Uptime Hamster: 12d 19h 58mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ranion

ranion

2 incidentes 0 paises 0 sectores ransomware Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Ranion is a ransomware-as-a-service (RaaS) operation that first emerged in February 2017, offering its customizable ransomware to cybercriminals through dark web portals. The group behind Ranion notably claimed their product was for 'educational purposes only' while actively selling access to their ransomware distribution network. Ranion's malware is based on the open-source HiddenTear ransomware, suggesting a low-cost, accessible entry point for aspiring threat actors rather than a highly resourced state-sponsored group. This characteristic distinguishes Ranion as a foundational tool for a broad range of financially motivated cybercriminals. While it does not operate under widely recognized aliases, it is frequently referred to within the cybersecurity community as 'Ranion RaaS'.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownranionv3j2o7wrn3um6de33eccbchhg32mkgnnoi72enkpp7jc25h3ad.onionranion
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: ranion
Tecnicas MITRE
T1486, T1078, T1489, T1210
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

GermanySpainFranceIran, Islamic Republic ofItalyNetherlandsRussian FederationUnited States

Sectores objetivo (SOCRadar)

ManufacturingRetailFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceArts & EntertainmentOtherPublic Administration

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com