Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Benzona

| RaaS

Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Extension(s): .benzona

Victims
14
 
First Discovered
2025-11-26
victim
Last Discovered
2026-01-30
victim
Inactive Since
105
days
Avg Delay
N/A
attack→claim
Infostealer
21.4%
victims with domain
Countries
8
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Benzona Ransomware Yes 2026-05-15T02:47:55 NGINX nginx 1.29.4 benzona6x5ggng3hx52h4mak5sgx5vukrdlrrd3of54g2uppqog2joyd.onion
favicon Support Chat No 2026-05-15T02:47:14 rwsu75mtgj5oiz3alkfpnxnopcbiqed6wllyoffpuruuu6my6imjzuqd.onion

Target
Top 5 Activity Sectors
  • Healthcare 3
  • Manufacturing 2
  • Hospitality and Tourism 1
  • Technology 1
  • Consumer Services 1
Top 5 Countries
  • RO flag Romania 4
  • GT flag Guatemala 1
  • FR flag France 1
  • TZ flag Tanzania, United Republic of 1
  • IR flag Iran, Islamic Republic of 1

Heatmap

Ransom Notes (1)

YARA Rules (1)

Indicators of Compromise (IoCs) (4)
Hash MD5 1 Hash SHA256 1 IP Address 1 tox 1
Type IOC
Hash MD5 6e2189ab11f130ead644b1d5bd00f1ac
Hash SHA256 09f7432834ce15e701aa7fcc84a9c2441c1c7e0a9cb66a6211845be73d2597cc
IP Address 179.43.139.126
tox 7308E8CFE8AA18D718B5EF44C34A2E5E2C90B7FDB150FA2EC31E995F5F4B23044A98802A4DF0

Victims (14)
Logo
Discovered: 2026-01-30 (3mo ago)
[AI generated] "Casamedica.com.gt" is a Guatemala-based company that provides a range of medical equ…
Logo
Discovered: 2026-01-22 (3mo ago)
[AI generated] The Empreinte Hotel is a luxury establishment located in Orleans, France. This 4-star…
Logo
Discovered: 2026-01-22 (3mo ago)
No description available
Logo
Discovered: 2026-01-17 (3mo ago)
[AI generated] Comprehensive Community Based Rehabilitation in Tanzania (CCBRT) is a healthcare orga…
Logo
Discovered: 2026-01-17 (3mo ago)
No description available
Logo
Discovered: 2026-01-12 (4mo ago)
No description available
Logo
Discovered: 2025-12-22 (4mo ago)
[AI generated] N/A…
Logo
Discovered: 2025-12-06 (5mo ago)
[AI generated] PlatinumOne.in is a company based in India that provides outsourced sales force servi…
Logo
Discovered: 2025-12-03 (5mo ago)
[AI generated] "SUNNYGO.COM.TW" is an online retailer based in Taiwan. The company specializes in th…
Logo
Discovered: 2025-11-26 (5mo ago)
[AI generated] N/A…
Logo
Discovered: 2025-11-26 (5mo ago)
[AI generated] N/A…
Logo
Discovered: 2025-11-26 (5mo ago)
[AI generated] N/A…
Logo
Discovered: 2025-11-26 (5mo ago)
[AI generated] N/A…
Logo
Discovered: 2025-11-26 (5mo ago)
Santé, Espoir et Vie, dans un système de soin fort…