Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Cheers

Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks against VMware ESXi servers, running a double-extortion leak site with four documented victims.

Victims
15
 
First Discovered
2022-05-29
victim
Last Discovered
2022-09-14
victim
Inactive Since
3yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
N/A
victims with domain
Countries
0
hit
View Victims on World Map View Group Statistics

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Cheers! No 2026-04-28T07:22:57 rwiajgajdr4kzlnrj5zwebbukpcbrjhupjmk6gufxv6tg7myx34iocad.onion
favicon sembmarine No 2026-04-28T07:25:32 crkfkmrh4qzbddfrl2axnkvjp5tgwx73d7lq4oycsfxc7pfgbfhtfiid.onion

Target
Top 5 Activity Sectors
  • Financial Services 6
  • Transportation/Logistics 4
  • Hospitality and Tourism 2
  • Technology 1
  • Healthcare 1
Top 5 Countries

Heatmap

YARA Rules (1)

Victims (15)
Logo
Discovered: 2022-09-14 (3y ago)
No description available
Logo
Discovered: 2022-09-01 (3y ago)
No description available
Logo
Discovered: 2022-08-18 (3y ago)
No description available
Logo
Discovered: 2022-08-09 (3y ago)
No description available
Logo
Discovered: 2022-08-09 (3y ago)
No description available
Logo
Discovered: 2022-07-19 (3y ago)
No description available
Logo
Discovered: 2022-07-18 (3y ago)
No description available
Logo
Discovered: 2022-07-18 (3y ago)
No description available
Logo
Discovered: 2022-07-01 (3y ago)
No description available
Logo
Discovered: 2022-06-30 (3y ago)
No description available
Logo
Discovered: 2022-06-28 (3y ago)
No description available
Logo
Discovered: 2022-05-29 (3y ago)
No description available
Logo
Discovered: 2022-05-29 (3y ago)
No description available
Logo
Discovered: 2022-05-29 (3y ago)
No description available
Logo
Discovered: 2022-05-29 (3y ago)
No description available