Ransomware Group:  
Monti



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | Yara Rules | Ransom Note(s) | Activity | Worldmap | Victims (92)


Sites

Title Available Last Visit FQDN Screenshot
404 Not Found 🔴 2022-10-10 17:13:45.969929 4s4lnfeujzo67fy2jebz2dxskez2gsqj2jeb35m75ktufxensdicqxad.onion N/A
MONTI - Leaks site 🟢 2024-11-21 06:14:36.112231 mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion 📸

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
SoftPerfect NetScan Action1 Avast Anti-Rootkit driver Mimikatz MEGA
AnyDesk GMER Veeam-Get-Creds PSCP
WinSCP

This information is provided by Ransomware-Tool-Matrix

Yara Rules

Ransom Note(s)

Activity over time

Worldmap

92 Victims

US flag

Oxford Auto Insurance 

Company logo
Ransomware Group:

Discovery Date: 2024-11-20 02:32

Insurance

Victim:   |  Group: 
GB flag

Anderson Miller LTD 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 14:31

Sector: Not Found
Hospitality

Victim:   |  Group: 
US flag

Premier Tax Services 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 14:30

Accounting Services

Victim:   |  Group: 
FO flag

KVF 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 14:29

Sector: Not Found
Industrial Machinery & Equipment

Victim:   |  Group: 
US flag

Southern Oregon Veterinary Specialty Center 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 14:28

Sector: Healthcare
Healthcare Services

Victim:   |  Group: 
TR flag

Superline 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 21:11
Estimated Attack Date: 2023-10-19

Sector: Not Found
Our utmost priorities are to bring the latest trends to our customers while providing each and every one with the quality care and service that they deserve.

Victim:   |  Group: 
US flag

City Of Forest Park 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 21:10
Estimated Attack Date: 2024-10-04

Georgia, United States

Victim:   |  Group: 
CA flag

Burgess Kilpatrick 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 21:09

Accounting Services

Victim:   |  Group: 
US flag

Welding and Fabrication (Humble Mfg) 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 21:08

Building Materials

Victim:   |  Group: 
CA flag

Raeyco Lab Equipment 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 21:07

Sector: Healthcare
Office Products Retail & Distribution

Victim:   |  Group: 
IT flag

La Tazza D'oro 

Company logo
Ransomware Group:

Discovery Date: 2024-10-21 19:46

Hospitality · Italy

Victim:   |  Group: 
US flag

City Of Forest Park - Full Leak 

Company logo
Ransomware Group:

Discovery Date: 2024-10-04 18:04

Georgia, United States

Victim:   |  Group: 
CA flag

bluemaven.ca problems 

Company logo
Ransomware Group:

Discovery Date: 2024-09-03 11:06
Estimated Attack Date: 2024-08-26

Sector: Technology
additional information

Victim:   |  Group: 
DE flag

Phyton Biotech 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 22:37

Sector: Healthcare
Business Services

Victim:   |  Group: 
CA flag

Burgess Kilpartick 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:17

Sector: Construction
Burgess Kilpatrick is an accounting and professional services firm located in Vancouver, BC.

Victim:   |  Group: 
CA flag

Richmond Auto Mall 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:16

Automobile Dealers

Victim:   |  Group: 
CA flag

Seng Tsoi Architect 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:14

Sector: Construction
Architecture, Engineering & Design

Victim:   |  Group: 
CA flag

Raeyco Lab Equipment Systems Management 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:13

Sector: Healthcare
Office Products Retail & Distribution

Victim:   |  Group: 
US flag

Welding and Fabrication (humblemfg) 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:12

Building Materials

Victim:   |  Group: 
 flag

City Projects 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:11

Sector: Construction
Commercial & Residential Construction

Victim:   |  Group: 
CA flag

Prism Construction 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:10

Sector: Construction
Commercial & Residential Construction

Victim:   |  Group: 
CA flag

Cotala Cross-Media 

Company logo
Ransomware Group:

Discovery Date: 2024-08-30 20:09

Business Services

Victim:   |  Group: 
US flag

Abatti Companies 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 16:21
Estimated Attack Date: 2023-08-04

Abatti Companies is a vertically integrated group of companies that handles all facets of farm products from field to market. In 1981 Alex Abatti Jr. started as a custom harvest operator that later began farming to become one of the largest farmers in the Imperial Valley, California.

Victim:   |  Group: 
 flag

Imt 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 16:20
Estimated Attack Date: 2023-11-27

Victim:   |  Group: 
US flag

Law Offices of John E Hill 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 16:19
Estimated Attack Date: 2023-11-28

We are dedicated to providing you with the personal service and attention you expect. Our goal is to help you understand your rights and assess your options, so that you can obtain the maximum recovery possible.

Victim:   |  Group: 
CA flag

Tryax Realty Management 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 16:18
Estimated Attack Date: 2023-12-07

Tryax Realty Management serves the West Bronx communities of Morris Heights, Mt. Eden, Melrose, High Bridge, Kingsbridge and Norwood, and the Harlem communities of Hamilton Heights, Sugar Hill, and Strivers Row.

Victim:   |  Group: 
DE flag

HMW 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 16:17
Estimated Attack Date: 2023-12-09

Sector: Not Found
#Robert_stop_fap_on_kids HMW Special Utility District is a Texas water district and special utility district under Chapters 49 and 65, Texas Water Code. Its purpose is to provide water utility services as permitted by applicable law.

Victim:   |  Group: 
ZA flag

Smith Capital 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 16:16
Estimated Attack Date: 2024-02-01

Sector: Not Found
Smith Affiliated Capital (SAC) was formed in 1982 to provide both discretionary and advisory investment management services to high-net worth individuals, their families, and institutional investors.

Victim:   |  Group: 
US flag

Blue Maven Group 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 11:18

Sector: Not Found
Blue Maven provides extensive IT Procurement services.

Victim:   |  Group: 
CA flag

Adorna & Guzman Dentistry 

Company logo
Ransomware Group:

Discovery Date: 2024-08-01 21:20

Sector: Healthcare
Dental

Victim:   |  Group: 
US flag

forestparkga.gov 

Company logo
Ransomware Group:

Discovery Date: 2024-07-24 11:15

City & PD

Victim:   |  Group: 
BG flag

Regas (regasenergy.com) 

Company logo
Ransomware Group:

Discovery Date: 2024-07-24 11:14

Sector: Energy
Electricity, Oil & Gas

Victim:   |  Group: 
 flag

Excelsior Orthopaedics 

Company logo
Ransomware Group:

Discovery Date: 2024-07-09 15:02
Estimated Attack Date: 2024-07-08

Sector: Healthcare
Hospitals & Physicians Clinics

Victim:   |  Group: 
 flag

Wayne Memorial Hospital 

Company logo
Ransomware Group:

Discovery Date: 2024-06-30 19:41

Sector: Healthcare
Wayne Memorial Hospital is a non-profit, community-controlled hospital based in Honesdale, Pennsylvania serving Wayne, Pike and Sullivan Counties.

Victim:   |  Group: 
 flag

Compagnia Trasporti Integrati S.R.L 

Company logo
Ransomware Group:

Discovery Date: 2024-06-24 15:33

Italian Logistics. ctilog.it

Victim:   |  Group: 
CA flag

VTWin.ca 

Company logo
Ransomware Group:

Discovery Date: 2024-06-24 15:32

Sector: Not Found
shitty

Victim:   |  Group: 
FR flag

CNPC Sport 

Company logo
Ransomware Group:

Discovery Date: 2024-05-26 14:16

Sector: Energy
Colleges & Universities

Victim:   |  Group: 
FR flag

Esc Pau Etudes-Conseils 

Company logo
Ransomware Group:

Discovery Date: 2024-05-26 14:16

Colleges & Universities

Victim:   |  Group: 
FR flag

Aéroport de Pau 

Company logo
Ransomware Group:

Discovery Date: 2024-05-26 14:15

Full leak

Victim:   |  Group: 
 flag

project sold 

Company logo
Ransomware Group:

Discovery Date: 2024-05-15 20:53

Sector: Technology
project sold

Victim:   |  Group: 
AT flag

Kuhn Rechtsanwlte GmbH 

Company logo
Ransomware Group:

Discovery Date: 2024-05-10 10:22

Law Firms & Legal Services

Victim:   |  Group: 
US flag

Spine West 

Company logo
Ransomware Group:

Discovery Date: 2024-02-24 14:43

Sector: Healthcare
Hospitals & Physicians Clinics · Colorado, United States

Victim:   |  Group: 
DE flag

APEX - apexspedition.de 

Company logo
Ransomware Group:

Discovery Date: 2024-02-23 14:51

Spedition Hamburg Apex - europaweit und international, Spedition Apex aus Hamburg transportiert europaweit und nach bersee Warengüter aller Art

Victim:   |  Group: 
FR flag

Smith Capital - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2024-01-23 08:44
Estimated Attack Date: 2024-01-21

Sector: Not Found
Smith Affiliated Capital (SAC) was formed in 1982 to provide both discretionary and advisory investment management services to high-net worth individuals, their families, and institutional investors.

Victim:   |  Group: 
US flag

Diablo Valley Oncology and Hematology Medical Group - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2024-01-04 13:14

Sector: Healthcare
Diablo Valley Oncology provides comprehensive cancer care to patients by bringing together medical oncology, chemotherapy, radiation therapy, PET/CT and diagnostic imaging, research, and supportive care all in one convenient location.

Victim:   |  Group: 
 flag

HMW - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-12-08 23:50

Sector:
#Robert_stop_fap_on_kid HMW Special Utility District is a Texas water district and special utility district under Chapters 49 and 65, Texas Water Code. Its purpose is to provide water utility services as permitted by applicable law.

Group: 
 flag

Tryax Realty Management - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-12-06 22:08

Sector:
Tryax Realty Management serves the West Bronx communities of Morris Heights, Mt. Eden, Melrose, High Bridge, Kingsbridge and Norwood, and the Harlem communities of Hamilton Heights, Sugar Hill, and Strivers Row.

Victim:   |  Group: 
 flag

Rudolf-Venture Chemical Inc - Part 1 

Company logo
Ransomware Group:

Discovery Date: 2023-12-05 16:10

Sector:
RUDOLF GROUP implements the manufacturing of chemical auxiliaries

Victim:   |  Group: 
 flag

Hello Cristina from Law Offices of John E Hill 

Company logo
Ransomware Group:

Discovery Date: 2023-12-01 19:00

Sector:
SSN

Victim:   |  Group: 
 flag

Hello Jacobs from RVC 

Company logo
Ransomware Group:

Discovery Date: 2023-12-01 17:31

Sector:
Passport

Victim:   |  Group: 
 flag

Rudolf GmbH & Rudolf Venture Chemicals Inc - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-11-30 22:08

Sector:
RUDOLF GROUP implements the manufacturing of chemical auxiliaries

Victim:   |  Group: 
 flag

Imt - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-11-27 20:52

Sector:
Time is critical and prompt reporting of results is our objective. Most negative reports are released in less than 2 hours. We report results 7 days per week 365 days per year.

Victim:   |  Group: 
 flag

Law Offices of John E Hill - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-11-27 20:52

Sector:
We are dedicated to providing you with the personal service and attention you expect. Our goal is to help you understand your rights and assess your options, so that you can obtain the maximum recovery possible.

Victim:   |  Group: 
 flag

Rudolf Venture Chemical Inc - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-11-09 17:38

Sector:
We are RUDOLF, a global innovation leader for the textile, construction, coatings and car care industries. We support our customers with personal service and outstanding know-how. Our products maximize performance while minimizing environmental impact.

Victim:   |  Group: 
 flag

Magsaysay Maritime - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-11-09 17:38

Sector:
Magsaysay People Resources is one of the world's leading human resource companies. Through its subsidiaries Magsaysay Global Services for land-based placement and Magsaysay Maritime Corporation for sea-based placement

Victim:   |  Group: 
 flag

University of Defence - Full Leak 

Company logo
Ransomware Group:

Discovery Date: 2023-10-23 17:48

Sector:
The city of Brno was chosen as the location for the new engineering-oriented military college due to its long tradition of superior quality engineering education.

Victim:   |  Group: 
 flag

Superline - Full Leak 

Company logo
Ransomware Group:

Discovery Date: 2023-10-19 23:31

Sector:
Our utmost priorities are to bring the latest trends to our customers while providing each and every one with the quality care and service that they deserve.

Victim:   |  Group: 
 flag

Superline - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-10-09 14:57

Sector:
Our utmost priorities are to bring the latest trends to our customers while providing each and every one with the quality care and service that they deserve.

Victim:   |  Group: 
 flag

University Obrany - Part 2 (Tiny Leak) 

Company logo
Ransomware Group:

Discovery Date: 2023-10-07 14:32

Sector:
story about scam negotiator and stupid top level of unob

Victim:   |  Group: 
 flag

For UNOB 

Company logo
Ransomware Group:

Discovery Date: 2023-10-06 13:12

Sector:
story about scams

Victim:   |  Group: 
 flag

University of Defence - Part 1 

Company logo
Ransomware Group:

Discovery Date: 2023-10-03 19:17

Sector:
The city of Brno was chosen as the location for the new engineering-oriented military college due to its long tradition of superior quality engineering education.

Victim:   |  Group: 
 flag

Cascade Family Dental - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-10-01 19:13

Sector:
Cascade Family Dental offers dental services for families in the Payson and Springville, Utah area.

Victim:   |  Group: 
 flag

Rainbow Travel Service - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-10-01 19:13

Sector:
Rainbow Travel is a full service agency specializing in upscale leisure, special interest travel, and cruises.

Victim:   |  Group: 
 flag

Auckland University of Technology 

Company logo
Ransomware Group:

Discovery Date: 2023-09-21 22:18

Sector:
Founded in 1895, Auckland University of Technology is an educational facility that offers certificates, undergraduates, and postgraduate diplomas in a variety of fields.

Victim:   |  Group: 
 flag

University Obrany - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-09-19 23:47

Sector:
The city of Brno was chosen as the location for the new engineering-oriented military college due to its long tradition of superior quality engineering education.

Victim:   |  Group: 
 flag

Ja Quith Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-09-14 17:36

Sector:
Jaquith Industries three main specialties - Airport Lighting - BMF Metal Forms - Custom Contract Fabrication are manufactured here in the USA.

Victim:   |  Group: 
 flag

East Baking Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-09-14 17:36

Sector:
East Baking Company Inc. has the ability to manufacture any private label bakery program from bagels, breads, rolls, pancakes, and sweet goods to a very specific customized bakery products.

Victim:   |  Group: 
 flag

Abatti Companies - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-08-04 07:07

Sector:
Abatti Companies is a vertically integrated group of companies that handles all facets of farm products from field to market. In 1981 Alex Abatti Jr. started as a custom harvest operator that later began farming to become one of the largest farmers in the Imperial Valley, California.

Victim:   |  Group: 
US flag

Bickel & Brewer - Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-08-02 13:06

Sector:
Founded in 1984, Bickel & Brewer has earned a reputation as one of the most successful law firms in the United States practicing exclusively in the field of complex commercial litigation and dispute resolution.

Victim:   |  Group: 
 flag

Hungarian Investment Promotion Agency 

Company logo
Ransomware Group:

Discovery Date: 2023-07-30 10:02

Sector:
Hungarian Investment Promotion Agency is a company that operates in the Financial Services industry. It employs 11-20 people and has $5M-$10M of revenue.

Victim:   |  Group: 
 flag

Siden & Associates Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-07-22 14:55

Sector:
Siden & Associates, P.C. provides legal services to clients throughout the greater Boston and New England areas. Our clients range from large and medium sized corporations to small and developing businesses.

Victim:   |  Group: 
 flag

Hungarian Investment Promotion Agency Press Release 

Company logo
Ransomware Group:

Discovery Date: 2023-07-22 14:55

Sector:
Hungarian Investment Promotion Agency is a company that operates in the Financial Services industry. It employs 11-20 people and has $5M-$10M of revenue.

Victim:   |  Group: 
 flag

Servizi Omnia All data upload 

Company logo
Ransomware Group:

Discovery Date: 2023-05-30 12:57

Sector:
I nostri consulenti svolgono tutte le attività di gestione della contabilità e predisposizione delle dichiarazioni tributarie..

Victim:   |  Group: 
 flag

Servizi Omnia 

Company logo
Ransomware Group:

Discovery Date: 2023-05-26 21:57

Sector:
I nostri consulenti svolgono tutte le attività di gestione della contabilità e predisposizione delle dichiarazioni tributarie..

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila *All data upload* 

Company logo
Ransomware Group:

Discovery Date: 2023-05-15 11:56

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila *UPD 05-13* 

Company logo
Ransomware Group:

Discovery Date: 2023-05-12 23:55

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

CSD Network Services Ltd 

Company logo
Ransomware Group:

Discovery Date: 2023-05-11 14:01

Sector:
Today, we are publishing a Data Breach report of an outsourcing company, and we want to announce that tomorrow we will leak the databases of the following hotels into public access.

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila *UPD 05-11* 

Company logo
Ransomware Group:

Discovery Date: 2023-05-11 12:54

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila *UPD 05-10* 

Company logo
Ransomware Group:

Discovery Date: 2023-05-10 15:56

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila *first 10gb upload* 

Company logo
Ransomware Group:

Discovery Date: 2023-05-08 20:55

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

{UPD} Control & Automation technology - LUX Automation 

Company logo
Ransomware Group:

Discovery Date: 2023-05-08 19:54

Sector:
lux-automation.com For drive, regulation or control technology: LUX Automation is your expert when it comes to automation technology and process automation.

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila *UPDATE* 

Company logo
Ransomware Group:

Discovery Date: 2023-05-06 13:48

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

ASL 1 - Avezzano Sulmona L'Aquila 

Company logo
Ransomware Group:

Discovery Date: 2023-05-03 16:54

Sector:
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila.

Victim:   |  Group: 
 flag

Control & Automation technology - LUX Automation 

Company logo
Ransomware Group:

Discovery Date: 2023-05-03 16:53

Sector:
lux-automation.com For drive, regulation or control technology: LUX Automation is your expert when it comes to automation technology and process automation.

Victim:   |  Group: 
 flag

Weickert Industries 

Company logo
Ransomware Group:

Discovery Date: 2023-03-23 22:41

Sector:
www.weickert.com

Victim:   |  Group: 
 flag

American Institute for Healthcare Quality 

Company logo
Ransomware Group:

Discovery Date: 2023-03-19 13:09

Sector:
https://www.zoominfo.com/c/american-institute-for-healthcare-quality/359823076

Victim:   |  Group: 
 flag

Donut Leaks 

Company logo
Ransomware Group:

Discovery Date: 2023-03-19 13:09

Sector:
this gay rippers : Monti #ransomware team posted about how Dount Leaks stole 100K from them and did not 'fulfill the terms of the deal' 👀

Victim:   |  Group: 
 flag

UnitedLex 

Company logo
Ransomware Group:

Discovery Date: 2023-03-17 19:21

Sector:
www.unitedlex.com

Victim:   |  Group: 
 flag

Cambridge College 

Company logo
Ransomware Group:

Discovery Date: 2023-03-15 11:13

Sector:
boston.cambridgecollege.edu

Victim:   |  Group: 
 flag

Regional Transportation Authority 

Company logo
Ransomware Group:

Discovery Date: 2023-03-08 00:14
Estimated Attack Date: 2023-03-07

Sector:
A government agency created by the State of Illinois to coordinate the Chicago region’s transit system https://rtachicago.org

Victim:   |  Group: 
 flag

Every one of you been a good customer this year 

Company logo
Ransomware Group:

Discovery Date: 2022-12-22 20:17

Sector:

Group: 
 flag

test 

Company logo
Ransomware Group:

Discovery Date: 2022-12-07 10:36

Sector:

Group: