Ransomware Victim: Corporación Primax S.A. (aurora)

Fecha
23 Jun 2026
Actor
aurora
Tipo
Ransomware
Pais
United States
Sector
Banking
Confianza
high
60
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

0IOCs
0TTPs
auroraActor
United StatesPais
Executive Summary
Victima de ransomware reportada en el dashboard de aurora.

Key Points

  • Ransomware Dashboard
  • Fuente original

Corporación Primax S.A.

Victima de ransomware reportada en el dashboard de aurora.

CampoValor
Grupoaurora
PaisPE
SectorNot Found
Fecha2026-06-23T06:21:35.978085+00:00

Detalles

[distribution, fuel] ***.A. is Peru's largest fuel distribution company, operating 2,185+ stations across Peru, Ecuador, Colombia, and Uruguay with annualised revenue of approximately USD 3.4 billion (Peru alone). The dataset spans every function of the business: Complete financial reporting — Monthly P&L, balance sheet, cash flow, and EBITDA through May 2025. GRIO (Grupo Romero Investment Office) management reporting packages. Budget 2025 vs. actuals. Employee identity data for 15,000–60,000 individuals — DNI national ID numbers, bank accounts, salary amounts, pension fund details, scanned identity documents. Live system credentials — Plaintext SQL database passwords, banking SFTP credentials (Banco Bolivariano Ecuador), AD encryption master key, OSINERGMIN fuel-control system credentials. Complete OT network map — IP addresses and identifiers for 137 fuel stations on the internal 10.55.40.x network, plus JD Edwards ERP production servers. 54 GB of POS transaction data — XML records of consumer fuel purchases across the entire station network. Legal and M&A documentation — Arbitration case files (PUCP/AMCHAM), UNO Corp acquisition materials (Dec 2025), bank covenant waivers.

Referencias

Diamond Model

Adversary
aurora
Ver perfil →
Victim
Ransomware Victim: Corporación Primax S.A. (aurora)
United States
Capability
Ransomware
Filtracion: 54 GB
Infrastructure
Sin infraestructura confirmada

Referencias y enlaces

→ Perfil del actor aurora en el blog → Ver aurora en IntelTracker → URL IntelTracker: u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion → Fuente OSINT: u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion → Buscar aurora en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes