Back to Threat Groups

0mega

ACTIVE

ransomware group

0mega is a ransomware group first observed in May 2022, operating with a double extortion model: <br/>* Encrypting victim files (adding the .0mega extension) <br/>* Threatening to leak stolen data if ransom demands are not met. <br/>Ransom notes are named DECRYPT-FILES.txt and include victim-specific details and a Tor-based negotiation portal. <br/>Unlike typical Ransomware-as-a-Service (RaaS) operations, 0mega appears to work as a closed group, selecting a limited number of high-value targets. <br/>The group employs two main tactics: <br/>* Traditional ransomware encryption of on-premise systems. <br/>* Cloud-based extortion, compromising Microsoft 365 Global Admin accounts, creating unauthorized admin users, and exfiltrating data via SharePoint. <br/>Active period: May 2022 – January 2024

Victims
7
records
First Discovered
Jul 14, 2022
victim
Last Discovered
Jan 25, 2024
victim
Inactive Since
883
days
Countries
1
hit
Avg Discount
β€”
no settlements

Group Activity

Last 12 months
Jul
2025
Aug
2025
Sep
2025
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026