Uptime Hamster: 10d 12h 29mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ups

ups

1 incidentes 1 paises 1 sectores Ultimo: 2026-07-09
Aliases: TG-0110, APT3, Buckeye, UPS Team, Group 6, Boyusec – the Guangzhou Boyu Information Technology Company, Ltd, Hellsing, Cycldek, Conimes Team, China1937CN Team, otros mencionados en fuentes OSINT verificadas, Energy technology, G20, NGOs, Dissident Groups, alias sugiere que debe ser monitoreado con atención, apt-c-60
Ver en IntelTracker → APTTrail →

Aliases del actor

TG-0110APT3BuckeyeUPS TeamGroup 6Boyusec – the Guangzhou Boyu Information Technology CompanyLtdHellsingCycldekConimes TeamChina1937CN Teamotros mencionados en fuentes OSINT verificadasEnergy technologyG20NGOsDissident Groupsalias sugiere que debe ser monitoreado con atenciónapt-c-60apt-q-12spyglaceaa22-264abanished kittenhomeland justicekarmared sandstormstorm-0842void manticorebisonaltontotontoteamAPT CARETOAPT FLIGHTNIGHT

Actores similares

Tonto Teamapt · 1Eloquent Pandaapt · 0apt-1877teamactor · 1apt-equationgroupactor · 1apt-group5actor · 1apt-hackingteamactor · 1Gamaredon Groupapt · 1The Gorgon Groupapt · 0Desert Dexter Groupapt · 0DarkStorm Teamapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: CISAThreatGroups
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: TrendMicroThreatGroups
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: TheDFIRReportGroups
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: TrendMicroThreatGroups
DLS / leak siteunknownwww.breachsense.comupstatehomecare.com - Pysa Data Breach
DLS / leak siteunknowngetbootstrap.comupstatehomecare.com - Pysa Data Breach
Repositoriounknowngithub.comupstatehomecare.com - Pysa Data Breach
DLS / leak siteunknownwww.breachsense.comtkemlups.ca - Conti Data Breach
DLS / leak siteunknownduckduckgo.comtkemlups.ca - Conti Data Breach
DLS / leak siteunknownduckduckgo.comtkemlups.ca - Conti Data Breach
DLS / leak siteunknownnitter.netIdo Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.
X/Twitterunknownx.comIdo Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.
DLS / leak siteunknownnitter.netIdo Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
DLS / leak siteunknownnitter.netIdo Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.
DLS / leak siteupnitter.netIdo Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.
DLS / leak siteupnitter.netIdo Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.
DLS / leak siteunknownnitter.netIdo Cohen: Threat Group Update Prinz Eugen has launched a newly redesigned leak site and updated its public profile. According to the group's latest statement, it describes itself as a for-profit organization that "specializes in hacking" while claiming it currently does not operate a Ransomware-as-a-Service (RaaS) program. The group also stated that membership intake is currently closed and limited to existing core members.
DLS / leak siteupnitter.netIdo Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.
DLS / leak siteunknownnitter.netIdo Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.
DLS / leak siteunknownnitter.netDark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion
Forounknownx.comDark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.
Forounknownnitter.netDark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1)

Sectores atacados

Technology (1)

Victimas (1)

UPS (China)9 Jul 2026
Reference China Technology
Que es UPS (China) es un actor APT (Advanced Persistent Threat) asociado a China, conocido por su actividad de ciberataque con múltiples alias y conex…