Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Nasirsecurity

Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle East (UAE, Oman, Saudi Arabia, Iraq) and Israeli IT supply chain firms, using spear-phishing, BEC, and exploitation of public-facing applications.

Victims
1
 
First Discovered
2025-10-12
victim
Last Discovered
2025-10-12
victim
Inactive Since
295
days
Avg Delay
7
days
Infostealer
N/A
victims with domain
Countries
1
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Nasir Security No 2026-04-28T07:25:15 yzcpwxuhbkyjnyn4qsf4o5dkvu6m2fyo7dwizmnlutanlmzlos7pa6qd.onion
favicon Error Response Page No 2026-04-28T07:27:47 Microsoft-IIS 10.0 nasir.cc

Target
Top 5 Activity Sectors
  • Technology 1
Top 5 Countries
  • IL flag Israel 1

Heatmap

YARA Rules (1)

Victims (1)
Logo
Discovered: 2025-10-12 (9mo ago)  ·  Attack est.: 2025-10-05
This is a warning... you remain in danger.…