ransombay logo

ransombay

1 incidentes 0 paises 0 sectores ransomware MY Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Ransombay is a data leak site and white-label branding service introduced by the DragonForce ransomware group in early 2025, enabling affiliates to operate under disguised ransomware strains. DragonForce, which emerged in August 2023 primarily out of Malaysia and is focused on financial gain through a multi-extortion model, established RansomBay to host data stolen by its affiliates. The group takes a 20% share of successful ransomware payouts and aims to build a 'Ransomware Cartel' ecosystem by providing infrastructure, malware, and support services. While DragonForce has claimed that the closely associated RansomHub ransomware-as-a-service (RaaS) operation joined its cartel, RansomHub has publicly denied this, though reports suggest RansomHub affiliates may be utilizing DragonForce's shared infrastructure or are a rebrand of former BlackCat affiliates. Ransombay represents DragonForce's strategic evolution to profit from a broader network of ransomware operations.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

AustraliaCanadaChinaCzech RepublicGermanyDenmarkEgyptFijiFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersEnterprises & HoldingManufacturingConstructionPublic AdministrationOil & GasEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com