Uptime Hamster: 10d 9h 47mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza 0mega

0mega

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
0mega is a financially motivated ransomware group that first emerged in May 2022, rapidly becoming known for its aggressive double extortion tactics. Initially, the group deployed ransomware that encrypted files with a unique .0mega extension, alongside exfiltrating sensitive data. Over time, 0mega has notably evolved its operational model to sometimes forego file encryption entirely, focusing instead on pure data theft and extortion, particularly targeting cloud-based Software-as-a-Service (SaaS) environments such as Microsoft 365 and SharePoint. This shift, observed in attacks from mid-2023, distinguishes them from many other ransomware operations by directly compromising cloud administrator accounts for data exfiltration without endpoint compromise. The group appears to operate as a closed entity, selectively targeting high-value organizations rather than functioning as a Ransomware-as-a-Service model.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: 0mega
Tecnicas MITRE
T1059.001, T1562.001, T1562.002, T1027
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAustraliaCanadaDenmarkUnited KingdomIndiaLiberiaTurkeyUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersHospitalsAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com