Ransomed.vc, initially known as RansomForums, emerged in August 2023, quickly rebranding from an illicit forum to a data extortion blog. This group is distinct for its unique strategy of leveraging data protection regulations, such as GDPR, to pressure victims by threatening regulatory fines upon data exposure if ransom demands are not met. Their primary motivation is financial gain. Ransomed.vc operated as a Ransomware-as-a-Service model and gained notoriety for claiming high-profile victims like Sony and NTT Docomo. The group claimed to cease operations in November 2023 following the alleged arrests of several affiliates. It has been noted for making unverified claims about successful compromises.
Tecnicas MITRE
T1071, T1486, T1059, T1078
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Construction of BuildingsOther Information ServicesSoftware PublishersHospitalsWaste Management and Remediation ServicesEnterprises & HoldingAir TransportationManufacturingConstructionPublic Administration