Ransomware Group intelligence
Qilin
ActiveTrack Qilin with 2564 published victims and 5 known leak locations in a single intelligence view.
Overview
Qilin is tracked by Breach House as a ransomware group with 2564 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 120 74.5%
- Pending 33 20.5%
- Deleted 8 5.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 2h ago | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 5 | Onion service | Down checked 2h ago | ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion |
| Leak location 4 | Onion service | Down checked 2h ago | b4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onion |
Top Activity Sectors (18)
- Not identified 498
- Communication / Marketing 271
- Manufacturing / Engineering 201
- Services 201
- Finance / Legal / Insurance 171
- Construction / Real Estate 157
- Healthcare / Pharma 139
- IT 121
- Retail / E-commerce 88
- Education 73
- Public Sector 68
- Transportation / Travel / Logistics 53
- Energy 53
- Hospitality / Food & Beverage / Tourism 45
- Agriculture / Food 41
- Telecommunications 28
- NGOs / Associations 23
- Sports 1
Typical Attacks (52)
▼How Qilin typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Qilin.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566.001 Spearphishing Attachment Initial Access
What they do: Qilin has been delivered to victims through malicious email attachments.
What that means: Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
-
T1566.002 Spearphishing Link Initial Access
What they do: Qilin has been delivered via malicious links in spearphishing emails.
What that means: Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.001 PowerShell Execution
What they do: Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1204.001 Malicious Link Execution
What they do: Qilin has been executed by luring victims into clicking links in spearphishing emails.
What that means: An adversary may rely upon a user clicking a malicious link in order to gain execution.
-
T1204.002 Malicious File Execution
What they do: Qilin has been delivered to victims through spearphishing emails with malicious attachments.
What that means: An adversary may rely upon a user opening a malicious file in order to gain execution.
-
What they do: Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: Qilin can configure a Winlogon registry entry.
What that means: Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
-
What they do: Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.
What that means: Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: Qilin can use an embedded Mimikatz module for token manipulation.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
What they do: Qilin has pushed a scheduled task via a Group Policy Object for payload execution.
What that means: Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1036.004 Masquerade Task or Service Stealth
What they do: Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.
What that means: Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Qilin can delete itself from infected hosts after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1480 Execution Guardrails Stealth
What they do: Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1480.002 Mutual Exclusion Stealth
What they do: Qilin can create a mutex to ensure only one instance is running.
What that means: Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
-
T1678 Delay Execution Stealth
What they do: Qilin has the ability to delay execution.
What that means: Adversaries may employ various time-based methods to evade detection and analysis.
-
T1222 File and Directory Permissions Modification Defense Impairment
What they do: Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Qilin can terminate antivirus-related processes and services.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Qilin has the ability to clear Windows Event Logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1688 Safe Mode Boot Defense Impairment
What they do: Qilin can reboot targeted systems in safe mode to avoid detection.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1003.001 LSASS Memory Credential Access
What they do: Qilin can employ an embedded Mimikatz module to dump LSASS memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1007 System Service Discovery Discovery
What they do: Qilin can identify specific services for termination or to be left running at execution.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1016 System Network Configuration Discovery Discovery
What they do: Qilin can accept a command line argument identifying specific IPs.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Qilin can enumerate domain-connected hosts during its discovery phase.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Qilin can define specific processes to be terminated or left alone at execution.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Qilin can run PowerShell cmdlets to discover domain groups.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Qilin can exclude specific directories and files from encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Qilin can list all local users found on a targeted system.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1087.002 Domain Account Discovery
What they do: Qilin can use PowerShell cmdlets to enumerate domain users.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1135 Network Share Discovery Discovery
What they do: Qilin has the ability to list network drives.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1673 Virtual Machine Discovery Discovery
What they do: Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.
What that means: An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
-
T1680 Local Storage Discovery Discovery
What they do: Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1021.004 SSH Lateral Movement
What they do: Qilin can enable SSH access on ESXi hosts.
What that means: Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.002 File Transfer Protocols Command and Control
What they do: Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.
What that means: Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.
-
T1219.002 Remote Desktop Software Command and Control
What they do: Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.
What that means: An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.
-
T1486 Data Encrypted for Impact Impact
What they do: Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Qilin can terminate specific services on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1529 System Shutdown/Reboot Impact
What they do: Qilin can initiate a reboot of the backup server to hinder recovery.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
Tools Observed (27)
▼Software Qilin has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER-[rand]_2.txt
-- Qilin We have 3.4TB of your data stored on our servers. Contact us or we will publish this data on our blog, in the media and pass it on to the relevant authorities. We are ready to offer you a discount in case of payment within a week. Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from your system/network. Our group cooperates with the mass media. If you refuse to communicate with us and we do not come to an agreement, your data will be reviewed and published on our blog and on the media page (https://wikileaks2.site/) Blog links: http://kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials Please note that communication with us is only possible via the website in the Tor browser, which is specified in this note. All other means of communication are not real and may be created by third parties, if such were not provided in this note or on the website specified in this note. -- Credentials Extension: 2ir53sQQAU Domain: [snip] login: [snip] password:[snip]
README-RECOVER-[rand].txt
-- Qilin Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials-- Credentials Extension: [snip] Domain: e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion login: [snip] password:[snip]
DtMXQFOCos-RECOVER-README.txt
-- Agenda
Your network/system was encrypted.
Encrypted files have new extension.
-- Compromising and sensitive data
We have downloaded compromising and sensitive data from you system/network
If you refuse to communicate with us and we do not come to an agreementyour data will be published.
Data includes:
- Employees personal dataCVsDLSSN.
- Complete network map including credentials for local and remote services.
- Financial information including clients databillsbudgetsannual reportsbank statements.
- Complete datagrams/schemas/drawings for manufacturing in solidworks format
- And more...
-- Warning
1) If you modify files - our decrypt software won't able to recover data
2) If you use third party software - you can damage/modify files (see item 1)
3) You need cipher key / our decrypt software to restore you files.
4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions.
-- Recovery
1) Download tor browser: https://www.torproject.org/download/
2) Go to domain
3) Enter credentials
-- Credentials
Extension: DtMXQFOCos
Domain: wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion
login: [snip]
password: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2564)
Search, filter and paginate the victim timeline for Qilin. Showing 1701–1800 of 2564.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Sistema Odontológico Privado id23064 View details | Argentina | Communication / Marketing | — | ||
|
Sistema Odontológico Privado Srl is a company that operates in the Dental Offices industry. It employs 50to99 people and has 10Mto25M of revenue. The company is headquartered in Cordoba, Cordoba Province, Argentina. The amount of downloaded ... |
||||||
| Ransomware | American Journal of Managed Care id23063 View details | United States | Communication / Marketing | — | ||
|
Founded in 1995, The American Journal of Managed Care is a multimedia peer-reviewed, Medline-indexed journal that keeps industry leaders on the forefront of various different policies. This company is headquartered in Cranbury, New Jersey. T ... |
||||||
| Ransomware | Catawba County Government id23062 View details | United States | Public Sector | — | ||
|
Catawba County, NC provides an online directory to services around the area including Human Resources, Libraries, Sheriff's Office and more. Created for Catawba County and located in North Carolina. |
||||||
| Ransomware | HMP Global id23061 View details | United States | Healthcare / Pharma | — | ||
|
For 40 years, the company has built trusted brands including Psych Congress, the premier source for mental health education, and the Symposium on Advanced Wound Care (SAWC), the largest wound care meeting in the world. HMP Global partners wit ... |
||||||
| Ransomware | Morris-Sockle id23060 View details | United States | Communication / Marketing | — | ||
|
Morris-Sockle, PLLC is a premier law firm specializing in Family Law and Divorce, with over 40 years of experience in protecting clients' rights during and after divorce. They offer a comprehensive range of services including divorce processe ... |
||||||
| Ransomware | Capitol Construction Services id23059 View details | United States | Construction / Real Estate | — | ||
|
For over 25 years, Capitol Construction Services, Inc. has been one of the most professional general contractors in the Indianapolis market and has followed many clients all over the United States. CCSI has become experts in the areas of tena ... |
||||||
| Ransomware | Polar-studio id23058 View details | Sweden | Manufacturing / Engineering | — | ||
|
In 1994, the company became a major energy company, marking the beginning of its rapid development in the electrical installation industry. A change of ownership in 2023 will undoubtedly ensure future growth and expansion. Our production fac ... |
||||||
| Ransomware | H. Gascon id23057 View details | France | Energy | — | ||
|
Assisted by her colleagues, who are authorized to represent her during hearings and interviews at the firm or in companies, Maître Gascon successfully carries out the various tasks entrusted to her:Judicial mandates for safeguard proceedings ... |
||||||
| Ransomware | Clifford Paper id23053 View details | United States | Communication / Marketing | — | ||
|
Clifford Paper is a family-owned business with a deep legacy in the forest products industry, operating since 1985. They specialize in providing paper products and value-added services, focusing on production management and packaging solution ... |
||||||
| Ransomware | MPM Imports id23052 View details | Cyprus | Communication / Marketing | — | ||
|
MPM IMPORTS LTD is a family owned business which has been established in September 2013 as a spin off from the MPM GROUP of companies. MPM Imports specializes in importing and distributing a diverse range of products in Cyprus, including cos ... |
||||||
| Ransomware | Radiant Beauty Supplies id23051 View details | Canada | Communication / Marketing | — | ||
|
Radiant Beauty Supplies is a Canadian owned and operated business which has been proudly serving the professional beauty industry since 1968. Focusing on the most sought after global brands, we carry only the finest products in the hair, esth ... |
||||||
| Ransomware | Tong Yang Group id23050 View details | Taiwan, Province of China | Manufacturing / Engineering | — | ||
|
Tong Yang Group is a manufacturer of automotive plastics, sheet metal, and cooling products, as well as motorcycle plastics products, molds, and paints. The company was founded in 1952 and is headquartered in Tainan, Taiwan. |
||||||
| Ransomware | Club Lleuresport id23049 View details | Spain | Communication / Marketing | — | ||
|
Club Lleuresport is a versatile organization based in Barcelona dedicated to leisure management, promoting culture, education, and sports for everyone. Since 1992, it has managed various public and private facilities, including civic centers ... |
||||||
| Ransomware | Repeated Signal Solutions id23048 View details | Sweden | Services | — | ||
|
Repeated Signal Solutions (RSS) specializes in Cellular, Public Safety, and Wireless Coverage Solutions, offering a wide range of services including engineering, construction management, and managed services since 2004. Their expertise spans ... |
||||||
| Ransomware | Atarfil id23047 View details | Spain | Services | — | ||
|
Atarfil Sl is a company that operates in the Repair Services industry. It employs 50to99 people and has 10Mto25M of revenue. The company is headquartered in Atarfe, Andalusia, Spain |
||||||
| Ransomware | Greenstar Social Marketing id23046 View details | Pakistan | Communication / Marketing | — | ||
|
Greenstar Social Marketing Pakistan (G) Limited is dedicated to improving health outcomes in Pakistan through various initiatives, including social marketing, social franchising, and health systems strengthening. Their services focus on mater ... |
||||||
| Ransomware | DuVal & Associates id23045 View details | United States | Finance / Legal / Insurance | — | ||
|
DuVal & Associates specializes in FDA law, assisting clients in navigating complex regulatory requirements for medical devices, drugs, and food products. Their services include advocacy, regulatory support, compliance guidance, and on-site tr ... |
||||||
| Ransomware | Pratt Homes id23044 View details | Canada | Communication / Marketing | — | ||
|
Pratt Homes was founded in 1973 by Len and Lowell, who, along with their partner Uncle Doug, built their first official Pratt Home in Scandia. They faced student loans but were driven by a passion for quality craftsmanship. Their commitment t ... |
||||||
| Ransomware | Force Marketing id23043 View details | United States | Communication / Marketing | — | ||
|
Force Marketing, USA - Founded in 2006, Force Marketing is a leading marketing technology provider to the automotive industry, whose Helix Technologies, WeDrive Automotive and DRIVE video technology brands deliver combined synergies to optimi ... |
||||||
| Ransomware | DV Hardwoods id23042 View details | Canada | Agriculture / Food | — | ||
|
DV Hardwoods, Canada - an undisputed leader in the hardwood lumber sector. In short, the company destroys forests in the country and sells them abroad – to the US and other countries. The company harvests traditional Canadian maple, birch, ... |
||||||
| Ransomware | M&E Global Group id23039 View details | United States | Manufacturing / Engineering | — | ||
|
M&E Global Group, Inc. USA - specializes in point of purchase display and store fixture manufacturing, offering comprehensive services from design to production and fulfillment. Another part of this business is the production of parts such a ... |
||||||
| Ransomware | Karnes Electric Cooperative id23022 View details | United States | Energy | — | ||
|
Karnes Electric Cooperative, USA is a not-for-profit electric distribution utility that serves 12 counties in South Texas and the Coastal Bend region. Headquartered in Karnes City, Texas, it offers competitive rates and innovative solutions t ... |
||||||
| Ransomware | Bank3 id23020 View details | Finance / Legal / Insurance | — | |||
|
Bank3, USA - it's a disaster for the clients. Bank3 is a community-driven banking institution offering personal and business banking services, as well as mortgage lending. The bank serves clients in various locations including Memphis, Nashvi ... |
||||||
| Ransomware | San Bernard Electric Cooperative id23019 View details | United States | Services | — | ||
|
San Bernard Electric Cooperative, USA - offers a range of services including outage reporting, generator installation, and energy efficiency programs. Its intended clients are members of the community who utilize electric services, as well as ... |
||||||
| Ransomware | BHI Co., Ltd. id23018 View details | Korea, Republic of | Energy | — | ||
|
BHI Co., Ltd. engages in the manufacturing and supplying of power plant equipment worldwide. It offers pulverized coal fired boilers, heat recovery steam generators, circulating fluidized bed combustion boilers, oil and gas boilers, industria ... |
||||||
| Ransomware | SourceOne Corporation id23015 View details | United States | Communication / Marketing | — | ||
|
SourceOne Corporation, USA - specializes in managing all phases of Outside Plant (OSP) and Inside Plant (ISP) projects, offering comprehensive solutions including fiber design, permitting, construction, and final inspection. The company provi ... |
||||||
| Ransomware | hautsdefrance.fr id23014 View details | France | Education | — | ||
|
The Regional Council manages regional programs (economy, transport, education, vocational training, culture/sports, ecology). 1.passports 2.Personal data 3.School incident report |
||||||
| Ransomware | Frisquet id22993 View details | France | Energy | — | ||
|
Frisquet, France - is a manufacturer specializing in gas boilers and renewable energy solutions, offering a range of products including heat pumps, hot water tanks, and hybrid systems. Their offerings are aimed at both residential and collect ... |
||||||
| Ransomware | Dynamic Precision Sverige id22992 View details | Sweden | Communication / Marketing | — | ||
|
Dynamic Precision Sverige, Norway - is a company that operates in the Electronics industry. The company designs and builds complex microelectronics, starting from an idea, through prototyping and production line development to a mass producti ... |
||||||
| Ransomware | Valtorta id22988 View details | Italy | Manufacturing / Engineering | — | ||
|
Valtorta, Italy - develops and manufactures industrial cranes. Valtorta is the natural evolution of TRASMEC srl that has been especially operating in the sector of the bridge cranes since 1969. Its highly skilled staff includes a lot of tech ... |
||||||
| Ransomware | Team Schierl Companies id22986 View details | United States | Construction / Real Estate | — | ||
|
Team Schierl Companies is an organization of retail businesses and real estate development. TSC was founded in 1956 and is currently headquartered in Stevens Point, Wisconsin. Today, the family owned and operated Team Schierl Companies passed ... |
||||||
| Ransomware | Artan Holding id22947 View details | Qatar | Construction / Real Estate | — | ||
|
Artan Holding is a Qatari family-owned holding company with a diverse portfolio of leading businesses in the Education, Real Estate, and Industrial sectors operating primarily in Qatar. Since its founding more than 25 years ago Artan Holding ... |
||||||
| Ransomware | grupocaparros.com id22946 View details | Spain | Agriculture / Food | — | ||
|
Caparrós, Spain - One of the leading companies at the national level for the sale of agricultural products abroad. The company sells local products: tomatoes, peppers, cucumbers, eggplants, zucchini and watermelons. The main sales market is ... |
||||||
| Ransomware | www.ucisd.net id22924 View details | United States | Education | — | ||
|
Uvalde Consolidated Independent School District, USA - is a public school district based in Uvalde, Texas, US. Located in Uvalde County, the district extends into portions of Zavala and Real counties. It is a progressive, rural school distri ... |
||||||
| Ransomware | Midsun Group id22920 View details | United States | Communication / Marketing | — | ||
|
Midsun Group, USA specializes in extending the life of power utility equipment through premium silicone covers and coatings. Their innovative products provide solutions for wildlife intrusion and environmental contamination, enhancing reliabi ... |
||||||
| Ransomware | MBS Secure id22916 View details | United States | IT | — | ||
|
MBS Secure, Ntiva - Ignore your teeth and they'll go away. The same goes for customers. If you leak their confidential data online, they'll leave. That's what happened to MBS Secure, a cybersecurity company. It has many customers, including i ... |
||||||
| Ransomware | cameronhodges.com id22904 View details | United States | Finance / Legal / Insurance | — | ||
|
Cameron, Hodges, Coleman, LaPointe & Wright, USA - No matter where you are in Florida, we are here to leak your data. law firm specializing in insurance defense with over 35 years of experience. They provide legal services to clients across F ... |
||||||
| Ransomware | Spectra Logic+DATA id22886 View details | United States | Communication / Marketing | — | ||
|
ALL THE DATE IS AVAILABLE FOR DOWNLOAD Spectra Logic, USA - data protection and storage company LMAOOOAHHAHA I'm dead!!! Sorry, but this is really really funny. PROTECTION! STORAGE! DATA!!!! On our blog, yes. So, Spectra Logic helps organiz ... |
||||||
| Ransomware | www.auto-bernhard.at id22864 View details | Austria | Retail / E-commerce | — | ||
|
Autohaus Bernhard, Germany - The naked truth about “reliable” European cars. The company sells, services, and rents well-known European cars such as Citroën and Opel. The company owns its own dealerships, auto repair shops, and a 2,200 m ... |
||||||
| Ransomware | BCR Recouvrement id22863 View details | France | Services | — | ||
|
BCR Recouvrement, located at 129 Rue Servient in Lyon, France, is a company specializing in debt recovery and credit management services. Their mission is to help businesses recover unpaid debts from clients, ensuring that companies can maint ... |
||||||
| Ransomware | California Golf Club of San Francisco id22862 View details | United States | Communication / Marketing | — | ||
|
California Golf Club of San Francisco, commonly known as Cal Club, is a private golf club established in 1918, originally located in Ingleside before moving to its current 425-acre site in 1924. The club features a world-class golf course des ... |
||||||
| Ransomware | Asahi Group Holdings, Ltd. id22860 View details | Japan | Hospitality / Food & Beverage / Tourism | — | ||
|
Asahi Group Holdings, Japan - a leading manufacturer of beer and non-alcoholic beverages in Japan. Asahi is headquartered in Sumida, Tokyo. It ranked 593rd on the Forbes Global 2000 list of the world's largest companies in 2023. The company's ... |
||||||
| Ransomware | Massachusetts Bay Community College id22859 View details | United States | Education | — | ||
|
Massachusetts Bay Community College is a comprehensive, open-access community college, offering associate degrees and certificate programs. We gave MassBay every opportunity to prevent this publication. We engaged their leadership. Their re ... |
||||||
| Ransomware | Clifford Paper Inc id22850 View details | United States | Communication / Marketing | — | ||
|
Clifford Paper Inc, USA - is a family-owned business with a deep legacy in the forest products industry, operating since 1985. They specialize in providing paper products and value-added services. Clifford Paper maintains strong relationships ... |
||||||
| Ransomware | kanzlei-schramm.com id22845 View details | Germany | Finance / Legal / Insurance | — | ||
|
Markus Schramm, Rechtsanwalt und Steuerberater, Germany - A lawyer you shouldn't trust with your secrets. As you might guess, its founder, Markus Schramm, is not one for false modesty. He wants his name to be remembered. Well, he has achieved ... |
||||||
| Ransomware | Development Services Group, Inc. id22843 View details | United States | IT | — | ||
|
Development Services Group, Inc., USA - The most high-profile terrorist attacks and crimes against the public that are being planned. All of this is contained in the reports of Development Services Group, Inc. You have to admit, it's interes ... |
||||||
| Ransomware | www.landmarkmgtinc.com id22842 View details | United States | Construction / Real Estate | — | ||
|
Landmark Management, Inc., manages 90 projects, consisting of 2,462 units across 5 states. Whether you are searching for an apartment to rent or a reliable company to manage your rural development property, let us put our thirty-six years of ... |
||||||
| Ransomware | ville-saintclaude.fr id22841 View details | France | Public Sector | — | ||
|
Mairie de Saint-Claude, France - life on a volcano. Saint-Claude is a commune in the Jura department, in the Burgundy-Franche-Comté region. It is the administrative center of the arrondissement of Saint-Claude and the canton of Saint-Claude. ... |
||||||
| Ransomware | Mecklenburg County Public Schools id22837 View details | United States | Public Sector | — | ||
|
Charlotte-Mecklenburg School District, USA - Do you keep your children's secrets? They are the most precious thing you have. They must not be betrayed. And that is exactly what the Charlotte-Mecklenburg School District (CMS) specializes in. T ... |
||||||
| Ransomware | mcgeorgeai.com id22836 View details | United States | Construction / Real Estate | — | ||
|
McGeorge Architecture Interiors (MAI), USA - свободный доступ в любой дом. MAI is a full service architecture and interior design firm specializing in corporate office, retail projects of all varying scopes and sizes, ... |
||||||
| Ransomware | kecymetals.com id22835 View details | United States | Manufacturing / Engineering | — | ||
|
Kecy Metal Technologies, USA - Terrible management, outdated equipment, uncompetitive salaries. This is how employees describe working conditions at Kecy Metal Technologies on condition of anonymity. The company was founded in 1988 in Michiga ... |
||||||
| Ransomware | Lipapromet id22834 View details | Croatia | Communication / Marketing | — | ||
|
Lipapromet, Croatia - is there light at the end of the tunnel? This Croatian company was founded in Zagreb in 1990. It specializes in LED lighting solutions. According to financial reports, Lipapromet's annual revenue in 2024 was €31,728,95 ... |
||||||
| Ransomware | Rihatec.de id22811 View details | Germany | Communication / Marketing | — | ||
|
Rihatec Systemlösungen, Germany - Automation of control systems, innovative solutions, cooperation with large corporations. Sounds impressive, doesn't it? However, there is one caveat. Rihatec Systemlösungen GmbH was founded in 1995 near Mu ... |
||||||
| Ransomware | uhlcompany.com id22810 View details | United States | Construction / Real Estate | — | ||
|
Imagine that the building where you live or work has gone haywire. You can't turn the lights on or off, the heating and air conditioning systems are out of order, and the video cameras have stopped focusing on the right areas. Do you think th ... |
||||||
| Ransomware | AIP Asset Management id22808 View details | Canada | Services | — | ||
|
AIP Asset Management, KoreanLeak3 - is a global financial error. A company with a market-leading specialization in alternative investment strategies. AIP provides institutional and retail clients with access to customized investments that gi ... |
||||||
| Ransomware | Corban OneSource id22794 View details | United States | Services | — | ||
|
Corban OneSource, USA - maximize risks to compliance. Company provides comprehensive HR outsourcing services, including payroll administration, employee benefits management, and HR support, aimed at reducing risks and improving organizational ... |
||||||
| Ransomware | IONODES id22793 View details | Canada | Communication / Marketing | — | ||
|
IONODES, Canada - Privacy? No, we don't know about that. The company supplies and configures solutions for IP video storage, management, and display. Its products include smart devices such as IP video encoders and decoders, NVR servers, reco ... |
||||||
| Ransomware | sagchip.org id22734 View details | United States | Retail / E-commerce | — | ||
|
the Saginaw Chippewa Indian Tribe of Michigan, USA - It's impossible to keep a poker face now. This small community of about 3,000 people is located in Isabella County, near Mount Pleasant. The tribe owns gas stations, a water park, a hotel, ... |
||||||
| Ransomware | Mitchell Industries id22733 View details | United States | Energy | — | ||
|
Mitchell Industries, USA - like sand through one's fingers. The company manufactures Accu-Weld¢ wedge wire screens for applications in both the petroleum and refining industries. The family-owned company has been in business for many years a ... |
||||||
| Ransomware | Shamir Medical Center id22728 View details | Israel | Healthcare / Pharma | — | ||
|
We have successfully infiltrated and gained full access to your systems at Shamir Hospital, the largest medical facility in Israel. Over the course of our operation, we have exfiltrated approximately 8 terabytes of sensitive and confidential ... |
||||||
| Ransomware | Mitrani Rynor Adamsky & Toland id22705 View details | United States | Other | — | ||
|
The company has failed to contact us. Full file directory: http://securo45z554mw7rgrt7wcgv5eenj2xmxyrsdj3fcjsvindu63s4bsid.onion/data/12/ -- Files of interest -- Trial list including discovery and perso ... |
||||||
| Ransomware | Foremost Asset Management id22680 View details | United States | Services | — | ||
|
Foremost Asset Management, KoreanLeak3 - First and foremost, they forgot the rules of survival in the market. Company was established in 2021 in Seoul, South Korea. Young businessman Kim Yong-chol was confident that he could manage investment ... |
||||||
| Ransomware | Rectory School id22678 View details | United States | Education | — | ||
|
Rectory School, USA - What began as a charitable educational project has, turned into a money-making machine for children. The school, founded by Reverend Frank H. Bigelow in 1920, is now far removed from its philanthropic ideals. Sending you ... |
||||||
| Ransomware | TRAUM Investment Co. id22677 View details | China | Finance / Legal / Insurance | — | ||
|
TRAUM Investment Co., KoreanLeak3 - We confirm your fears. TRAUM Investment, a major player in the country's stock market, appeared in 2016. The company now has capital of 3.8 billion won ($2.7 million) and an investment portfolio of 119.8 bi ... |
||||||
| Ransomware | Petraville Asset Management id22676 View details | Hong Kong | Services | — | ||
|
Petraville Asset Management, KoreanLeak3 - a direct path to investment loss. Company was founded in Seoul, Korea, in 2022. The company is young but growing rapidly. Last year, they acquired a logistics center in Ichon (Gyeonggi Province). The ... |
||||||
| Ransomware | Mobidic Asset Management id22658 View details | Korea, Republic of | Services | — | ||
|
Mobidic Asset Management Co., KoreanLeak3 - another failure. The company has been operating on the country's stock market since 2021 (EX-DK Investment Korea) and currently has capital of 6 billion won ($4.2 million). The company operates as a ... |
||||||
| Ransomware | Pangea Travel Store id22654 View details | Spain | Retail / E-commerce | — | ||
|
PANGEA The Travel Store is a boutique travel agency that designs bespoke, full-service trips tailored to individual tastes. It blends an online platform with physical flagship stores so customers can get face-to-face consultations as well as ... |
||||||
| Ransomware | lakehaven.org id22636 View details | United States | Communication / Marketing | — | ||
|
Lakehaven Water District provides essential water and sewer services to residents of South King County, Washington. 1.The document dated January 3, 2025, is a report on GL Distribution for the pay period December 16–31, 2024 (payment on Ja ... |
||||||
| Ransomware | heparks.org id22632 View details | United States | Communication / Marketing | — | ||
|
The Hoffman Estates Park District strives to provide the local community with exceptional recreational programs, well-maintained parks, and high-quality facilities. Their offerings include a variety of programs for youth, adults, and seniors, ... |
||||||
| Ransomware | PTR Asset Management id22617 View details | Hong Kong | Services | — | ||
|
PTR Asset Management, KoreanLeak3 - A shell company that jumps from bed to bed. Meet PTR Asset Management. An investment company from South Korea. As they state on their official website, PTR Asset Management engages in value investing, ident ... |
||||||
| Ransomware | Yooshin Engineering Corporation id22606 View details | Korea, Republic of | Manufacturing / Engineering | — | ||
|
Yooshin Engineering Corporation provides engineering consulting services in South Korea and internationally. It offers various services, including feasibility study, basic and detailed design, construction project management, and post-complet ... |
||||||
| Ransomware | thomasmhughes.com id22602 View details | United States | Finance / Legal / Insurance | — | ||
|
Thomas M. Hughes, Ltd. USA - Calculation error. Company specializes in providing experienced legal counsel focused on employee benefits, ERISA, tax, and pension law. With over 30 years of expertise, they offer clear, practical solutions tailo ... |
||||||
| Ransomware | Podo Asset Management id22590 View details | Korea, Republic of | Services | — | ||
|
Podo Asset Management, KoreanLeak3 - Don't bite off more than you can chew. Not everyone follows this simple rule. A clear example is Podo Asset Management. It was founded in 2018. It specializes in direct investments and IPOs. Podo Asset Ma ... |
||||||
| Ransomware | WEST Inc. id22588 View details | Energy | — | |||
|
West Water & Energy Systems Technology, USA - clean, but dangerous. Company specializes in sustainable water treatment solutions for various industries, particularly mining, boiler systems, and cooling towers. The company suffered a global da ... |
||||||
| Ransomware | XCAssociates id22587 View details | Healthcare / Pharma | — | |||
|
XC Associates, USA specializes in the design and manufacturing of advanced carbon glass fiber composites tailored for various high-performance industries including medical, aerospace, energy, and consumer sectors. They offer a comprehensive r ... |
||||||
| Ransomware | HUB ASSET MANAGEMENT Co id22586 View details | Japan | Services | — | ||
|
HUB ASSET MANAGEMENT Co, KoreanLeak3 - an alternative approach to investment security. The company has a portfolio of 2.8 billion won, $2 million. HUB ASSET "strives to set standards for best practices in alternative investments by making inv ... |
||||||
| Ransomware | Trustar Capital Management Co id22585 View details | China | Services | — | ||
|
Trustar Capital Management Co., Korean Leak3 - the company has an investment portfolio of 2.4 billion won ($1.7 million). Registered on July 29, 2022 with the Financial Services Commission as a specialized asset manager in the private equity ... |
||||||
| Ransomware | Summit Asset Management id22584 View details | United States | Services | — | ||
|
Summit Asset Management, Inc., KoreanLeak3 - a report that investors do not want to get. The company has been operating on the stock market since 2022 and has a portfolio of 2.8 billion won, $2 million. Summit Asset, as required by law, publi ... |
||||||
| Ransomware | oconnorcp.com id22582 View details | United States | Construction / Real Estate | — | ||
|
O'Connor Capital Partners is a real estate investment company specializing in retail, office, industrial, residential, and multifamily properties in major cities across North America and Europe. The company was founded in 1983 and is headquar ... |
||||||
| Ransomware | waxhaw.com id22581 View details | United States | Communication / Marketing | — | ||
|
The Town of Waxhaw in North Carolina. 1.All files relate to municipal procurement and contracts for the Town of Waxhaw (NC) for land rights acquisition services, map preparation, and related work for the Waxhaw-Marvin Road and Kensington Dri ... |
||||||
| Ransomware | smpeurope.com id22580 View details | United Kingdom | Services | — | ||
|
SMP EUROPE, a family-owned business based in Nottingham, has been supplying engine management and ignition components to original equipment manufacturers and the aftermarket for over 50 years. We have achieved success in a competitive market ... |
||||||
| Ransomware | regalmold.com id22579 View details | United States | Communication / Marketing | — | ||
|
We design and manufacture custom molds, components, and many other types of tools and assemblies for a wide range of customers.To manufacture custom products, we use precision machining on CNC machines, 5-axis machining, electrical discharge ... |
||||||
| Ransomware | sperispa.com id22578 View details | Italy | Telecommunications | — | ||
|
SPERI SPA provides its clients with a full range of services related to the architectural environment, buildings, and infrastructure. 1.Summary of the project “Sustainable Management of Protected Areas in Mauritania – Fisheries Monitorin ... |
||||||
| Ransomware | grupobocel.com id22577 View details | Colombia | Manufacturing / Engineering | — | ||
|
Grupo Bocel is a holding company comprising two companies: La Dominicana Industrial and Molinos Valle del Cibao, located in Santiago de los Caballeros, Dominican Republic.La Dominicana Industrial manufactures and sells pasta, while Molinos Va ... |
||||||
| Ransomware | halemakua.org id22576 View details | United States | Communication / Marketing | — | ||
|
Hale Makua Health Services is a private, non-profit company located on the Hawaiian island of Maui. Our mission is to improve the well-being of our clients by providing personalized medical services at home, both at our facility and at your ... |
||||||
| Ransomware | www.officepro.cl id22565 View details | Chile | Communication / Marketing | — | ||
|
Office Pro, Chile - a leading distributor of office supplies. The company began operations in 1991 in the Vitacura district under the name Distribuidora Capri. Over many years of operation, the company has accumulated a huge number of custome ... |
||||||
| Ransomware | www.mpmimports.com.cy id22564 View details | Cyprus | Retail / E-commerce | — | ||
|
MPM IMPORTS LTD, Cyprus - is a family owned business which has been established in September 2013 as a spin off from the MPM GROUP of companies. The company supplies cosmetics, car tires, and other consumer goods to the island. Over the years ... |
||||||
| Ransomware | www.apm-finance.de id22561 View details | Germany | Finance / Legal / Insurance | — | ||
|
APM Finance GmbH, Germany specializes in outsourced accounting services specifically designed for the automotive industry. The company offers comprehensive accounting, payroll, management accounting, and control consulting services. The compa ... |
||||||
| Ransomware | www.meduane-habitat.fr id22560 View details | France | Construction / Real Estate | — | ||
|
MEDUANE HABITAT, France - The company builds and rents out social housing. Today, Méduane Habitat manages 6,300 housing units, mainly in Laval, but since 1996, the company has expanded its activities to other municipalities in the Laval aggl ... |
||||||
| Ransomware | www.cr-installers.com id22559 View details | United States | Transportation / Travel / Logistics | — | ||
|
Chris Rodriguez Installers, USA - The company specializes in the installation, delivery, and warehousing of system furniture for federal, regional, and commercial organizations. CRI also operates a 50,000-square-foot warehouse conveniently lo ... |
||||||
| Ransomware | www.chinup.com.tw id22558 View details | Taiwan, Province of China | Manufacturing / Engineering | — | ||
|
Chinup Technology Co., Taiwan - Chinup specializes in manufacturing Cutting Presses, Die Cutting Machines, Automated Cutting Systems, and Card Processing Machinery. Established in 2001, the company expanded its expertise to include solar modu ... |
||||||
| Ransomware | cegconstruction.com id22526 View details | United States | Construction / Real Estate | — | ||
|
CEG Construction is on a path to self-destruction. This company is an industrial contractor based in Southern California that specializes in the construction of concrete warehouses and food processing facilities. They offer comprehensive desi ... |
||||||
| Ransomware | ZEF id22511 View details | Finland | Education | — | ||
|
ZEF, Germany - Center for Development Research University of Bonn. ZEF conducts interdisciplinary research in the fields of political, economic, and general development. The institute advises governments, national and international organizati ... |
||||||
| Ransomware | goodcents.com id22509 View details | United States | Agriculture / Food | — | ||
|
Goodcents, USA - Cheap food outlets are part of Custom Foods Inc., a company that produces frozen dough. The company manufactures a wide range of products, including dough for pizza, bread, cookies, and much more. The company supplies its pro ... |
||||||
| Ransomware | NV ELMAR id22508 View details | Aruba | Energy | — | ||
|
A blackout in Aruba is only a matter of time. The incompetence and unprofessionalism of NV ELMAR managers — the only electricity supplier on the island — could send the entire island back to the Stone Age. It has long been known that thin ... |
||||||
| Ransomware | Promociones Luis Barros id22504 View details | Spain | Hospitality / Food & Beverage / Tourism | — | ||
|
Promociones Luis Barros is a Galician family firm specializing in the construction and promotion of luxury residences in southern Pontevedra. They offer high-end housing solutions, including custom-built homes, catering to discerning client ... |
||||||
| Ransomware | EUM Asset Management id22501 View details | Korea, Republic of | Services | — | ||
|
EUM Asset Management, Korean Leak2. Company claims that customer trust is their top priority. Well, they have lost that trust. The Seoul-based asset management company focuses primarily on private equity funds. They also deal in stocks, bonds ... |
||||||
| Ransomware | Broad High Asset Management id22478 View details | China | Services | — | ||
|
Broad High Asset Management Co., Korean Leak2. A private investment fund management company registered with the Financial Services Commission in April 2022. The company's total investment portfolio is 2.65 billion won ($1.8 million). Key prod ... |
||||||
| Ransomware | EOS Asset management id22477 View details | United Kingdom | Services | — | ||
|
EOS Asset management CO., Korean Leak2. The company has been operating on the Korean stock market since 2021. Its total investment portfolio is 22 bil won ($15.8 mil). An asset management company specializing in brokerage services for lendin ... |
||||||
| Ransomware | ST Asset Management Co id22476 View details | Korea, Republic of | Services | — | ||
|
ST Asset Management Co, Korean Leak2. You can change your name and declare a new mission, but you still won't be able to hide your deceitful nature. Meet ST Asset Management Co., Ltd., Seoul, Korea. They position themselves as specialists in ... |
||||||