arvinclub
INACTIVEransomware group
Arvin Club first appeared around early to mid-2021, debuting on its Tor leak site with posts dating back to May 5, 2021. While frequently characterized as ransomware, there is no verified evidence of file encryption or RaaS operations—its behavior aligns more closely with data-leak and hacktivist activity. The group actively publishes stolen data via its Onion site and maintains a prominent presence on Telegram, operating both official channels and group chats (notably with Persian-language content). A known target includes India's Kendriya Vidyalaya school network among others. Arvin Club has shown ideological leanings (notably support for REvil) and claims to have “hacktivist” motivations, including activities against the Iranian regime. No encryption algorithms, file extensions, or ransom notes have been publicly documented.
Group Activity
Last 12 monthsVictims (35)
Islamic Azad University Electronic Campus
Jahesh Innovation
Kimia Tadbir Kiyan
Islamic Azad University of Shiraz
Pasouk biological company
Shirin Travel Agency
Aban Tether & OK exchange
sti company
Sabalan Azmayesh
Parsian Bitumen
Draje food industrial group
seaside-kish co
AFTA Isfahan
hamyari Shahrdari golestan
Haraz dairy
150k sib360 Database
Padena Factory
Bitimen
A harmful truth is better than a useful lie
Al Bijjar
AM International
stormous
bedfordshire.police.uk
afcx.co
vidisha.kvs.ac.in
Revil
Bureau van Dijk(bvdinfo.com)
Compilation of Many Breaches
CardPayPortal
33M Bank Mellat – Iran
Etoudplus.ir
Beh Pardakht Mellat Cards
UtAir
Leiden University Hacked
T-Mobile
elitemate.com
Infrastructure
No sites tracked