Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Ms13089 / Ms13-089

| Active

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.

Victims
4
 
First Discovered
2025-12-18
victim
Last Discovered
2026-05-05
victim
Inactive Since
8
days
Avg Delay
N/A
attack→claim
Infostealer
0.0%
victims with domain
Countries
4
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months
1 victim this month

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon MS13-089 Blog Yes 2026-05-13T22:18:06 NGINX nginx 1.24.0 msleakjir7pxbe6onlqe5uwgvdmy6nq4mnwfy7ojswbhnleenm77vgad.onion

Target
Top 5 Activity Sectors
  • Business Services 2
  • Consumer Services 1
  • Healthcare 1
Top 5 Countries
  • US flag United States 1
  • LU flag Luxembourg 1
  • IT flag Italy 1
  • DE flag Germany 1

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (1)
Email 1
Type IOC
Email ms13@onionmail.org

Victims (4)
Logo
Discovered: 2026-05-05 (8d ago)
At Brittany Residential, Inc., we believe in creating a world where individuals with developmental d…
Logo
Discovered: 2026-01-15 (3mo ago)
SJL is a high-end independent business law firm renowned for its savoir faire and reliability. The f…
Logo
Discovered: 2025-12-18 (4mo ago)
Aree di specializzazione: contabilità, bilanci, dichiarazioni fiscali, incarichi di sindaco e reviso…
Logo
Discovered: 2025-12-18 (4mo ago)
Virginia Urology (VU) has a long history of providing quality care to the Greater Richmond metro are…