Active ransomware operator
← All groupsRagroup
aka ra group · 0 victims indexed · last activity 1 year ago
At a glance
- Status
- active
- Aliases
- ra group
- First seen
- —
- Last activity
- 1 year ago
- Onion sites
- 4 known endpoints
About
References
1 linkExternal sources curated by the MISP threat-intel community.
Recent victims
Loading…
Onion infrastructure
4 known- http://pa32ymaeu62yo5th5mraikgw5fcvznnsiiwti42carjliarodltmqcqd.onion
- http://raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion
- http://raworlddecssyq43oim3hxhc5oxvlbaxuj73xbz2pbbowso3l4kn27qd.onion
- http://hkpomcx622gnqp2qhenv4ceyrhwvld3zwogr4mnkdeudq2txf55keoad.onion
Source
Updated 1 year agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
