Uptime Hamster: 11d 15h 8mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza hotarus

hotarus

2 incidentes 1 paises 1 sectores ransomware null Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Hotarus is a ransomware and data extortion group first observed in February 2021 with a notable attack against Ecuador's Ministry of Finance and a major bank. The group is believed with moderate confidence to be of Latin American origin and primarily targets financial institutions, government agencies, and private companies in South America and the United States. Hotarus's core motivation is financial gain, achieved through the deployment of custom ransomware and data theft. A distinctive characteristic of the group is its willingness to engage in pure data leak threats without necessarily encrypting files, leveraging exposure as a primary pressure tactic in its extortion model.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownr6d636w47ncnaukrpvlhmtdbvbeltc6enfcuuow3jclpmyga7cz374qd.onionhotarus
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: hotarus
Tecnicas MITRE
TA0001, TA0005, TA0040, TA0009, TA0011
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

EcuadorSingaporeThailandTurkeyTaiwan, Province of ChinaUnited States

Sectores atacados

Finance (1)

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingInformation ServicesFinanceEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic AdministrationMonetary Authorities-Central Bank

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com