Skip to main content

Operator dossier

Losttrust (also tracked as LOST TRUST) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 53 public victims claimed by this operator between September 26, 2023. Losttrust is a relatively new ransomware group that emerged in September 2023, operating with apparent financial motivations and demonstrating a broad international targeting scope across multiple sectors. The group's origin and affiliations remain largely undocumented by major threat intelligence organizations, with limited public reporting from established security firms regarding their operational structure or potential ransomware-as-a-service connections. Based on available victim data, Losttrust appears to employ opportunistic targeting methods, having compromised 53 known victims across diverse geographic regions including the United States, Italy, Germany, Argentina, and India, with particular focus on education, legal services, media organizations, food and agriculture companies, and government entities. The specific attack methodologies, initial access vectors, encryption techniques, and extortion tactics employed by Losttrust have not been extensively documented in public threat intelligence reports from major security vendors or law enforcement agencies. Given the group's recent emergence and limited visibility in established threat intelligence channels, their current operational status and activity levels remain unclear, though the breadth of their reported victim base suggests ongoing operations as of recent observations.

Most-targeted sectors

Most-affected countries

Recent disclosures by Losttrust

All 53 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Losttrust

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Losttrust

aka LOST TRUST · 53 victims indexed · first seen 3 years ago · last activity 3 years ago

53
Victims indexed
#105 of 370 tracked operators
<1m
Active period
Sep 2023 → Sep 2023
11
Countries hit
top United States · 38

At a glance

Status
inactive
Aliases
LOST TRUST
First seen
3 years ago
Last activity
3 years ago
Onion sites
1 known endpoint
Primary sector
Manufacturing · 8 hits

About

Losttrust is a relatively new ransomware group that emerged in September 2023, operating with apparent financial motivations and demonstrating a broad international targeting scope across multiple sectors. The group's origin and affiliations remain largely undocumented by major threat intelligence organizations, with limited public reporting from established security firms regarding their operational structure or potential ransomware-as-a-service connections. Based on available victim data, Losttrust appears to employ opportunistic targeting methods, having compromised 53 known victims across diverse geographic regions including the United States, Italy, Germany, Argentina, and India, with particular focus on education, legal services, media organizations, food and agriculture companies, and government entities. The specific attack methodologies, initial access vectors, encryption techniques, and extortion tactics employed by Losttrust have not been extensively documented in public threat intelligence reports from major security vendors or law enforcement agencies. Given the group's recent emergence and limited visibility in established threat intelligence channels, their current operational status and activity levels remain unclear, though the breadth of their reported victim base suggests ongoing operations as of recent observations.

References

1 link

External sources curated by the MISP threat-intel community.

Timeline

1 months
2023-09-01T00:00:00+00:00 · 53
2023-09-01T00:00:00+00:002023-09-01T00:00:00+00:00

Top countries

🇺🇸 United States
38
🇮🇹 Italy
4
🇦🇷 Argentina
2
🇨🇦 Canada
2
🇲🇽 Mexico
1
🇬🇧 United Kingdom
1
🇮🇳 India
1
🇸🇪 Sweden
1

Top sectors

Manufacturing
8
Business Services
6
Education
5
Legal
5
Construction
4
Government
4
Technology
3
Food & Agriculture
3

MITRE ATT&CK

4 techniques · 4 tactics

Tactics

Initial AccessExecutionDefense EvasionImpact

Techniques

  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1027Obfuscated Files or Information
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://hscr6cjzhgoybibuzn2xud7u4crehuoo4ykw3swut7m7irde74hdfzyd.onion

Source

Updated 3 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Losttrust posts a victim.

Add Losttrust to your watchlist — Pro pings you within 5 minutes of any new Losttrust leak-site post, Telegram callout, or affiliate-rebrand inference.