Uptime Hamster: 10d 6h 2mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza IMNCrew

IMNCrew

2 incidentes 1 paises 0 sectores ransomware Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
IMNCrew is a financially motivated ransomware and extortion group first observed in late March 2025. The group initially focused solely on data exfiltration and extortion, but later evolved to also deploy encryption payloads, using the .imn file extension for encrypted data. They launched their dedicated leak site around April 15, 2025, to publish exfiltrated victim data. Unlike many other emerging ransomware groups, IMNCrew has no confirmed associations with established operations. Their operational style is characterized by being polite and not overly aggressive during ransom negotiations. The group primarily targets small to medium-sized businesses across various sectors.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownimncrewwfkbjkhr2oylerfm5qtbzfphhmpcfag43xc2kfgvluqtlgoid.onionIMNCrew
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: IMNCrew
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Indonesia (2)

Paises objetivo (SOCRadar)

CanadaColombiaCzech RepublicSpainCroatiaIndonesiaItalyMexicoPhilippinesSweden

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankAccommodationManufacturingConstructionPublic AdministrationBeverag & Tobacco ManufacturingEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com