lv logo

lv

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
LV is a ransomware group that first emerged in late 2020. It operates as a ransomware-as-a-service (RaaS) offering, primarily distinguished by its use of a modified REvil (also known as Sodinokibi) ransomware binary. The group's primary motivation is financial gain through double extortion, where they encrypt victim data and threaten to leak stolen information. While they often frame their attacks as retaliation against organizations that fail to protect data, this serves as a justification for their financially driven operations. Despite leveraging a powerful, repurposed ransomware, LV's backend infrastructure is considered less sophisticated than the original REvil operation, specifically lacking the extensive command and control network.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

ArmeniaArgentinaAustraliaBosnia and HerzegovinaBrunei DarussalamBolivia, Plurinational State ofBrazilCanadaSwitzerlandChina

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com