raworld logo

raworld

1 incidentes 1 paises 0 sectores ransomware CN Ultimo: 2026-06-25
Aliases: RA Group
Ver en IntelTracker → APTTrail →
RA World is a ransomware group that emerged in April 2023, rebranding from its earlier identity as RA Group. Its primary motivation is financial gain through a multi-extortion scheme, which involves both encrypting victim data and exfiltrating sensitive information to leak on dark web sites if ransom demands are not met. What distinguishes RA World is its unique tactic of including a list of past victims who refused to pay in their ransom notes to pressure new targets, alongside an experimental "cost per customer" calculation. The group notably evolved its targeting, initially impacting healthcare organizations before shifting focus to the manufacturing sector by mid-2024. While no confirmed country of origin exists for RA World, some of its activities in late 2024 and early 2025 involved the use of tools previously associated with China-linked advanced persistent threat groups, suggesting a possible, though unverified, connection.
Tecnicas MITRE
T1036, T1195, T1490, T1059.001, T1486, T1562.001

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArmeniaAngolaArgentinaAmerican SamoaAustriaAustraliaArubaAzerbaijanBarbados

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersTransit and Ground Passenger TransportationReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com