underground
ACTIVEransomware group
π·πΊRussiaUnderground ransomware (also known as Underground Team) is a Russia-linked group associated with the RomCom RAT threat cluster, assessed to be connected to the Void Rabisu/Cuba ransomware operation. Active since late 2023, the group targets Windows systems and is notable for not encrypting files but instead threatening to publish stolen data. Researchers at Trend Micro linked the Underground group to infrastructure and tooling shared with RomCom campaigns attributed to Russian state-adjacent actors.
Group Activity
Last 12 monthsVictims (25)
SFA Engineering
Revenue: $1.7 Billion Type: Industry Size: 2,3 TBytes
GMORS Co., Ltd
Revenue: $100 million Type: Manufacturing Size: 302,7 GBytes
Afa Systems Ltd.
Revenue: $37.2 million Type: Industry Size: 1,1 TBytes
shengyusteel.com
Revenue: $431.6 million Type: Manufacturing Size: 353,9 GBytes
semex.com
Revenue: $170 million Type: Research Size: 214,2 GBytes
Simmtech Co., Ltd.
Revenue:$ 760M - Country :South Korea
hcsgcorp.com
Revenue:$1.7 Billion - Country :USA
Casio Computer Co., Ltd
Revenue:$1.858 billion - Country :Japan
ramservices.com
Revenue:$162M - Country :USA
Ethypharm
Revenue:$ 670M - Country :France
A-Line Staffing Solutions
Revenue:$96.1M - Country :USA
belcherpharma.com
Revenue:$25.7M - Country :USA
CentralSecurities.com
Revenue:$230M - Country :USA
kc.co.kr
Revenue:$650M - Country :South Korea
bulldogbag.com
Revenue:$20.6M - Country :Canada
frenckengroup.com
Revenue:$50.0M - Country :Singapore
synology.com
Revenue:$183.6M - Country :Germany, Taiwan
tpa-group.sk
Revenue:tpa-group.com $281M; tpa-group.sk $15M - Country :Slovakia
Triathlon.group
Revenue:$176M - Country :Australia, Germa...
awwg.com
Revenue:β¬585M - Country :France, Spain, U...
KyungChang
Revenue:$650M - Country :South Korea
Y. Hata & Co., Ltd.
Revenue:$268M - Country :USA
Skender Construction
Revenue:$318.3 Million - Country :USA
Creative Business Interiors
Revenue:$27M - Country :USA
cochraneglobal.com
Revenue:$270.8 Million - Country :United Arab Emir...
Infrastructure
http://47glxkuxyayqrvugfumgsblrdagvrah7gttfscgzn56eyss5wg3uvmqd.onion2783ms
22d ago