Skip to main content

Operator dossier

Sovcali is a ransomware operator currently active on public leak sites. Darkfield has indexed 6 public victims claimed by this operator between August 9, 2026 and August 24, 2026. Sovcali is a ransomware group first observed in August 2026 with an apparently financial motivation, though limited public documentation exists given its recent emergence and small known victim footprint. With only one confirmed victim recorded to date, the group remains obscure, and no attributions to a specific country of origin, threat actor collective, or ransomware-as-a-service infrastructure have been publicly documented by CISA, the FBI, Mandiant, or other reputable security research organizations at this time. What is known from available data is that Sovcali has demonstrated a targeting preference for the transportation sector within the United States, suggesting a degree of deliberate victim selection rather than opportunistic targeting, though the limited sample size makes definitive pattern analysis premature. No specific initial access vectors, encryption methods, extortion tactics, or toolsets have been publicly attributed to this group in open-source intelligence reporting. No notable high-profile campaigns, record ransoms, or law enforcement actions involving Sovcali have been publicly documented. Given its August 2026 first-observed date and minimal victim count, Sovcali should be considered an emerging and under-documented threat actor warranting continued monitoring as additional telemetry and reporting become available.

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status changes from active to dormant when no new disclosure appears for 60 days. Without a disclosure date, activity is unknown. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

Sovcali

6 victims indexed · first seen 1 month ago · last activity 21 days ago

6
Victims indexed
#270 of 399 tracked operators
<1m
Active period
Aug 2026 → Aug 2026
Countries hit

At a glance

Status
active
First seen
1 month ago
Last activity
21 days ago
Onion sites
1 known endpoint

About

Sovcali is a ransomware group first observed in August 2026 with an apparently financial motivation, though limited public documentation exists given its recent emergence and small known victim footprint. With only one confirmed victim recorded to date, the group remains obscure, and no attributions to a specific country of origin, threat actor collective, or ransomware-as-a-service infrastructure have been publicly documented by CISA, the FBI, Mandiant, or other reputable security research organizations at this time. What is known from available data is that Sovcali has demonstrated a targeting preference for the transportation sector within the United States, suggesting a degree of deliberate victim selection rather than opportunistic targeting, though the limited sample size makes definitive pattern analysis premature. No specific initial access vectors, encryption methods, extortion tactics, or toolsets have been publicly attributed to this group in open-source intelligence reporting. No notable high-profile campaigns, record ransoms, or law enforcement actions involving Sovcali have been publicly documented. Given its August 2026 first-observed date and minimal victim count, Sovcali should be considered an emerging and under-documented threat actor warranting continued monitoring as additional telemetry and reporting become available.

Recent victims

  • Loading recent victims

Onion infrastructure

1 known
  • http://z3mojpjnxt5tgqvu4wgosihl7pxvrcbyjcgquw2bwkyye5gwbhnf4kqd.onion

Source

Updated 21 days ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Sovcali posts a victim.

Add Sovcali to your watchlist — Pro pings you within 5 minutes of any new Sovcali leak-site post, Telegram callout, or affiliate-rebrand inference.