Ransomware Group intelligence
Orion
ActiveTrack Orion with 19 published victims and 1 known leak locations in a single intelligence view.
Overview
Orion is tracked by Breach House as a ransomware group with 19 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 4h ago | cjfntkj5qeizxowuy3srceg7zo6namc3kfeor7pfn6bpdkl3w265ooid.onion |
Top Activity Sectors (3)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Orion, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Orion executes malicious payloads through PowerShell scripts to stage ransomware components across targeted systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Orion executes ransomware binaries through Windows Service installation to ensure persistence and stealth.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Orion disables security tools by terminating antivirus processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Orion deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Orion uses file and directory discovery via PowerShell to enumerate critical system and data folders before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1486 Data Encrypted for Impact Impact
What they do: Orion encrypts victim files using custom symmetric encryption routines targeting engineering documents and IT databases.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Orion inhibits system recovery by corrupting restore points and disabling automated backup restoration services.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Orion performs internal defacement by replacing project files with ransom notes containing decryption instructions.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (19)
Search, filter and paginate the victim timeline for Orion. Showing 1–19 of 19.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | huntongroup.com id31339 View details | United Kingdom | — | ||
|
huntongroup.com |
|||||
| Ransomware | hphood.com id31340 View details | United States | — | ||
|
hphood.com |
|||||
| Ransomware | bridgestoneamericas.com id31341 View details | United States | — | ||
|
bridgestoneamericas.com |
|||||
| Ransomware | albanybank.com id31342 View details | United States | — | ||
|
albanybank.com |
|||||
| Ransomware | ipsenlogistics.com id31343 View details | — | |||
|
ipsenlogistics.com |
|||||
| Ransomware | hetero.com id31344 View details | — | |||
|
hetero.com |
|||||
| Ransomware | sitrack.com id31345 View details | Germany | — | ||
|
sitrack.com |
|||||
| Ransomware | kioti.com id31346 View details | United States | — | ||
|
kioti.com |
|||||
| Ransomware | udhaiyamdhall.com id31347 View details | India | — | ||
|
udhaiyamdhall.com |
|||||
| Ransomware | emanic.net id31295 View details | Germany | IT | ||
|
emanic.net is an IT company based in Germany, providing various IT services. The company operates in the IT sector, offering its services to clients in Germany. emanic.net was listed as a ransomware victim associated with orion |
|||||
| Ransomware | emanic.net id31295 View details | Germany | IT | ||
|
emanic.net |
|||||
| Ransomware | daubertchemical.com id31296 View details | United States | Manufacturing / Engineering | ||
|
Daubert Chemical is a US-based company operating in the manufacturing and engineering sector, providing various chemical products and solutions. The company is headquartered in the United States and offers a range of services to its clients. Daubert Chemical is listed as a ransomware victim associated with orion |
|||||
| Ransomware | daubertchemical.com id31296 View details | United States | Manufacturing / Engineering | ||
|
daubertchemical.com |
|||||
| Ransomware | morrisgroupint.com id31297 View details | United Kingdom | Manufacturing / Engineering | ||
|
Morris Group International is a manufacturing and engineering company based in the United Kingdom. The company operates in the sector of manufacturing and engineering, providing various offerings to its clients. Morris Group International was listed as a ransomware victim associated with orion threat actor. |
|||||
| Ransomware | morrisgroupint.com id31297 View details | United Kingdom | Manufacturing / Engineering | ||
|
morrisgroupint.com |
|||||
| Ransomware | pricemodern.com id31298 View details | United States | Retail / E-commerce | ||
|
Pricemodern.com operates in the retail and e-commerce sector in the United States, offering various products and services to its customers. As an e-commerce company, it provides online shopping experiences, catering to a wide range of consumer needs. Pricemodern.com was listed as a ransomware victim associated with orion |
|||||
| Ransomware | pricemodern.com id31298 View details | United States | Retail / E-commerce | ||
|
pricemodern.com |
|||||
| Ransomware | Nitrex Chemicals India id31299 View details | India | Manufacturing / Engineering | ||
|
Nitrex is a company based in India, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Nitrex was listed as a ransomware victim associated with orion |
|||||
| Ransomware | Nitrex Chemicals India id31299 View details | India | Manufacturing / Engineering | ||
|
We only seek money. No morals, no political stance Your data is only secure IF you pay us |
|||||