Uptime Hamster: 11d 9h 27mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza orca

orca

3 incidentes 3 paises 3 sectores ransomware RU Ultimo: 2026-06-29
Aliases: camofei, Ke3chang, Mirage, Playful Dragon, Royal APT, Vixen Panda, apt15, CAPI backdoor, cargotalon, eaglet implant, headmare, phantomc2, phantomcore, phantomocx, phantomproxylite, phantomremote, ung0901, APT REAPER
Ver en IntelTracker → APTTrail →
Orca is a ransomware group that first emerged in September 2024, identified as a variant of the Zeppelin malware family. The group's primary motivation is financial, and it claims to adhere to a strict policy against targeting government institutions, hospitals, or non-profit organizations. This self-imposed restriction aims to avoid unnecessary harm while pursuing financial gains.

Aliases del actor

camofeiKe3changMiragePlayful DragonRoyal APTVixen Pandaapt15CAPI backdoorcargotaloneaglet implantheadmarephantomc2phantomcorephantomocxphantomproxylitephantomremoteung0901APT REAPER

Actores similares

apt-camarodragonactor · 1apt-dragonokactor · 1apt-reaperactor · 1apt-sharppandaactor · 1apt-twistedpandaactor · 1Aoqin Dragonapt · 1Mustang Pandaapt · 1Night Dragonapt · 1APT27 (Emissary Panda)actor · 1Putter Pandaapt · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownwww.breachsense.commatco-norca.com - Conti Data Breach
DLS / leak siteunknowngetbootstrap.comtaylor-cad.org - Conti Data Breach
Repositoriounknowngithub.comtaylor-cad.org - Conti Data Breach
Repositoriounknowngithub.comorcasnaturals.com - Conti Data Breach
Repositoriounknowngithub.comtaylor-cad.org - Conti Data Breach
DLS / leak siteunknownwww.breachsense.comorcasnaturals.com - Conti Data Breach
DLS / leak siteunknownwww.breachsense.comtaylor-cad.org - Conti Data Breach
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: orca
DLS / leak siteunknownnitter.netIdo Cohen: Supply Chain Extortion Alert The Icarus ransomware group has escalated pressure tactics against a major Canadian consulting and competitive intelligence provider. After initially naming the organization, the group is now threatening to release data belonging to the company's clients, giving them a deadline to make contact before publication begins.
X/Twitterunknownx.comIdo Cohen: Supply Chain Extortion Alert The Icarus ransomware group has escalated pressure tactics against a major Canadian consulting and competitive intelligence provider. After initially naming the organization, the group is now threatening to release data belonging to the company's clients, giving them a deadline to make contact before publication begins.
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Italy (1) France (1)

Paises objetivo (SOCRadar)

AustriaChinaColombiaSpainFranceItalyTunisiaTaiwan, Province of China

Sectores atacados

Software (1) Agriculture and Food Production (1) Government (1)

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesSoftware PublishersTransportation Equipment ManufacturingEnterprises & HoldingManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPlastics Product ManufacturingAircraft Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com

Victimas (1)

Casale Del Giglio27 Apr 2026
Ransomware Italy Agriculture and Food Production
Resumen Casale Del Giglio es una entidad con un historial de actividad en el sector de ciberseguridad, pero no se ha reportado ningún incidente de ran…