Uptime Hamster: 10d 6h 1mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza J

J

1 incidentes 1 paises 0 sectores ransomware Ultimo: 2026-06-29
Aliases: lo que sugiere una red de actividades coordenadas, Comment Panda, PLA Unit 61398, TG-8223, APT1, BrownFox, Group 3, GIF89a, ShadyRAT, Shanghai Group, Byzantine Candor, G0006, Putter Panda, PLA Unit 61486, TG-6952, especialmente en entornos de oficina, TG-0110, APT3
Ver en IntelTracker → APTTrail →
J, also known as J Group, emerged as a new ransomware group in early 2025, launching its data leak site in May 2025. This group operates as a cybercriminal cartel primarily focused on double extortion through data exfiltration and public leakage. Their primary motivation is financial gain, monetizing stolen data even if ransom negotiations fail. J Group's behavior indicates an evolving modus operandi, as they are still establishing their operational procedures, and have been observed to adopt data brokerage as a common approach. They are often characterized as a leak-site-centric extortion identity, distinguishing themselves by attempting to sell data publicly rather than solely relying on encryption-based ransom payments.

Aliases del actor

lo que sugiere una red de actividades coordenadasComment PandaPLA Unit 61398TG-8223APT1BrownFoxGroup 3GIF89aShadyRATShanghai GroupByzantine CandorG0006Putter PandaPLA Unit 61486TG-6952especialmente en entornos de oficinaTG-0110APT3BuckeyeUPS TeamGroup 6Boyusec – the Guangzhou Boyu Information Technology CompanyLtdG0023ELMER backdoorGh0stHTRANUNICATPoison IvyPandora1Hammer Panda

Actores similares

Conquerors Electronic Armyapt · 0Operation DRBControlapt · 0PhantomControlapt · 0Eloquent Pandaapt · 0apt-desertfalconactor · 1Desert Falconsapt · 0apt-stealthfalconactor · 1Stealth Falconapt · 1Contagious Interviewapt · 1Confuciusapt · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comJCPenney
Webunknownduckduckgo.comJCPenney
Webupsecurelist.comAPT GOLDENJACKAL indicators and references
X/Twitteruptwitter.comAPT GOLDENJACKAL indicators and references
Webupwww.virustotal.comAPT GOLDENJACKAL indicators and references
Webupwww.welivesecurity.comAPT GOLDENJACKAL indicators and references
Repositoriounknowngithub.comAPT TAJMAHAL indicators and references
Webunknownraw.githubusercontent.comAPT TAJMAHAL indicators and references
X/Twitterupsecurelist.comAPT GOLDENJACKAL indicators and references
Webunknownwww.recordedfuture.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.virustotal.comAPT REDJULIETT indicators and references
Webunknownwww.recordedfuture.comAPT REDJULIETT indicators and references
Webunknownotx.alienvault.comAPT TAJMAHAL indicators and references
Webunknownsecurelist.comAPT TAJMAHAL indicators and references
Webunknownotx.alienvault.comAPT TAJMAHAL indicators and references
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-001-AKIRA-JUN-2025
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-020-INCRANSOM-JAN-2026
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Germany (1)

Paises objetivo (SOCRadar)

ArgentinaAustraliaBarbadosBelgiumBrazilCanadaSwitzerlandChinaGermanyFrance

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateAir TransportationManufacturingConstructionPublic AdministrationOil & Gas

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com