Skip to main content

Operator dossier

raworld is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 112 public victims claimed by this operator between May 6, 2023 and December 28, 2024. Raworld is a relatively new ransomware group that emerged in May 2023, operating with primarily financial motivations and demonstrating a broad international targeting approach. The group's origin and specific affiliations remain unclear based on publicly available information, though their targeting patterns suggest they may operate independently rather than as part of a larger ransomware-as-a-service ecosystem. Limited public documentation exists regarding their specific attack methodologies, though their victim profile spanning multiple sectors including business services, technology, manufacturing, and healthcare suggests they likely employ opportunistic targeting rather than highly specialized initial access vectors. With 112 documented victims across major economies including Germany, the United States, United Kingdom, France, and Italy, Raworld has demonstrated significant operational capability despite their recent emergence, though specific details about notable high-profile attacks or law enforcement disruption efforts have not been widely reported by major threat intelligence organizations. As of current reporting, the group appears to remain active, though the limited public intelligence available makes definitive assessment of their operational status challenging.

Most-targeted sectors

Most-affected countries

Recent disclosures by raworld

Most recent 30 of 112 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for raworld

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

raworld

112 victims indexed · first seen 3 years ago · last activity 1 year ago

112
Victims indexed
#67 of 356 tracked operators
1y 7m
Active period
May 2023 → Dec 2024
10
Countries hit
top DE · 11

At a glance

Status
inactive
First seen
3 years ago
Last activity
1 year ago
Onion sites
1 known endpoint
Primary sector
Not Found · 20 hits

About

Raworld is a relatively new ransomware group that emerged in May 2023, operating with primarily financial motivations and demonstrating a broad international targeting approach. The group's origin and specific affiliations remain unclear based on publicly available information, though their targeting patterns suggest they may operate independently rather than as part of a larger ransomware-as-a-service ecosystem. Limited public documentation exists regarding their specific attack methodologies, though their victim profile spanning multiple sectors including business services, technology, manufacturing, and healthcare suggests they likely employ opportunistic targeting rather than highly specialized initial access vectors. With 112 documented victims across major economies including Germany, the United States, United Kingdom, France, and Italy, Raworld has demonstrated significant operational capability despite their recent emergence, though specific details about notable high-profile attacks or law enforcement disruption efforts have not been widely reported by major threat intelligence organizations. As of current reporting, the group appears to remain active, though the limited public intelligence available makes definitive assessment of their operational status challenging.

Timeline

15 months
2023-05-01T00:00:00+00:00 · 52023-06-01T00:00:00+00:00 · 32023-07-01T00:00:00+00:00 · 52023-08-01T00:00:00+00:00 · 62023-09-01T00:00:00+00:00 · 72023-11-01T00:00:00+00:00 · 82023-12-01T00:00:00+00:00 · 52024-03-01T00:00:00+00:00 · 102024-04-01T00:00:00+00:00 · 192024-05-01T00:00:00+00:00 · 52024-07-01T00:00:00+00:00 · 52024-08-01T00:00:00+00:00 · 12024-10-01T00:00:00+00:00 · 102024-11-01T00:00:00+00:00 · 102024-12-01T00:00:00+00:00 · 13
2023-05-01T00:00:00+00:002024-12-01T00:00:00+00:00

Top countries

🇩🇪 Germany
11
🇺🇸 United States
9
🇬🇧 United Kingdom
3
🇫🇷 France
2
🇮🇹 Italy
2
🇦🇪 United Arab Emirates
2
🇮🇳 India
1
🇦🇹 Austria
1

Top sectors

Business Services
11
Technology
10
Manufacturing
9
Healthcare
4
Transportation/Logistics
3
Energy
3
Financial
2
Agriculture and Food Production
2

MITRE ATT&CK

5 techniques · 4 tactics

Tactics

Initial AccessExecutionDefense EvasionImpact

Techniques

  • T1566Phishing
  • T1190Exploit Public-Facing Application
  • T1059Command and Scripting Interpreter
  • T1027Obfuscated Files or Information
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion

Source

Updated 1 year ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time raworld posts a victim.

Add raworld to your watchlist — Pro pings you within 5 minutes of any new raworld leak-site post, Telegram callout, or affiliate-rebrand inference.