Skip to main content

Operator dossier

Section9 is a ransomware operator currently active on public leak sites. Darkfield has indexed 13 public victims claimed by this operator between July 26, 2026 and July 29, 2026. Section9 is a ransomware group first observed in July 2026 with an apparent primary motivation of financial gain, though limited public documentation exists given the group's relatively recent emergence and modest operational footprint. With only 12 known victims recorded, Section9 remains a low-to-moderate threat actor that has not yet attracted significant public reporting from major threat intelligence organizations such as CISA, FBI, or Mandiant, and as such its origin, affiliation, and operational structure — including whether it operates as a RaaS platform or as an independent closed group — cannot be confirmed with available open-source information. Targeting patterns indicate a geographically diverse victim set spanning Brazil, China, Sweden, Portugal, and the United States, suggesting the group does not restrict operations to a single region or geopolitical bloc, which may indicate financially motivated opportunistic targeting rather than a state-directed or politically motivated campaign. Victimology spans multiple sectors including Financial Services, Technology, Agriculture and Food Production, Retail and E-Commerce, and Hospitality, a breadth of targeting that is consistent with opportunistic ransomware operations rather than a specialized or highly selective threat actor. No notable high-profile campaigns, record ransom demands, or law enforcement actions against Section9 have been publicly documented as of the time of this writing, and the group's current operational status cannot be definitively assessed pending further reporting from authoritative cybersecurity and law enforcement sources.

Most-targeted sectors

Most-affected countries

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

Section9

13 victims indexed · first seen 3 days ago · last activity 4 hours ago

13
Victims indexed
#200 of 369 tracked operators
<1m
Active period
Jul 2026 → Jul 2026
9
Countries hit
top BR · 3

At a glance

Status
active
First seen
3 days ago
Last activity
4 hours ago
Onion sites
1 known endpoint
Primary sector
Financial Services · 3 hits

About

Section9 is a ransomware group first observed in July 2026 with an apparent primary motivation of financial gain, though limited public documentation exists given the group's relatively recent emergence and modest operational footprint. With only 12 known victims recorded, Section9 remains a low-to-moderate threat actor that has not yet attracted significant public reporting from major threat intelligence organizations such as CISA, FBI, or Mandiant, and as such its origin, affiliation, and operational structure — including whether it operates as a RaaS platform or as an independent closed group — cannot be confirmed with available open-source information. Targeting patterns indicate a geographically diverse victim set spanning Brazil, China, Sweden, Portugal, and the United States, suggesting the group does not restrict operations to a single region or geopolitical bloc, which may indicate financially motivated opportunistic targeting rather than a state-directed or politically motivated campaign. Victimology spans multiple sectors including Financial Services, Technology, Agriculture and Food Production, Retail and E-Commerce, and Hospitality, a breadth of targeting that is consistent with opportunistic ransomware operations rather than a specialized or highly selective threat actor. No notable high-profile campaigns, record ransom demands, or law enforcement actions against Section9 have been publicly documented as of the time of this writing, and the group's current operational status cannot be definitively assessed pending further reporting from authoritative cybersecurity and law enforcement sources.

Timeline

1 months
2026-07-01T00:00:00+00:00 · 12
2026-07-01T00:00:00+00:002026-07-01T00:00:00+00:00

Top countries

🇧🇷 Brazil
3
🇨🇳 China
1
🇸🇪 Sweden
1
🇵🇹 Portugal
1
🇺🇸 United States
1
Monaco
1
🇫🇷 France
1
🇯🇵 Japan
1

Top sectors

Financial Services
3
Technology
2
Agriculture and Food Production
2
Retail & E-Commerce
1
Hospitality
1
Healthcare
1
Education
1

MITRE ATT&CK

14 techniques · 8 tactics

Tactics

Initial AccessExecutionPersistenceDefense EvasionDiscoveryCollectionExfiltrationImpact

Techniques

  • T1190Exploit Public-Facing Application
  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1106Native API
  • T1543Create or Modify System Process
  • T1112Modify Registry
  • T1562Impair Defenses
  • T1083File and Directory Discovery
  • T1082System Information Discovery
  • T1057Process Discovery
  • T1074Data Staged
  • T1041Exfiltration Over C2 Channel
  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery

Recent victims

Loading…

Onion infrastructure

1 known
  • http://v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion

Source

Updated 4 hours ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Section9 posts a victim.

Add Section9 to your watchlist — Pro pings you within 5 minutes of any new Section9 leak-site post, Telegram callout, or affiliate-rebrand inference.