Uptime Hamster: 11d 23h 20mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza u-bomb

u-bomb

2 incidentes 0 paises 0 sectores ransomware Ultimo: 2026-06-29
Aliases: 0xFFF
Ver en IntelTracker → APTTrail →
U-bomb is a ransomware group that emerged in March 2023, operating as a semi-private entity targeting a smaller pool of victims compared to larger ransomware operations. The group is primarily motivated by financial gain and employs double extortion tactics. While it shares some visual similarities with the Hive ransomware group in its negotiation portal, there is no confirmed connection between the two operations. U-bomb is notable for its focus on Linux payloads as of November 2023, distributing them as .sh files that are, in fact, ELF binaries, a technique used to bypass certain security measures.

Aliases del actor

0xFFF

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknowncontiuevxdgdhn3zl2kubpajtfgqq4ssj2ipv6ujw7fwhggev3rk6hqd.onionu-bomb
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: u-bomb
Tecnicas MITRE
T1082, T1059.001, T1078.003, T1566.002, T1490
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Sectores objetivo (SOCRadar)

Food ManufacturingMonetary Authorities-Central BankCredit UnionsSoftware PublishersEnterprises & HoldingAccommodationManufacturingConstructionPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com