Ransomware Group:  
Fog



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | Ransom Note(s) | Activity | Worldmap | Victims (189)

Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.


Sites

Favicon Title Type Available Last Visit FQDN Screenshot
FOG 🟢 2025-03-25 20:01:30.835744 xql562evsy7njcsngacphc2erzjfecwotdkobn3m4uxu2gtqh26newid.onion 📸
Blog 🟢 2025-03-25 20:02:46.529738 xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion 📸
Blog 🟢 2025-03-25 20:03:47.827770 xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion 📸

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
Advanced Port Scanner Veeam-Get-Creds Metasploit PsExec
SharpShares
SoftPerfect NetScan

This information is provided by Ransomware-Tool-Matrix

Ransom Note(s)

Activity over time

Worldmap

189 Victims

US flag

Newtown Friends School (newtownfriends.org) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-20 14:02

Sector: Education
[AI generated] Newtown Friends School is a private, co-educational day school located in Newtown, Pennsylvania. It offers high-standard education to students from preschool to grade 8. The school, established by Quakers in 1948, upholds Quaker values and aims to cultivate students' intellectual, ethical, and spiritual growth. They have a curriculum regionally recognized for its rigor and creativity, serving around 250 students.

Victim:   |  Group: 
ES flag

RAE (Real Academia Española) (rae.es) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-17 14:54

Sector: Education
<1 GB

Victim:   |  Group: 
US flag

University Diagnostic Medical Imaging, PC (udmi.net) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-13 05:28

Sector: Healthcare
28.1 GB

Victim:   |  Group: 
 flag

El Camino Real Academy (elcaminorealacademy) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-13 01:00
Estimated Attack Date: 2025-03-12

Sector: Education
111 GB

Victim:   |  Group: 
 flag

Wilkinson Rogers (wilkinsonrogers.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-11 01:28
Estimated Attack Date: 2025-03-10

Sector: Not Found
57 GB

Victim:   |  Group: 
US flag

Magnolia Manor (magnoliamanor.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-10 23:55

Sector: Healthcare
54.6 GB

Victim:   |  Group: 
US flag

WJCC Public Schools (wjccschools.org) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 15:52
Estimated Attack Date: 2025-02-09

Sector: Education
27.7 GB

Victim:   |  Group: 
US flag

Oberlin Cable Co-op (oberlin.net) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 12:43

33 GB

Victim:   |  Group: 
DE flag

1X Internet 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:10
Estimated Attack Date: 2025-03-05

Sector: Technology
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
IT flag

Bizcode 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:09
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
US flag

Manning Publications Co. 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:07
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
 flag

Engikam 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:06
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
CH flag

FHNW 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:04
Estimated Attack Date: 2025-03-05

Sector: Education
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
MY flag

Aeonsparx 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:03
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
CZ flag

CIE 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 02:01
Estimated Attack Date: 2025-02-01

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
 flag

Flightsim studio 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:59
Estimated Attack Date: 2025-03-05

Sector: Technology
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
DE flag

Neopoly 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:58
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
DE flag

Kr3m 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:56
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
US flag

InfoReach 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:55
Estimated Attack Date: 2025-03-05

Sector: Technology
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
BE flag

Euranova 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:53
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
ES flag

Inelmatic 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:52
Estimated Attack Date: 2025-03-05

Sector: Technology
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
RU flag

Kotliva 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:50
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
TH flag

Inet 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:49
Estimated Attack Date: 2021-12-20

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
 flag

Blue Planet 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:47
Estimated Attack Date: 2025-03-05

Sector: Not Found
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
DE flag

Eumetsat 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:46
Estimated Attack Date: 2025-03-05

Sector: Technology
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
BE flag

Melexis 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:44
Estimated Attack Date: 2025-03-05

Sector: Technology
Extract from The 19 biggest gitlabs

Victim:   |  Group: 
US flag

USGS 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:42
Estimated Attack Date: 2023-07-12

Extract from The 19 biggest gitlabs

Victim:   |  Group: 
 flag

The 19 biggest gitlabs 

Company logo
Ransomware Group:

Discovery Date: 2025-03-05 23:55

Sector: Technology

Victim:   |  Group: 
US flag

SCOLARO FETTER GRIZANTI & McGOUGH, P.C. (scolaro.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-05 17:53

92.5 GB

Victim:   |  Group: 
BR flag

Pampili (pampili.com.br) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-04 16:30

36.3 GB

Victim:   |  Group: 
BR flag

Grupo Baston Aerossol (baston.com.br) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-04 15:02

88.3 GB

Victim:   |  Group: 
US flag

Central McGowan (centralmcgowan.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-03 12:57

23.5 GB

Victim:   |  Group: 
US flag

Klesk Metal Stamping Co (kleskmetalstamping.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-03 12:55

2.2 GB

Victim:   |  Group: 
 flag

Gitlabs: Synelixis Solutions, INGV, VMO Holdings 

Company logo
Ransomware Group:

Discovery Date: 2025-02-26 21:56

Sector: Technology
[AI generated] It seems there is a bit of confusion in the request as GitLab, Synelixis Solutions, INGV (National Institute of Geophysics and Volcanology), and VMO Holdings appear to be separate entities. GitLab is a web-based DevOps tool that provides a platform for software development and version control. Synelixis Solutions is an IT company specializing in hardware and software solutions. INGV deals with research in geophysics and volcanology. VMO Holdings is a private holding company.

Victim:   |  Group: 
EC flag

Bayteq 

Company logo
Ransomware Group:

Discovery Date: 2025-02-23 18:47

Sector: Technology
Extract from Gitlabs: Naphix, WDNA, Bayteq - Bayteq is a technology partner specializing in software development, staff augmentation, robotic process automation, UX/UI design, and innovation consulting, delivering personalized digital solutions to businesses.

Victim:   |  Group: 
ES flag

WDNA 

Company logo
Ransomware Group:

Discovery Date: 2025-02-23 18:47

Sector: Technology
Extract from Gitlabs: Naphix, WDNA, Bayteq - WDNA (Wireless Domestic Network Auditors) is a Spanish business group with an international presence, developing innovative technologies and specialized solutions in network monitoring and auditing, advanced meteorology, and IoT monitoring of critical infrastructures, integrated into their entro© platform.

Victim:   |  Group: 
AU flag

Naphix 

Company logo
Ransomware Group:

Discovery Date: 2025-02-23 18:46

Sector: Technology
Extract from Gitlabs: Naphix, WDNA, Bayteq - gitlab

Victim:   |  Group: 
 flag

Gitlabs: Naphix, WDNA, Bayteq 

Company logo
Ransomware Group:

Discovery Date: 2025-02-23 18:22

Sector:

Victim:   |  Group: 
DE flag

Hochschule 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 15:01
Estimated Attack Date: 2023-09-28

Sector: Education
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - Hochschule Trier is a German university of applied sciences offering a wide range of practice-oriented programs and conducting forward-looking research across its main campus and specialized campuses for design and environmental studies.

Victim:   |  Group: 
FR flag

VISEO 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 15:01

Sector: Technology
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - VISEO is a global technology company offering digital transformation services, including customer experience, modern ERP cloud systems, supply chain management, finance transformation, custom development, and data analytics & AI, to help businesses optimize processes and enhance customer interactions.

Victim:   |  Group: 
ID flag

Next TI 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 14:54

Sector: Technology
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier: Next TI is an Indonesian IT solutions company specializing in financial digital platforms for banking and multifinance industries, supported by South Korea's Hana Financial Group.

Victim:   |  Group: 
US flag

Haggin Oaks Golf (hagginoaks.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 11:52

29,2 GB

Victim:   |  Group: 
 flag

Gitlabs: Next TI, VISEO, Hochschule Trier 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 08:46

Sector:

Victim:   |  Group: 
US flag

Greencastle-Antrim Senior High School (gcasd.org) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:21

Sector: Education
7.6 GB

Victim:   |  Group: 
DE flag

Pamrya.de 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 11:05

Sector: Not Found
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de- Pamyra.de is a platform that allows users to compare prices and book shipping services with over 600 verified freight companies.

Victim:   |  Group: 
IN flag

QBurst 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 11:04

Sector: Technology
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de- QBurst is a full-service software development company offering services in cloud enablement, data and AI, digitalization, and more.

Victim:   |  Group: 
RO flag

Acqua development 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 11:04

Sector: Not Found
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de

Victim:   |  Group: 
 flag

Gitlabs: Acqua development, QBurst, Pamyra.de 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 08:37

Sector:
[AI generated] Gitlabs: Acqua development, QBurst, Pamyra.de refers to a combination of several tech companies. GitLab, a web-based DevOps lifecycle tool that provides a Git-repository manager, is pivotal. Acqua Development creates personalized software solutions, while QBurst provides development services across digital platforms. Pamyra.de, on the other hand, is a German online shipping price comparison portal, focusing on courier, express and parcel services.

Victim:   |  Group: 
FR flag

ADULLACT 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 21:12

Sector: Technology
Extract from Gitlabs: Omydoo, Ayomi, ADULLACT- ADULLACT is a French association that develops and promotes a repository of free software for local authorities and administrations.

Victim:   |  Group: 
FR flag

Ayomi 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 21:11

Sector: Not Found
Extract from Gitlabs: Omydoo, Ayomi, ADULLACT- Ayomi is a French platform that assists entrepreneurs in financing their businesses.

Victim:   |  Group: 
FR flag

Omydoo 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 21:11

Sector: Not Found
Extract from Gitlabs: Omydoo, Ayomi, ADULLACT - Omydoo is a French company specializing in implementing integrated management software solutions for SMEs using the open-source ERP Odoo.

Victim:   |  Group: 
 flag

Gitlabs: Omydoo, Ayomi, ADULLACT 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 21:03

Sector: Not Found

Victim:   |  Group: 
ES flag

Mozo Grau (mozo-grau.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 17:05

Sector: Healthcare
72.2

Victim:   |  Group: 
 flag

Squeezer-software 

Company logo
Ransomware Group:

Discovery Date: 2025-02-12 17:18

Sector: Technology
Extract from Gitlabs: INGV, Spacemanic, Squeezer-software

Victim:   |  Group: 
CZ flag

Spacemanic 

Company logo
Ransomware Group:

Discovery Date: 2025-02-12 17:18

Sector: Technology
Extract from Gitlabs: INGV, Spacemanic, Squeezer-softwareSpacemanic is a Czech start-up that provides innovative nanosatellite solutions and CubeSat components, offering services from design and development to launch and ground station support.

Victim:   |  Group: 
IT flag

INGV 

Company logo
Ransomware Group:

Discovery Date: 2025-02-12 17:18

Sector: Not Found
Extract from Gitlabs: INGV, Spacemanic, Squeezer-software - The Istituto Nazionale di Geofisica e Vulcanologia (INGV) is an Italian research institution specializing in geophysics and volcanology, focusing on monitoring and studying seismic and volcanic activities.

Victim:   |  Group: 
US flag

Gitlabs: INGV, Spacemanic, Squeezer-software 

Company logo
Ransomware Group:

Discovery Date: 2025-02-12 16:57

Sector: Technology
[AI generated] Gitlabs: INGV, Spacemanic, Squeezer-software is a conglomerate of three diverse specialty companies. INGV, the Italian National Institute for Geophysics and Volcanology, focuses on scientific research in earth sciences. Spacemanic is a Slovak company specializing in the production of small and nano-satellites. Squeezer offers a decentralized platform for multi-cloud and blockchain deployment, aiding developers in cloud apps production.

Victim:   |  Group: 
DE flag

Hess (hess-gmbh.de) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-12 13:18

6.5 GB

Victim:   |  Group: 
CL flag

Saint George's College (saintgeorge.cl) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-11 17:35

Sector: Education
5 GB

Victim:   |  Group: 
US flag

Aurora Public Schools (aurorak12.org) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-11 16:24
Estimated Attack Date: 2025-01-13

Sector: Education
171 GB

Victim:   |  Group: 
AU flag

The University of Notre Dame Australia (nd.edu.au) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-11 14:55

Sector: Education
62 GB

Victim:   |  Group: 
JP flag

iRidge Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-09 18:45

Sector: Technology
Extract from Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc.

Victim:   |  Group: 
IN flag

Maxvy Technologies Pvt 

Company logo
Ransomware Group:

Discovery Date: 2025-02-09 18:44

Sector: Technology
Extract from Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc.

Victim:   |  Group: 
RO flag

Universitatea Politehnica din Bucuresti 

Company logo
Ransomware Group:

Discovery Date: 2025-02-09 18:44

Sector: Education
Extract from Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc.

Victim:   |  Group: 
 flag

Gitlabs: Universitatea Politehnica din Bucuresti, Maxvy Technologies Pvt, iRidge Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-09 11:38

Sector:

Victim:   |  Group: 
DE flag

3SS 

Company logo
Ransomware Group:

Discovery Date: 2025-02-07 23:45

Sector: Technology
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS

Victim:   |  Group: 
NO flag

Fligno 

Company logo
Ransomware Group:

Discovery Date: 2025-02-07 23:45

Sector: Technology
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS

Victim:   |  Group: 
SE flag

Chalmers tekniska högskola 

Company logo
Ransomware Group:

Discovery Date: 2025-02-07 23:45

Sector: Education
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS

Victim:   |  Group: 
 flag

Gitlabs: Chalmers tekniska högskola, Fligno, 3SS 

Company logo
Ransomware Group:

Discovery Date: 2025-02-07 21:40

Sector: Not Found

Victim:   |  Group: 
IT flag

DIEM 

Company logo
Ransomware Group:

Discovery Date: 2025-02-06 07:59

Sector: Not Found
Extract from Gitlabs: eConceptions, Top Systems, DIEM

Victim:   |  Group: 
BR flag

Top Systems 

Company logo
Ransomware Group:

Discovery Date: 2025-02-06 07:59

Sector: Technology
Extract from Gitlabs: eConceptions, Top Systems, DIEM

Victim:   |  Group: 
PK flag

eConceptions 

Company logo
Ransomware Group:

Discovery Date: 2025-02-06 07:58

Sector: Not Found
Extract from Gitlabs: eConceptions, Top Systems, DIEM

Victim:   |  Group: 
 flag

Gitlabs: eConceptions, Top Systems, DIEM 

Company logo
Ransomware Group:

Discovery Date: 2025-02-06 07:54

Sector: Technology

Victim:   |  Group: 
AT flag

Kombinat 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:28
Estimated Attack Date: 2025-01-30

Sector: Not Found
Extract from Gitlabs: Prasaga, HE2B, Kombinat

Victim:   |  Group: 
BE flag

HE2B 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:28
Estimated Attack Date: 2025-01-30

Sector: Not Found
Extract from Gitlabs: Prasaga, HE2B, Kombinat

Victim:   |  Group: 
US flag

Prasaga 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:28
Estimated Attack Date: 2025-01-30

Sector: Technology
Extract from Gitlabs: Prasaga, HE2B, Kombinat

Victim:   |  Group: 
CH flag

Propulsion Academy AG 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:18
Estimated Attack Date: 2025-01-31

Sector: Education
Extract from Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG

Victim:   |  Group: 
FR flag

X-Pans 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:18
Estimated Attack Date: 2025-01-31

Sector: Not Found
Extract from Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG

Victim:   |  Group: 
TH flag

Professional Computer Co., Ltd. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:18
Estimated Attack Date: 2025-01-31

Sector: Technology
Extract from Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG

Victim:   |  Group: 
ID flag

LUA Coffee 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:13
Estimated Attack Date: 2025-02-01

Extract from Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA Coffee

Victim:   |  Group: 
DE flag

GFZ Helmholtz Centre for Geosciences 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:12
Estimated Attack Date: 2025-02-01

Extract from Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA Coffee

Victim:   |  Group: 
ID flag

PT. ITPRENEUR INDONESIA TECHNOLOGY 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:12
Estimated Attack Date: 2025-02-01

Sector: Technology
Extract from Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA Coffee

Victim:   |  Group: 
IL flag

Devlion 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:10

Sector: Not Found
Extract from Gitlabs: hemio.de, SOLEIL, Devlion

Victim:   |  Group: 
FR flag

SOLEIL 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:09

Sector: Not Found
Extract from Gitlabs: hemio.de, SOLEIL, Devlion

Victim:   |  Group: 
DE flag

hemio.de 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:07

Sector: Technology
Extract from Gitlabs: hemio.de, SOLEIL, Devlion

Victim:   |  Group: 
NL flag

Madia 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:05
Estimated Attack Date: 2025-02-03

Extract from Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia

Victim:   |  Group: 
EG flag

X-lab group 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:04
Estimated Attack Date: 2025-02-03

Sector: Not Found
Extract from Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia

Victim:   |  Group: 
SE flag

Bolin Centre for Climate Research 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 21:02
Estimated Attack Date: 2025-02-03

Sector: Education
Extract from Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia

Victim:   |  Group: 
DE flag

Gitlabs: hemio.de, SOLEIL, Devlion 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 20:19

Sector: Technology

Victim:   |  Group: 
 flag

Gitlabs: Bolin Centre for Climate Research, X-lab group, Madia 

Company logo
Ransomware Group:

Discovery Date: 2025-02-03 19:07

Sector: Technology

Victim:   |  Group: 
TR flag

Karadeniz Holding (karadenizholding.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-03 16:27

Sector: Energy
1.5 TB

Victim:   |  Group: 
ID flag

Gitlabs: PT. ITPRENEUR INDONESIA TECHNOLOGY, GFZ Helmholtz Centre for Geosciences, LUA Cof... 

Company logo
Ransomware Group:

Discovery Date: 2025-02-01 22:15

Sector: Technology

Victim:   |  Group: 
CH flag

Gitlabs: Professional Computer, X-Pans, Propulsion Academy AG 

Company logo
Ransomware Group:

Discovery Date: 2025-01-30 20:59

Victim:   |  Group: 
US flag

Gitlabs: Prasaga, HE2B, Kombinat 

Company logo
Ransomware Group:

Discovery Date: 2025-01-29 23:28

Sector: Technology

Victim:   |  Group: 
US flag

Boutin Jones (boutindentino.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-29 11:59

180 GB

Victim:   |  Group: 
US flag

De La Salle High School (dlshs.org) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-24 12:34

Sector: Education
20 GB

Victim:   |  Group: 
IT flag

ELTEK Group (eltekgroup.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-24 12:01

13 GB

Victim:   |  Group: 
NL flag

Kooijman Vianen (kooijmanvianen.nl) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-23 17:38

25.7 GB

Victim:   |  Group: 
US flag

The University of Oklahoma (ou.edu) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-14 12:31
Estimated Attack Date: 2025-01-08

Sector: Education
91 MB

Victim:   |  Group: 
US flag

SciTech Services, Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-01-14 12:30

Sector: Technology
15 GB

Victim:   |  Group: 
US flag

Buttery (butterycompany.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-14 12:29

Sector: Retail
1.7 GB

Victim:   |  Group: 
US flag

OmniRide (omniride.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-10 12:20

7.2 GB

Victim:   |  Group: 
BE flag

Saint-Bar (saintbar.be) 

Company logo
Ransomware Group:

Discovery Date: 2025-01-07 20:17

Sector: Not Found
16.8 GB

Victim:   |  Group: 
US flag

Ober Mountain (OberGatlinburg.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-26 20:18

14.3 GB

Victim:   |  Group: 
US flag

Aroma Housewares Co (Aromaco.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-25 17:19

35 GB

Victim:   |  Group: 
AU flag

RODS Surveying (rods.cc) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-23 16:09

43.5 GB

Victim:   |  Group: 
US flag

Forum Architecture & Interior Design (forumarchitecture.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-23 13:19

5.7 GB

Victim:   |  Group: 
US flag

Gallade Chemical (galladechem.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-23 13:18

2.4 GB

Victim:   |  Group: 
BR flag

Industria e Comercio Jolitex Ltda (jolitex.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-23 13:17

23 GB

Victim:   |  Group: 
DE flag

Schenkelberg - Die Medienstrategen (schenkelberg-druck.de) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 15:18

6.8 GB

Victim:   |  Group: 
US flag

Village Community School (vcsnyc.org) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 15:17

Sector: Education
1 GB

Victim:   |  Group: 
US flag

Circle Electric (circleelectric.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 15:16

25.9 GB

Victim:   |  Group: 
US flag

Howell Township Public Schools (howell.k12.nj.us) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 13:20

Sector: Education
14.2 GB

Victim:   |  Group: 
US flag

EP Holdings (epholdingsinc.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 13:19

Sector: Energy
2.7 GB

Victim:   |  Group: 
US flag

Jet Edge (jetedgewaterjets.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 04:22
Estimated Attack Date: 2024-12-19

5 GB

Victim:   |  Group: 
US flag

Energy Capital Credit Union (eccu.net) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 04:21
Estimated Attack Date: 2024-12-19

Sector: Financial

Victim:   |  Group: 
BE flag

Vroninks Ricker Weyts & Sacre- Notaires (notassoc.be) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-18 16:54

15 GB

Victim:   |  Group: 
US flag

Reliance Connects (relianceconnects.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-18 16:53

19 GB

Victim:   |  Group: 
CA flag

SpeedLine Solutions (speedlinesolutions.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-17 14:22

Sector: Technology
6 GB

Victim:   |  Group: 
BR flag

Ouro Verde (ouroverde.net.br) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-17 12:34

4 GB

Victim:   |  Group: 
GR flag

Cognity (cognity.gr) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-16 18:55

Sector: Technology
36 GB

Victim:   |  Group: 
AU flag

Waverley Christian College (wcc.vic.edu.au) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-16 18:54

Sector: Education
5 GB

Victim:   |  Group: 
US flag

Planters Telephone Cooperative (planters.net) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-11 16:44

about 1 GB

Victim:   |  Group: 
DE flag

Dorner (dorner-gmbh.de) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-05 15:09

1 GB

Victim:   |  Group: 
IE flag

Conlin's Pharmacy (conlinspharmacy.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-02 14:10

Sector: Healthcare
10 GB

Victim:   |  Group: 
US flag

Weld Racing (weldracing.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-29 13:03

10,1 GB

Victim:   |  Group: 
CM flag

Chanas Assurances S.A. (chanasassurances.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 15:36

Sector: Financial
6 GB

Victim:   |  Group: 
FR flag

ALLTUB Group (alltub.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 14:07

20 GB

Victim:   |  Group: 
US flag

Bedminster School (bedminsterschool.org) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 12:51

Sector: Education

Victim:   |  Group: 
AU flag

WPM Pathology Laboratory (wpmpath.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 11:02

Sector: Healthcare
3 GB

Victim:   |  Group: 
US flag

Gruber Tool & Die (grubertool.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-27 16:55

8,2 GB

Victim:   |  Group: 
US flag

Signal Health Washington (signalhealthwa.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-27 14:07

Sector: Healthcare
1 GB

Victim:   |  Group: 
IN flag

Pioneer Urban Land & Infrastructure (pioneerurban.in) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 16:39

10 GB

Victim:   |  Group: 
US flag

Pinnacle Plastic Products (pinnacleplasitcporducts.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 16:38

5,3 GB

Victim:   |  Group: 
US flag

Complete Recycling Services (completerecyclingservices.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 16:37

1,4 GB

Victim:   |  Group: 
IE flag

Marketing Incentives (leinsterappointments.ie) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 14:42

about 1 GB

Victim:   |  Group: 
US flag

Metroline (metrolinedirect.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 13:08

1,3 GB

Victim:   |  Group: 
US flag

Hogan Mfg (hoganmfg.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-21 14:38

10,5 GB

Victim:   |  Group: 
US flag

Fifteenfortyseven Critical Systems Realty (1547realty.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-21 14:37

Sector: Technology
6 GB

Victim:   |  Group: 
US flag

Burkburnett Independent School District 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 18:09

Sector: Education
1 GB

Victim:   |  Group: 
US flag

Valley Planing Mill (valleyplaning.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 18:08

5,6 GB

Victim:   |  Group: 
US flag

Waters Truck and Tractor (waterstruck.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-18 15:44

3 GB

Victim:   |  Group: 
IN flag

Vector Transport (vectortransport.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-15 19:06

19 GB

Victim:   |  Group: 
US flag

Cape Cod Regional Technical High School (capetech.us) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-06 15:17

Sector: Education
6 GB

Victim:   |  Group: 
BR flag

GSR Andrade Architects (gsr-andrade.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-11-06 15:16

65 GB

Victim:   |  Group: 
SE flag

Askling Car (asklingbil.se) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-31 15:21

2,6 GB

Victim:   |  Group: 
US flag

Jillamy (jillamy.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-30 15:55

28 GB

Victim:   |  Group: 
US flag

SmartSource (smartsource-inc.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-30 14:00

Sector: Technology
81 GB

Victim:   |  Group: 
US flag

Jordan Public Schools (https://www.jordan.k12.mn.us/) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-29 13:43

Sector: Education
11 GB

Victim:   |  Group: 
US flag

Sage Automotive Interior (sageautomotiveinteriors.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-29 12:23

76 GB

Victim:   |  Group: 
CA flag

Evergreen SD50 (evergreensd50.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-28 13:17
Estimated Attack Date: 2024-10-25

Sector: Education
5,1 GB

Victim:   |  Group: 
US flag

Cucamonga Valley Water District (cvwdwater.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-25 13:11
Estimated Attack Date: 2024-08-15

Sector: Government
41 GB

Victim:   |  Group: 
US flag

Evergreen Local School District (evgvikings.org) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-25 13:10

Sector: Government
5,1 GB

Victim:   |  Group: 
US flag

Value City NJ (valuecitynj.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 15:35

25 GB

Victim:   |  Group: 
HK flag

The Getz Group (getz.com.hk) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 15:34

45 GB

Victim:   |  Group: 
US flag

Apache Mills, Inc. (apachemills.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 14:05

27 GB

Victim:   |  Group: 
US flag

Goshen Central School District (gcsny.org) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-23 14:30
Estimated Attack Date: 2024-07-10

Sector: Government
10 GB

Victim:   |  Group: 
US flag

Mar-Bal (mar-bal.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-23 13:09

37 GB

Victim:   |  Group: 
US flag

Lincoln University (lincolnu.edu) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-22 16:05

Sector: Government
10 GB

Victim:   |  Group: 
US flag

Clear Connection (clearconnection.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-22 14:38

71 GB

Victim:   |  Group: 
DE flag

Schweiger Transport (schweiger-gmbh.de) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 16:33

118 GB

Victim:   |  Group: 
US flag

Philadelphia Macaroni (philamacaroni.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 15:06

102 GB

Victim:   |  Group: 
US flag

Trimarc Financial (trimarc.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 12:08

Sector: Financial
3 GB

Victim:   |  Group: 
US flag

Fromm (FrommBeauty.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-18 17:02

16 GB

Victim:   |  Group: 
AU flag

Ultra Tune (ultratune.com.au) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-18 15:07

3 GB

Victim:   |  Group: 
US flag

Welker (welker.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-16 18:03

27,6 GB

Victim:   |  Group: 
US flag

Cordogan Clark and Associates (cordoganclark.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-16 18:02

107 GB

Victim:   |  Group: 
US flag

Food Sciences Corporation (foodsciences.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-16 13:36

86 GB

Victim:   |  Group: 
US flag

Central Pennsylvania Food Bank 

Company logo
Ransomware Group:

Discovery Date: 2024-10-15 16:33

20 GB

Victim:   |  Group: 
US flag

Juice Generation 

Company logo
Ransomware Group:

Discovery Date: 2024-09-20 16:32

10 GB

Victim:   |  Group: 
CA flag

Sunrise Farms 

Company logo
Ransomware Group:

Discovery Date: 2024-09-19 17:58

30 GB

Victim:   |  Group: 
US flag

Prentke Romich Company 

Company logo
Ransomware Group:

Discovery Date: 2024-09-18 16:03

Sector: Healthcare
250 GB

Victim:   |  Group: 
US flag

S. Walter Packaging 

Company logo
Ransomware Group:

Discovery Date: 2024-09-11 13:07

Victim:   |  Group: 
DE flag

Clatronic International GmbH 

Company logo
Ransomware Group:

Discovery Date: 2024-09-11 13:05

469 GB

Victim:   |  Group: 
US flag

Seaway Manufacturing Corp. 

Company logo
Ransomware Group:

Discovery Date: 2024-08-15 21:27

Victim:   |  Group: 
 flag

IOI Corporation Berhad 

Company logo
Ransomware Group:

Discovery Date: 2024-08-06 16:23

20 GB

Victim:   |  Group: 
 flag

Ziba Design 

Company logo
Ransomware Group:

Discovery Date: 2024-08-06 16:22

22 GB

Victim:   |  Group: 
 flag

Hi-P International 

Company logo
Ransomware Group:

Discovery Date: 2024-08-05 17:36

22 GB

Victim:   |  Group: 
NL flag

BASF - Nunhems 

Company logo
Ransomware Group:

Discovery Date: 2024-07-29 19:34

30 GB

Victim:   |  Group: 
CA flag

City of Cold Lake 

Company logo
Ransomware Group:

Discovery Date: 2024-07-26 16:07
Estimated Attack Date: 2024-07-23

Sector: Government
10 GB

Victim:   |  Group: 
US flag

Odessa College 

Company logo
Ransomware Group:

Discovery Date: 2024-07-25 17:41

Sector: Government
18 GB

Victim:   |  Group: 
 flag

Wichita State University Campus of Applied Sciences and Technology 

Company logo
Ransomware Group:

Discovery Date: 2024-07-22 16:36

Sector: Education
10 GB

Victim:   |  Group: 
 flag

Geelong Lutheran College 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 22:05
Estimated Attack Date: 2024-06-19

Sector: Government
4GB

Victim:   |  Group: 
 flag

Asbury Theological Seminary 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 22:04
Estimated Attack Date: 2024-06-24

Sector: Not Found
10 GB

Victim:   |  Group: 
 flag

Djg Projects 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 22:04
Estimated Attack Date: 2024-07-07

19.4GB

Victim:   |  Group: 
 flag

Verweij Elektrotechniek 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 22:03
Estimated Attack Date: 2024-07-04

95GB

Victim:   |  Group: 
US flag

Alvin Independent School District 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 21:43
Estimated Attack Date: 2024-07-04

Sector: Government
60GB

Victim:   |  Group: 
US flag

West Allis-West Milwaukee School District 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 21:42
Estimated Attack Date: 2024-07-11

Sector: Government
9,5 GB

Victim:   |  Group: 
OM flag

German University of Technology in Oman 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 21:42

Sector: Education
10 GB

Victim:   |  Group: