Back to Threat Groups

ms13089

ACTIVE

ransomware group

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Secu

Victims
6
records
First Discovered
Dec 18, 2025
victim
Last Discovered
Aug 15, 2026
victim
Inactive Since
0
days
Countries
5
hit
Avg Discount
no settlements

Group Activity

Last 12 months
Sep
2025
Oct
2025
Nov
2025
2
Dec
2025
1
Jan
2026
Feb
2026
Mar
2026
Apr
2026
1
May
2026
Jun
2026
Jul
2026
2
Aug
2026

Infrastructure

leak site
ONLINE
http://msleakjir7pxbe6onlqe5uwgvdmy6nq4mnwfy7ojswbhnleenm77vgad.onion

3337ms

28m ago

leak site
ONLINE
http://chatmsuppxeoma533636ga3g5k56wlyl3zvycya35nhgoktrtg7wgzyd.onion/home

1886ms

28m ago