Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Ransomed

| RaaS

RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims including Sony, innovating by threatening GDPR regulatory fines as an additional extortion lever; it briefly operated as a RaaS before shutting down in an apparent exit scam following reported arrests of six members.

Victims
68
 
First Discovered
2023-08-21
victim
Last Discovered
2023-10-30
victim
Inactive Since
2yrs
more than
Avg Delay
2.1
days
Infostealer
27.1%
victims with domain
Countries
10
hit
View Victims on World Map View Group Statistics

Known Locations (4)
Favicon Title Type Available Last Visit Server Info FQDN
favicon No 2026-04-28T07:25:56 ransomed.vc
favicon 404 Not Found No 2026-04-28T07:28:28 k63fo4qmdnl4cbt54sso3g6s5ycw7gf7i6nvxl3wcf3u6la2mlawt5qd.onion
favicon Ransomedvc – Leading Agency In Digital Peace – Ran No 2026-04-28T07:31:00 f6amq3izzsgtna4vw24rpyhy3ofwazlgex2zqdssavevvkklmtudxjad.onion
favicon Ransomed No 2026-04-28T07:32:23 g6ocfx3bb3pvdfawbgrbt3fqoht5t6dwc3hfmmueo76hz46qepidnxid.onion

Target
Top 5 Activity Sectors
  • Consumer Services 15
  • Technology 10
  • Financial Services 7
  • Business Services 4
  • Healthcare 3
Top 5 Countries
  • BG flag Bulgaria 19
  • BR flag Brazil 3
  • JP flag Japan 3
  • VC flag Saint Vincent and the Grenadines 1

Heatmap

YARA Rules (1)

Victims (68)
Logo
Discovered: 2023-10-30 (2y ago)
I do not want to continue being monitored by federal agencies and i would wish to sell the project t…
Logo
Discovered: 2023-10-22 (2y ago)
Visit us: http://g6ocfx3bb3pvdfawbgrbt3fqoht5t6dwc3hfmmueo76hz46qepidnxid.onion…
Logo
Discovered: 2023-10-20 (2y ago)
@RansomedSupport on telegram to join Ransomed.vc is in need of only advanced pentesters, our jobs ar…
Logo
Discovered: 2023-10-16 (2y ago)
Ransomedvc now offers pentesting services! share your targets with us on @RansomedSupport on telegra…
Logo
Discovered: 2023-10-16 (2y ago)
Third-party involvement in the editing of the last 2 posts cannot be more obvious, considering the E…
Logo
Discovered: 2023-10-16 (2y ago)
Note : Threat actor Rob Lee has failed to cooperate with the demands made by us, including an admiss…
Logo
Discovered: 2023-10-15 (2y ago)
Threat actors – they hide amongst us. It is becoming increasingly difficult to differentiate these b…
Logo
Discovered: 2023-10-15 (2y ago)
How ironic! Rob Lee, the outed threat actor, working under the guise of a seasoned cyber-security pr…
Logo
Discovered: 2023-10-15 (2y ago)
No description available
Logo
Discovered: 2023-10-13 (2y ago)
We successfully extracted the entire content of the metroclub.org website, belonging to Metroclub, a…
Logo
Discovered: 2023-10-13 (2y ago)
We’ve successfully obtained control of their entire Azure cloud environment, which now resides under…
Logo
Discovered: 2023-10-13 (2y ago)
We have successfuly obtained all data from Balmit.bg. We have got all of their data + source + priva…
Logo
Discovered: 2023-10-13 (2y ago)
Our group was able to access everything from the main company servers, and it happened that their da…
Logo
Discovered: 2023-10-13 (2y ago)
Sample: https://qu.ax/LHRf.gOur group was able to access everything from the main company servers, a…
Logo
Discovered: 2023-10-13 (2y ago)
Our group was able to access everything from the main company servers, and it happened that their da…
Logo
Discovered: 2023-10-13 (2y ago)
https://qu.ax/nUmY.7z…
Logo
Discovered: 2023-10-13 (2y ago)
https://qu.ax/nEqR.7z…
Logo
Discovered: 2023-10-13 (2y ago)
https://qu.ax/fiSD.sql…
Logo
Discovered: 2023-10-13 (2y ago)
https://qu.ax/danH.7z…
Logo
Discovered: 2023-10-13 (2y ago)
Ransomedvc is now buying access on gaza countries + iran. message our admins!…
Logo
Discovered: 2023-10-13 (2y ago)
Tweets by RansomedSupport…
Logo
Discovered: 2023-10-07 (2y ago)
We have taken everything from your servers, you failed to contact us back, contact ASAP to fix. We a…
Logo
Discovered: 2023-10-07 (2y ago)
links: http://breachedu76kdyavc6szj6ppbplfqoz3pgrk3zw57my4vybgblpfeayd.onion/ https://breachforums.i…
Logo
Discovered: 2023-10-06 (2y ago)  ·  Attack est.: 2023-10-04
With approximately 310,000 employees worldwide, NTT (Nippon Telegraph and Telephone Corporation) is …
Logo
Discovered: 2023-10-06 (2y ago)  ·  Attack est.: 2023-10-05
We have successfully breached the District of Columbia Board Of Elections and have gotten more than …
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-16
Did I hear gov? Yep. We have accessed the majorty of their servers that were storing personal data, …
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-25
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-25
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-25
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-25
We will leak all of the info we have on you if dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-25
We will leak all of the info we have on you if we dont get paid.We require a ransom of $50,000…
Logo
Discovered: 2023-09-26 (2y ago)  ·  Attack est.: 2023-09-25
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)
We will leak all of the info we have on you if we dont get paid.We require a ransom of $15,000…
Logo
Discovered: 2023-09-26 (2y ago)
We will leak all of the info we have on you if we dont get paid.We require a ransom of $30,000…
Logo
Discovered: 2023-09-26 (2y ago)
We will leak all of the info we have on you if we dont get paid.We require a ransom of $14,000…
Logo
Discovered: 2023-09-26 (2y ago)
Sony Group Corporation, formerly Tokyo Telecommunications Engineering Corporation, and Sony Corporat…
Logo
Discovered: 2023-09-26 (2y ago)
With approximately 310,000 employees worldwide, NTT (Nippon Telegraph and Telephone Corporation) is …
Logo
Discovered: 2023-09-09 (2y ago)
All of your customer data,records and private documents are mine now, if you pay you wiWe require a …
Logo
Discovered: 2023-09-09 (2y ago)
You have been hacked, all your data is now mine, if you want to get your backups back you will have …
Logo
Discovered: 2023-09-09 (2y ago)
We have been able to access all of linktera critical infrastructure including her database, we dumpe…
Logo
Discovered: 2023-09-09 (2y ago)
We have been able to access all of linktera critical infrastructure including the database, we dumpe…
Logo
Discovered: 2023-09-08 (2y ago)
We have been able to access all of linktera critical infrastructure including her database, we dumpe…
Logo
Discovered: 2023-09-04 (2y ago)
We Have accessed all of the critical infrasrtucture of the company, we are on our way to publish all…
Logo
Discovered: 2023-09-04 (2y ago)
we have access everything on their servers, including the Database, and other non public documents.…
Logo
Discovered: 2023-09-04 (2y ago)
we have access everything on their servers, including the Database, and other non public documents.W…
Logo
Discovered: 2023-09-04 (2y ago)
we have access everything on their servers, including the Database, and other non public documents.W…
Logo
Discovered: 2023-09-04 (2y ago)
we have access everything on their servers, including the Database,Customers Chats, and other non pu…
Logo
Discovered: 2023-09-04 (2y ago)
we have access everything on their servers, including the Database,Customers Chats, Bank Transfer Do…
Logo
Discovered: 2023-09-04 (2y ago)
we have access everything on their servers, including the Database,Customers Chats, Bank Transfer Do…
Logo
Discovered: 2023-09-04 (2y ago)
We have successfuly obtained all data from Swipe.bg A online marketplace known for its cheap prices.…
Logo
Discovered: 2023-09-04 (2y ago)
We have successfuly obtained all data from Balmit.bg. We have got all of their data + source + priva…
Logo
Discovered: 2023-09-03 (2y ago)
We have hacked and exported the database of phms.com.au. We have gathered root access and access to …
Logo
Discovered: 2023-09-03 (2y ago)
We have compromissed the servers of paynesvilleareainsurance.com. We decided to make sure they remem…
Logo
Discovered: 2023-09-03 (2y ago)
SKF�s network was compromised(by collaboration withEverest Ransomware Group) a few days ago. The com…
Logo
Discovered: 2023-09-01 (2y ago)
We were able to dump and deface the official site of the hawaii health system. We demand a ransom no…
Logo
Discovered: 2023-08-31 (2y ago)
We were able to dump the entire metroclub.org site. Metroclub is a privte club from DC. There is…
Logo
Discovered: 2023-08-31 (2y ago)
Affected nearly 6tb of data. Because of the size of the data I require a payment to the following ad…
Logo
Discovered: 2023-08-31 (2y ago)
We are in hold of Everything any of their employes ever downloaded or used on their systems. whole c…
Logo
Discovered: 2023-08-28 (2y ago)
No description available
Logo
Discovered: 2023-08-27 (2y ago)
We were able to dump the entire metroclub.org site. Metroclub is a privte club from DC. There is 2.1…
Logo
Discovered: 2023-08-26 (2y ago)
No description available
Logo
Discovered: 2023-08-23 (2y ago)
No description available
Logo
Discovered: 2023-08-23 (2y ago)
No description available
Logo
Discovered: 2023-08-23 (2y ago)
Their whole azure cloud was exported and is now in our hands. luckly and sadly for them we have take…
Logo
Discovered: 2023-08-21 (2y ago)
I&G brokers are top top favourite Bulgarian Broker houses.First Payment Due, leaking dataDownload Sa…
Logo
Discovered: 2023-08-21 (2y ago)
A1 Data Provider (1/4 partial payments have been paid on 2023-08-23)…