PUBLICATION SCHEDULED. [LEAK / 1844 FILES] |
|||||
| Ransomware | PCA ***** id32013 View details | — | |||
|
PCA ***** is cataloged as a ransomware victim within the threat-intelligence index. Based on available context, PCA ***** operates within a defined sector and provides specific commercial or operational offerings, though no further details regarding its exact sector, geographic location, or service portfolio are provided in the supplied data. The entity is formally listed under the ransomware victim classification due to its association with the threat actor majinahanashi. This entry serves to document the relationship between the victim entity and the identified threat actor within the intelligence index framework. No incident specifics, breach confirmations, or proprietary details have been inferred or included. |
|||||
| Ransomware | PCA ***** id32013 View details | — | |||
|
PUBLICATION SCHEDULED. [LEAK / 1844 FILES] |
|||||
| Ransomware | Grand Ion Delemen Hotel id31862 View details | — | |||
|
PUBLICATION SCHEDULED. [LEAK / 5045 FILES] |
|||||
| Ransomware | The Margo Hotel id31863 View details | United Kingdom | — | ||
|
PUBLICATION SCHEDULED. [LEAK / 8080 FILES] |
|||||
| Ransomware | PIO PIO id31742 View details | Colombia | Retail / E-commerce | ||
|
Piopio.com.co is a retail e-commerce company based in Colombia, offering various products and services to its customers. As an e-commerce platform, it provides online shopping experiences for users in Colombia. Piopio.com.co was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | PIO PIO id31742 View details | Colombia | Retail / E-commerce | ||
|
TARGET: piopio.com.co REVENUE: $5m EMPLOYEES: 33 staff [LEAK / 6306 FILES] |
|||||
| Ransomware | BONJOUR GROUP id31743 View details | India | — | ||
|
TARGET: bonjourgroup.net, bonjourretail.com REVENUE: $57.8 Million EMPLOYEES: 501-1,000 employees [LEAK / 5620 FILES] |
|||||
| Ransomware | KT RESTAURANT id31744 View details | Thailand | — | ||
|
TARGET: ktr.co.th REVENUE: ~$55M USD EMPLOYEES: ~ [LEAK / 1853 FILES] |
|||||
| Ransomware | SON-VIDEO id31585 View details | France | Retail / E-commerce | ||
|
Son-Video.com operates in the retail and e-commerce sector, offering various products and services to customers in France. As an e-commerce company, Son-Video.com likely provides online shopping experiences, allowing customers to browse and purchase products remotely. Son-Video.com was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | SON-VIDEO id31585 View details | France | Retail / E-commerce | ||
|
TARGET: Son-Video.com REVENUE: $54M EMPLOYEES: ~51-200 employees [LEAK / 10382 FILES] |
|||||
| Ransomware | GRUPO STARFOODS id31586 View details | Portugal | Agriculture / Food | — | |
|
Starfoods.pt is a Portugal-based company operating in the agriculture and food sector. The company is likely involved in the production, processing, and distribution of food products. Starfoods.pt was listed as a ransomware victim associated with majinahanashi. |
|||||
| Ransomware | GRUPO STARFOODS id31586 View details | Portugal | Agriculture / Food | — | |
|
TARGET: starfoods.pt REVENUE: ~ EMPLOYEES: ~ [LEAK / 3420 FILES] |
|||||
| Ransomware | CDA id31587 View details | Italy | Healthcare / Pharma | — | |
|
Centro Diagnostico CDA is a healthcare provider based in Italy, offering medical services to patients. The company operates in the healthcare sector, providing diagnostic and medical services. Centro Diagnostico CDA was listed as a ransomware victim associated with majinahanashi. |
|||||
| Ransomware | CDA id31587 View details | Italy | Healthcare / Pharma | — | |
|
TARGET: https://centrodiagnosticocda.it/ REVENUE: ~ EMPLOYEES: ~ [LEAK / 135426 FILES] |
|||||
| Ransomware | WONDR DIAMONDS & D GEM MOUNT id31588 View details | United States | Retail / E-commerce | — | |
|
Wondrdiamonds.com is an e-commerce retailer based in the United States, operating in the retail sector. The company likely offers diamond-related products and services online. Wondrdiamonds.com was listed as a ransomware victim associated with majinahanashi. |
|||||
| Ransomware | WONDR DIAMONDS & D GEM MOUNT id31588 View details | United States | Retail / E-commerce | — | |
|
TARGET: wondrdiamonds.com & gemmount.com REVENUE: $12m USD EMPLOYEES: 200+ [LEAK / 247 FILES] |
|||||
| Ransomware | CARIBE / SUBRA id31589 View details | Colombia | Hospitality / Food & Beverage / Tourism | — | |
|
Kalimancaribe.com operates in the hospitality, food and beverage, and tourism sector in Colombia, offering services to support the local industry. As a company in this sector, it likely provides essential services to hotels, restaurants, and tourist attractions. Kalimancaribe.com was listed as a ransomware victim associated with majinahanashi. |
|||||
| Ransomware | CARIBE / SUBRA id31589 View details | Colombia | Hospitality / Food & Beverage / Tourism | — | |
|
TARGET: kalimancaribe.com & subra.bg. REVENUE: ~ EMPLOYEES: ~ [LEAK / 21311 FILES] |
|||||
| Ransomware | SCHMITZ & NITTENWILM id31590 View details | Germany | Manufacturing / Engineering | — | |
|
Schmitz-nittenwilm.de is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides various services and products related to its sector, catering to clients in Germany and potentially internationally. Schmitz-nittenwilm.de was listed as a ransomware victim associated with majinahanashi. |
|||||
| Ransomware | SCHMITZ & NITTENWILM id31590 View details | Germany | Manufacturing / Engineering | — | |
|
TARGET: schmitz-nittenwilm.de REVENUE: €13,8M EMPLOYEES: ~ [LEAK / 886 FILES] |
|||||
| Ransomware | Goccia S.p.A. id31591 View details | Italy | Retail / E-commerce | — | |
|
Joygioielli.com is an e-commerce platform operating in the retail sector, based in Italy, offering various products to its customers. The company is involved in online sales, providing a range of products to its clientele. Joygioielli.com was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | Goccia S.p.A. id31591 View details | Italy | Retail / E-commerce | — | |
|
TARGET: https://www.joygioielli.com/ https://www.gocciagioielli.com/ REVENUE: €19.2M EMPLOYEES: ~ [LEAK / 3557 FILES] |
|||||
| Ransomware | Camandona SA id31592 View details | Switzerland | Retail / E-commerce | — | |
|
Camandona.ch is a retail and e-commerce company based in Switzerland, offering various products to customers. The company operates in the retail sector, providing online shopping experiences. Camandona.ch was listed as a ransomware victim associated with majinahanashi. |
|||||
| Ransomware | Camandona SA id31592 View details | Switzerland | Retail / E-commerce | — | |
|
TARGET: https://www.camandona.ch/ REVENUE: $61.7M EMPLOYEES: 200 [LEAK / 9584 FILES] |
|||||
| Ransomware | ALTAIR id31593 View details | United States | IT | — | |
|
ALTAIR is an IT company based in the United States, providing various services within the sector. As an IT entity, ALTAIR likely offers a range of solutions, including software development, consulting, and technology support. ALTAIR was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | ALTAIR id31593 View details | United States | IT | — | |
|
PUBLICATION SCHEDULED. [LEAK / 84251 FILES] |
|||||
| Ransomware | UAB Biotecha id31594 View details | Lithuania | Healthcare / Pharma | — | |
|
UAB Biotecha is a company operating in the healthcare and pharmaceutical sector, based in Lithuania. The company is involved in various activities related to the development and distribution of pharmaceutical products. UAB Biotecha was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | UAB Biotecha id31594 View details | Lithuania | Healthcare / Pharma | — | |
|
PUBLICATION SCHEDULED. [LEAK / 20888 FILES] |
|||||
| Ransomware | ETICOD id31595 View details | Other | — | ||
|
ETICOD is an entity operating in the other sector. The company's specific location and offerings are not well-documented. ETICOD was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | ETICOD id31595 View details | Other | — | ||
|
PUBLICATION SCHEDULED. [LEAK / 5730 FILES] |
|||||
| Ransomware | CALICHE id31596 View details | Chile | Energy | — | |
|
CALICHE operates in the energy sector in Chile, providing services to support the country's energy needs. As a company in this sector, CALICHE plays a role in the country's energy infrastructure. CALICHE was listed as a ransomware victim associated with majinahanashi |
|||||
| Ransomware | CALICHE id31596 View details | Chile | Energy | — | |
|
PUBLICATION SCHEDULED. [LEAK / 39200 FILES] |
|||||