sarcoma logo

sarcoma

4 incidentes 4 paises 3 sectores ransomware UZ Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Sarcoma ransomware group, first identified in October 2024, operates as a financially motivated threat actor primarily employing a double extortion model to maximize profit from its victims. The group's operational patterns, including the observed avoidance of infecting systems with Uzbek keyboard layouts, suggest its core operators may be located in Uzbekistan or the broader CIS region. Sarcoma quickly rose to prominence due to its aggressive campaigns and a tightly controlled operational structure managed by a compact core team, which allows for disciplined execution often not seen in newly emerged ransomware groups. It is known for rapidly escalating its victim count and is reportedly capable of utilizing zero-day exploits in its attacks, a characteristic that differentiates it from many other ransomware operations.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
3
TTPs unicas
1
Info robada historica
1.62 TB
Rescates reclamados
N/D
Pagos detectados
N/D

TTPs observadas

T1566 Phishing

Paises afectados

Argentina (1) Canada (1) Italy (1) United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaAustraliaBangladeshBelgiumBulgariaBolivia, Plurinational State ofBrazilCanada

Sectores atacados

Technology (2) Energy (1) Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesCredit UnionsSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com

Victimas (3)

GYF30 Mar 2026
Ransomware Argentina Technology
Resumen GYF es una alerta de ransomware atribuida al grupo sarcoma, vinculado a la industria financiera en Argentina. Se reportó un incidente el 30 de…
Propane Levac Inc.23 Jan 2026
Ransomware Canada Energy
Resumen Una alerta de ransomware ha sido publicada relacionada con la empresa Propane Levac Inc., una empresa canadiense especializada en la distribuc…
MecMatica20 Jan 2026
Ransomware Italy Technology
Resumen MecMatica es una alerta de ransomware relacionada con el grupo sarcoma, que ha afectado sistemas de monitorización y gestión industrial en el …