Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Ms13089 / Ms13-089

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.

Victims
4
 
First Discovered
2025-12-18
victim
Last Discovered
2026-05-05
victim
Inactive Since
90
days
Avg Delay
N/A
attack→claim
Infostealer
0.0%
victims with domain
Countries
4
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon MS13-089 Blog Yes 2026-08-03T07:29:51 NGINX nginx 1.24.0 msleakjir7pxbe6onlqe5uwgvdmy6nq4mnwfy7ojswbhnleenm77vgad.onion

Target
Top 5 Activity Sectors
  • Professional Services 2
  • Retail & E-Commerce 1
  • Healthcare 1
Top 5 Countries
  • US flag United States 1
  • LU flag Luxembourg 1
  • IT flag Italy 1
  • DE flag Germany 1

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (1)
Email 1
Type IOC
Email ms13@onionmail.org

Victims (4)
Logo
Discovered: 2026-05-05 (2mo ago)
At Brittany Residential, Inc., we believe in creating a world where individuals with developmental d…
Logo
Discovered: 2026-01-15 (6mo ago)
SJL is a high-end independent business law firm renowned for its savoir faire and reliability. The f…
Logo
Discovered: 2025-12-18 (7mo ago)
Aree di specializzazione: contabilità, bilanci, dichiarazioni fiscali, incarichi di sindaco e reviso…
Logo
Discovered: 2025-12-18 (7mo ago)
Virginia Urology (VU) has a long history of providing quality care to the Greater Richmond metro are…