benzona
8 incidentes
4 paises
3 sectores
ransomware Ultimo: 2026-06-29
Benzona is a financially motivated ransomware group that emerged in late November 2025, operating under a double-extortion model. The group distinguishes itself by encrypting victim files and exfiltrating sensitive data, threatening to publish this information on a dedicated Tor-based leak site if ransom demands are not met. They primarily target small to mid-sized organizations across various sectors, demonstrating a coordinated approach in simultaneous attacks against multiple related entities. The group is known solely as Benzona in public reporting, with no widely reported aliases or confusion with other threat actors.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Paises objetivo (SOCRadar)
Côte d'Ivoire
France
Guatemala
IndiaIran, Islamic Republic of
JapanNamibia
New Zealand
RomaniaTaiwan, Province of China
Sectores atacados
Software (1)
Healthcare (3)
Hospitality and Tourism (1)
Sectores objetivo (SOCRadar)
Other Information ServicesHospitalsEnterprises & HoldingAccommodationManufacturingWholesale TradeRestaurantsEducational ServicesAircraft ManufacturingAutomotive
URLs nuevas detectadas en IntelTracker
Victimas (6)