Orion Ransomware
0 incidentes
0 paises
0 sectores
ransomware Global Ultimo: -
Aliases: Orion Leaks
Orion Ransomware is a financially motivated cybercrime group that surfaced in early 2024, distinguished by its tactical focus on high-speed encryption and a preference for targeting small-to-mid-sized enterprises (SMEs) that often lack dedicated 24/7 Security Operations Centers. The group notably brands itself as 'security consultants' in its ransom notes, highlighting perceived vulnerabilities in the victim's security posture. Operating under aliases such as Orion Leaks Ransomware, the group has also been observed engaging in 're-leaking' activities, where it publishes data previously exfiltrated by other ransomware groups as its own, showcasing a unique opportunistic behavior within the ransomware ecosystem. While the core Orion Ransomware emerged in early 2024, its alias Orion Leaks Ransomware was first documented in October 2025, suggesting a possible evolution or rebranding of operations.
Paises objetivo (SOCRadar)
Argentina
Australia
Canada
Germany
IndiaKorea, Republic of
Russian Federation
Thailand
United StatesGlobal
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingSoftware PublishersEnterprises & HoldingManufacturingElectrical Equipment, Appliance, and Component ManufacturingEducational ServicesInsuranceClothing StoresAccommodation&Food Services