onepercent logo

onepercent

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
OnePercent is a financially motivated ransomware group that emerged in November 2020, known for its double extortion tactics against US companies. The group's name derives from its unique 'one percent leak' tactic, where it releases a small portion of exfiltrated data as proof before escalating extortion efforts. OnePercent operates as a ransomware-as-a-service affiliate, partnering with other prominent ransomware operations such as REvil (Sodinokibi), Maze, and Egregor, often leveraging their data leak sites for auctions if ransoms are not paid. The group is distinguished by its direct and persistent communication with victims, including follow-up calls and emails using spoofed numbers, maintaining network access for up to a month to thoroughly exfiltrate data before deploying ransomware.
Tecnicas MITRE
T1059, T1078, T1105, T1047

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United States

Sectores objetivo (SOCRadar)

ManufacturingInformation ServicesFinanceEnterprises & HoldingHealthCare & Social AssistanceOtherBanking

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com