Ransomware Group intelligence
Qilin
ActiveTrack Qilin with 2564 published victims and 5 known leak locations in a single intelligence view.
Overview
Qilin is tracked by Breach House as a ransomware group with 2564 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 120 74.5%
- Pending 33 20.5%
- Deleted 8 5.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 4h ago | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 5 | Onion service | Down checked 4h ago | ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion |
| Leak location 4 | Onion service | Down checked 4h ago | b4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
| Leak location 2 | Onion service | Down checked 4h ago | kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion |
| Leak location 1 | Onion service | Down checked 4h ago | ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onion |
Top Activity Sectors (18)
- Not identified 498
- Communication / Marketing 271
- Manufacturing / Engineering 201
- Services 201
- Finance / Legal / Insurance 171
- Construction / Real Estate 157
- Healthcare / Pharma 139
- IT 121
- Retail / E-commerce 88
- Education 73
- Public Sector 68
- Transportation / Travel / Logistics 53
- Energy 53
- Hospitality / Food & Beverage / Tourism 45
- Agriculture / Food 41
- Telecommunications 28
- NGOs / Associations 23
- Sports 1
Typical Attacks (52)
▼How Qilin typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Qilin.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566.001 Spearphishing Attachment Initial Access
What they do: Qilin has been delivered to victims through malicious email attachments.
What that means: Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
-
T1566.002 Spearphishing Link Initial Access
What they do: Qilin has been delivered via malicious links in spearphishing emails.
What that means: Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.001 PowerShell Execution
What they do: Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1204.001 Malicious Link Execution
What they do: Qilin has been executed by luring victims into clicking links in spearphishing emails.
What that means: An adversary may rely upon a user clicking a malicious link in order to gain execution.
-
T1204.002 Malicious File Execution
What they do: Qilin has been delivered to victims through spearphishing emails with malicious attachments.
What that means: An adversary may rely upon a user opening a malicious file in order to gain execution.
-
What they do: Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: Qilin can configure a Winlogon registry entry.
What that means: Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
-
What they do: Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.
What that means: Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: Qilin can use an embedded Mimikatz module for token manipulation.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
What they do: Qilin has pushed a scheduled task via a Group Policy Object for payload execution.
What that means: Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1036.004 Masquerade Task or Service Stealth
What they do: Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.
What that means: Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Qilin can delete itself from infected hosts after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1480 Execution Guardrails Stealth
What they do: Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1480.002 Mutual Exclusion Stealth
What they do: Qilin can create a mutex to ensure only one instance is running.
What that means: Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
-
T1678 Delay Execution Stealth
What they do: Qilin has the ability to delay execution.
What that means: Adversaries may employ various time-based methods to evade detection and analysis.
-
T1222 File and Directory Permissions Modification Defense Impairment
What they do: Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Qilin can terminate antivirus-related processes and services.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Qilin has the ability to clear Windows Event Logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1688 Safe Mode Boot Defense Impairment
What they do: Qilin can reboot targeted systems in safe mode to avoid detection.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1003.001 LSASS Memory Credential Access
What they do: Qilin can employ an embedded Mimikatz module to dump LSASS memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1007 System Service Discovery Discovery
What they do: Qilin can identify specific services for termination or to be left running at execution.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1016 System Network Configuration Discovery Discovery
What they do: Qilin can accept a command line argument identifying specific IPs.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Qilin can enumerate domain-connected hosts during its discovery phase.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Qilin can define specific processes to be terminated or left alone at execution.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Qilin can run PowerShell cmdlets to discover domain groups.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Qilin can exclude specific directories and files from encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Qilin can list all local users found on a targeted system.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1087.002 Domain Account Discovery
What they do: Qilin can use PowerShell cmdlets to enumerate domain users.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1135 Network Share Discovery Discovery
What they do: Qilin has the ability to list network drives.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1673 Virtual Machine Discovery Discovery
What they do: Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.
What that means: An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
-
T1680 Local Storage Discovery Discovery
What they do: Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1021.004 SSH Lateral Movement
What they do: Qilin can enable SSH access on ESXi hosts.
What that means: Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.002 File Transfer Protocols Command and Control
What they do: Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.
What that means: Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.
-
T1219.002 Remote Desktop Software Command and Control
What they do: Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.
What that means: An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.
-
T1486 Data Encrypted for Impact Impact
What they do: Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Qilin can terminate specific services on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1529 System Shutdown/Reboot Impact
What they do: Qilin can initiate a reboot of the backup server to hinder recovery.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
Tools Observed (27)
▼Software Qilin has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER-[rand]_2.txt
-- Qilin We have 3.4TB of your data stored on our servers. Contact us or we will publish this data on our blog, in the media and pass it on to the relevant authorities. We are ready to offer you a discount in case of payment within a week. Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from your system/network. Our group cooperates with the mass media. If you refuse to communicate with us and we do not come to an agreement, your data will be reviewed and published on our blog and on the media page (https://wikileaks2.site/) Blog links: http://kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials Please note that communication with us is only possible via the website in the Tor browser, which is specified in this note. All other means of communication are not real and may be created by third parties, if such were not provided in this note or on the website specified in this note. -- Credentials Extension: 2ir53sQQAU Domain: [snip] login: [snip] password:[snip]
README-RECOVER-[rand].txt
-- Qilin Your network/system was encrypted. Encrypted files have new extension. -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning 1) If you modify files - our decrypt software won't able to recover data 2) If you use third party software - you can damage/modify files (see item 1) 3) You need cipher key / our decrypt software to restore you files. 4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Go to domain 3) Enter credentials-- Credentials Extension: [snip] Domain: e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid.onion login: [snip] password:[snip]
DtMXQFOCos-RECOVER-README.txt
-- Agenda
Your network/system was encrypted.
Encrypted files have new extension.
-- Compromising and sensitive data
We have downloaded compromising and sensitive data from you system/network
If you refuse to communicate with us and we do not come to an agreementyour data will be published.
Data includes:
- Employees personal dataCVsDLSSN.
- Complete network map including credentials for local and remote services.
- Financial information including clients databillsbudgetsannual reportsbank statements.
- Complete datagrams/schemas/drawings for manufacturing in solidworks format
- And more...
-- Warning
1) If you modify files - our decrypt software won't able to recover data
2) If you use third party software - you can damage/modify files (see item 1)
3) You need cipher key / our decrypt software to restore you files.
4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions.
-- Recovery
1) Download tor browser: https://www.torproject.org/download/
2) Go to domain
3) Enter credentials
-- Credentials
Extension: DtMXQFOCos
Domain: wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid.onion
login: [snip]
password: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2564)
Search, filter and paginate the victim timeline for Qilin. Showing 2501–2564 of 2564.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Upper Merion Township id10766 View details | United States | NGOs / Associations | — | — | |
|
The Upper Merion Youth Wrestling Association (UMYWA) is a non-profit organization, which has been in existence for over 40 years. The wrestling club was formed with the purpose of introducing our communities youth into the sport of wrestling. ... |
||||||
| Ransomware | ZGEO id10741 View details | Austria | Other | — | — | |
|
The company makes a decision to ignore us, all personal data are open and available for download below. |
||||||
| Ransomware | wannago.cloud id10739 View details | United Arab Emirates | IT | — | — | |
|
This service declares about its safety qualities and storing data in its site: "\COPIA - Backup as a service\ \DUplicato - Disaster recovery as a service\ \Controllo - Firewall as a service\ \ARCHIVO - Archival as a service\ \Securro - Secur ... |
||||||
| Ransomware | Commonwealth Sign id10659 View details | United States | Other | — | — | |
|
The company has chosen to ignore us means its data will be open and available for download below. |
||||||
| Ransomware | mordfin id10590 View details | United States | Construction / Real Estate | — | ||
|
The Mordfin Group was founded in 1922. The company provides accounting, tax, real estate, luxury, auditing, and estate planning services.Now you can download all data from this company. |
||||||
| Ransomware | wannagocloud id10564 View details | United Arab Emirates | IT | — | ||
|
you have a few days left until your customers are hurt by you. |
||||||
| Ransomware | neafidi id10563 View details | Italy | Finance / Legal / Insurance | — | ||
|
On February 2, we will publish personal data, financial statements and other confidential information |
||||||
| Ransomware | PROJECTSW id10465 View details | Saudi Arabia | Communication / Marketing | — | ||
|
The company makes a decision to ignore us, all personal data are open and available for download below. |
||||||
| Ransomware | F J O'Hara & Sons id10434 View details | United States | IT | — | — | |
|
F J O'Hara & Sons Inc is a company that operates in the Information Technology and Services industry. It employs 11-20 people and has $5M-$10M of revenue. The company is headquartered in Boston, Massachusetts. We have a lot of data from this ... |
||||||
| Ransomware | hotelcontinental.no id10410 View details | Norway | Hospitality / Food & Beverage / Tourism | — | — | |
|
We are waiting for you in the beginning of the next week. Hurry up... |
||||||
| Ransomware | molnar&partner id10385 View details | Hungary | Other | — | — | |
|
All data of this company will be available for download on 15.01.2024 |
||||||
| Ransomware | Corinth Coca-Cola Bottling Works id10376 View details | United States | Retail / E-commerce | — | — | |
|
Corinth Coca-Cola Bottling Works Grocery Retail · Mississippi, United States · 109 Employees About Corinth Coca-Cola Bottling Works Inc.: Corinth Coca-Cola Bottling Works, Inc. is a privately held, family-owned Coca-Cola bottling and di ... |
||||||
| Ransomware | HALLEONARD id10373 View details | Australia | Communication / Marketing | — | — | |
|
We are a subsidiary of Hal Leonard Corporation who, founded in 1947, is the world leader in the print music industry. Selling products in more than 65 countries around the world, Hal Leonard Corporation represents in print some of the world's ... |
||||||
| Ransomware | EPS.RS id10314 View details | Serbia | Energy | — | — | |
|
The joint stock company "Electric Power Industry of Serbia" is the largest company in Serbia, the economic and energy support of the country. The main activities of EPS AD are production, supply and trade of electricity. EPS is fully committe ... |
||||||
| Ransomware | Ware Manufacturing id9889 View details | Manufacturing / Engineering | — | — | ||
|
Family-owned for 25 years, we make innovative, fun products that enrich the lives of pets and their people, at a great value.Soon you will be able to download all the data taken from this company. |
||||||
| Ransomware | Neurology Center of Nevada id9888 View details | Healthcare / Pharma | — | — | ||
|
Neurology Center of Nevada™s medical team specializes in the diagnosis and treatment of the Nervous System and Neurological Disorders. Soon you will be able to download all the data taken from this company. |
||||||
| Ransomware | CMS Communications id9845 View details | Communication / Marketing | — | — | ||
|
CMS Solutions, founded in 1985, is a communications solutions provider. It offers new and refurbished voice, data, mobile products, advanced IP telephone systems and technical support. CMS Solutions serves a wide range of organizations from m ... |
||||||
| Ransomware | Great Lakes Technologies id9843 View details | IT | — | — | ||
|
Great Lakes Technologies & Manufacturing LLC promotes a culture of innovation and is committed to eliminating waste, costly duplication of efforts and production start-up problems for our customers. We accomplish this by providing proprietary ... |
||||||
| Ransomware | Yanfeng id9730 View details | Manufacturing / Engineering | — | — | ||
|
Yanfeng is a leading global automotive supplier, focusing on interior, exterior, seating, cockpit electronics, and passive safety, and is exploring new business actively. Yanfeng has more than 240 locations and approximately 57,000 employees ... |
||||||
| Ransomware | HAESUNG DS CO Ltd id9608 View details | Services | — | — | ||
|
We will publish data on next week |
||||||
| Ransomware | Epstein Law id9596 View details | Finance / Legal / Insurance | — | — | ||
|
Established in 1958, Epstein Law serves clients throughout the Greater Vancouver Area. Led by Mark Epstein, we have a reputation for providing quality and professional legal services Soon you will be able to download all the data taken fro ... |
||||||
| Ransomware | Assurius.be id9393 View details | Belgium | Other | — | — | |
|
Coming soon... |
||||||
| Ransomware | unique-relations.at id9392 View details | Austria | Other | — | — | |
|
We will publish data on next week |
||||||
| Ransomware | SG World id9232 View details | Other | — | — | ||
|
Company data will be made available for download below |
||||||
| Ransomware | Paul-Alexandre Doïcesco, Notaires Associés id9219 View details | Belgium | Other | — | ||
|
The company has chosen to ignore us means its data will be open and available for download below. |
||||||
| Ransomware | Cardiovascular Consultants Ltd id9218 View details | Services | — | |||
|
You can download all personal data of clients and employees of this company below |
||||||
| Ransomware | WT PARTNERSHIP id9009 View details | Services | — | — | ||
|
WT Partnership Asia provides project management, cost management & specialist consultancy advisory services for the property & construction industries. "Our risk and value focused approach supports our clients by delivering financially rob ... |
||||||
| Ransomware | DiTRONICS Financial Services id8965 View details | Services | — | — | ||
|
"DiTRONICS continues to define the future of funds access with a fully integrated suite of products and services that includes ATMs, Ticket Redemption Kiosks, Check Guarantee Software, Cash Advance Software, and now offers a Title 31 complian ... |
||||||
| Ransomware | Siamese Asset id8866 View details | Thailand | Public Sector | — | — | |
|
In the near future we will be publishing more data related to very interesting money laundering schemes. The state should be interested in what these guys are doing :) |
||||||
| Ransomware | CORTEL Technologies id8589 View details | IT | — | — | ||
|
Cortel is a cloud technology vendor that partners with businesses to deploy phone systems that connect customers to businesses. Below you can see a small part of the data which were taken from the servers of this company. |
||||||
| Ransomware | PAUL-ALEXANDRE DOICESCO id8543 View details | Belgium | Other | — | — | |
|
The company did not give a damn about the security of its customers' data, so you can download all this from the link below. archive password: passwordbe |
||||||
| Ransomware | WACOAL id8542 View details | Telecommunications | — | — | ||
|
Wacoal America is an apparel & fashion company specializing in lingerie and intimate wear. In the near future, we will publish a large leak from the network of this company. Including all customer data. |
||||||
| Ransomware | GYP New Tree SA id8313 View details | Argentina | Manufacturing / Engineering | — | ||
|
GYP NEW TREE SA is a wholesale importer operating in the market since 1998, marketing brands that are synonymous with excellence and innovation. We integrate the value chain of these brands, either with local assembly of PCs and AIOs, or with ... |
||||||
| Ransomware | Thonburi Energy Storage Systems (TESM) id8080 View details | Thailand | Energy | — | ||
|
The company has decided not to contact our team in any way so we are starting a large publication of various documents At the moment you can read the screenshots below |
||||||
| Ransomware | Better System Co.,Ltd id7245 View details | Thailand | Services | — | ||
|
Some of the data taken from the servers of this company can be found below |
||||||
| Ransomware | MicroPort Scientific / LivaNova id7221 View details | Agriculture / Food | — | |||
|
Our team has prepared a big announcement for the public to check out some interesting files of this company. In addition to developments ( 1冠脉产品研发部 ) We will publish terabytes of various data from European and Chinese servers ... |
||||||
| Ransomware | ASIC Soluciones id7135 View details | Communication / Marketing | — | — | ||
|
ASIC is an IT solutions company that provides data, analytics and artificial intelligence services. The data dump is provided below for your review. |
||||||
| Ransomware | Daiwa House Industry Co. id6993 View details | Japan | Retail / E-commerce | — | — | |
|
Daiwa House Industry Co., Ltd. is Japan's largest homebuilder, specializing in prefabricated houses. The company is also engaged in the construction of factories, shopping centers, health care facilities, the management and operation of resor ... |
||||||
| Ransomware | Printmarksolution id6931 View details | Communication / Marketing | — | — | ||
|
Distributor of production date, expiry date, barcode, lot number, quality products imported from Europe by a team of professionals with more than 15 years of experience in industrial printing. we are committed to providing quality service, at ... |
||||||
| Ransomware | ASZ GmbH & Co id6880 View details | Germany | Services | — | — | |
|
The object of the company is the acquisition and management of shareholdings in service companies on the basis of the Occupational Safety Act and the Occupational Safety Act, as well as the assumption of personal liability and management in t ... |
||||||
| Ransomware | iECM Company Limited id6856 View details | Thailand | Manufacturing / Engineering | — | — | |
|
iECM Company Limited is one of the leading firm of Engineering and Consultancy Services in Thailand. Our company is proud of its successful record of the achievements, which bring its stock of experience, know-how, capabilities to bear when f ... |
||||||
| Ransomware | Del Bono Hotel id6793 View details | Argentina | Hospitality / Food & Beverage / Tourism | — | — | |
|
Del Bono Hotels, the most important chain of hotels with function rooms for events, in San Juan Argentina. The data taken from the company's servers is shown below. |
||||||
| Ransomware | Clarity Water Technologies, LLC id6785 View details | United States | IT | — | ||
|
Clarity Water Technologies specializes in comprehensive industrial and commercial water treatment that includes expert consulting and cutting-edge chemistry, as well as a full service team to support facility needs . Some of the data take ... |
||||||
| Ransomware | AWM Global Advisors id6781 View details | Communication / Marketing | — | |||
|
AWM offers security backed loans and margin account lending at very competitive rates. You'll soon see for yourself how much these guys care about the privacy of their customers and employees. |
||||||
| Ransomware | Ascentia Group Pty Ltd id6727 View details | United States | Construction / Real Estate | — | — | |
|
Ascentia is a independent Civil Engineering Contracting company that services the Defence, Civil Infrastructure Construction and the Oil & Gas Industries. The data taken from the company's servers is shown below. |
||||||
| Ransomware | Conley & Wirick, P.A. id6724 View details | Finance / Legal / Insurance | — | |||
|
Conley & Wirick, P.A. has served the communities of Bath and Midcoast Maine for more than forty years, and today our attorneys are still committed to serving the people of our community and solving their problems. Lawyers always like to th ... |
||||||
| Ransomware | SMDEA id6509 View details | France | Public Sector | — | ||
|
The SMDEA, a public operator, is an intermunicipal cooperation tool specializing in the areas of water and sanitation; domestic cycle and large cycle. The company decided to ignore the gigabytes of data taken from their servers. That's wh ... |
||||||
| Ransomware | Oppida Estates Limited id6508 View details | Construction / Real Estate | — | |||
|
Oppida is a real estate agency that provides a wide range of modern spaces and apartment complexes for rent and sale. The data of ordinary and wealthy (very) customers you will be able to observe in the very near future. By the way person ... |
||||||
| Ransomware | Kannangara Thomson id6476 View details | New Zealand | Finance / Legal / Insurance | — | — | |
|
Christchurch Lawyers, Kannangara Thomson provides advice on the law and a full range of legal services including family law, employment law and conveyancing Some of this company's data will be uploaded shortly. All the personal data of th ... |
||||||
| Ransomware | Maier Sanitär-Technik GmbH id6475 View details | Germany | IT | — | — | |
|
Maier sanitary technology GmbH is mentioned in public sources in the context of the following products and services. Customer service, hall construction and heating technology are the most common. Some of this company's data will be uploa ... |
||||||
| Ransomware | HECTOR MARTINEZ SOSA Y CIA SA id6470 View details | Finance / Legal / Insurance | — | — | ||
|
HMSOSA is a group of companies in the insurance industry, responding to all the needs of individuals, companies and organizations, public and private. We have our own offices in CABA, Rio Grande, Ushuaia, Rio Gallegos, Vicente Lopez and Mar d ... |
||||||
| Ransomware | Dialog Information Technology id6349 View details | Australia | IT | — | ||
|
Dialog Information Technology is one of Australia's leading technology services organisations trading nationally from offices in Brisbane, Sydney, Canberra, Melbourne, Adelaide, Perth and Darwin. Established in 1979, Dialog employs over 1,200 ... |
||||||
| Ransomware | Robert Bernard id6348 View details | Retail / E-commerce | — | |||
|
Since its founding in 1950, Robert Bernard Pneus et Mécanique has become one of the largest tire retailers in Quebec. Thanks to our solid distribution network, we are able to serve our customers throughout Quebec. It's time to showcase what ... |
||||||
| Ransomware | Contempo Card id6347 View details | Manufacturing / Engineering | — | |||
|
Vark Sr worked with his father in the jewelry manufacturing business in Rhode Island. In the 80’s, Providence, RI was the jewelry capital of the world, and everyone wanted a piece of the jewelry pie. Vark Sr noticed something odd: while the ... |
||||||
| Ransomware | Lojas Torra id6346 View details | Brazil | Communication / Marketing | — | ||
|
Lojas Torra is a fashion retailer that provides fashion accessories and products. We have all the data of customers and employees and we are ready to share them with you... |
||||||
| Ransomware | Emtelco id6345 View details | Colombia | Services | — | ||
|
EMTELCO SA is a company that operates in the Outsourcing/Offshoring industry. It employs 101-250 people and has $25M-$50M of revenue. We also have several hundred gigabytes of data. Data of all large clients (corporate), non-disclosure docume ... |
||||||
| Ransomware | fsmsolicitors.co.uk id6344 View details | United Kingdom | Other | — | ||
|
DB Backups: FSM_backup Isokon2_backup Isokon2CGT_backup Partner_backup PartnerTCDatabase_backup TCDatabase_backup Dept_data - internal data including accounts, commercial information, ligitation etc. Isocon documents Client's data ... |
||||||
| Ransomware | eyeDOCS Ottawa id6341 View details | Other | — | |||
|
The company has decided not to care about its customers' data. Therefore, we are forced to publish their data. You can download the first part at the link below pass for archive: ys5YHSpkbp;sYT5&^%,FPERLHP |
||||||
| Ransomware | Gropper & Nejat, PLLC id6329 View details | Services | — | |||
|
Another company that decided it was a good idea to ignore our team. We will now post their customer data in pieces. Pass for archive: moR~?HHJ%IqTymMH7XHv$o7fi |
||||||
| Ransomware | SIIX Corporation id6295 View details | Japan | Services | — | ||
|
In 3 days we will publish all the data taken from their servers. |
||||||
| Ransomware | Sippex id6108 View details | Other | — | |||
|
Another company that does not care about the data of its employees and customers at all. Publishing another leak |
||||||
| Ransomware | Attent Zorg en Behandeling id5556 View details | Netherlands | Telecommunications | — | ||
|
Dear friends decided to deceive us and their customers, saying that everything works fine for them and there were no serious leaks in the network. https://www.attentzorgenbehandeling.nl/nieuws/update-ongeautoriseerde-toegang-it-systemen W ... |
||||||
| Ransomware | GIGATRON.RS id5495 View details | Serbia | Retail / E-commerce | — | ||
|
Gigatron downloaded data overview: From 172.31.244.50: DB backups of shops: G1-G69, G88, G89 From 172.31.248.10: DB backups: CTRetail_backup CTRetailWSRepl_backup GigatronWMS_Sync_backup From 192.168.2.144: employee disability ... |
||||||
| Ransomware | scinopharm.com id4305 View details | Other | — | — | ||
|
No additional victim description available. |
||||||