ULose is a ransomware operator currently active on public leak sites. Darkfield has indexed 5 public victims claimed by this operator between June 9, 2026. ULose is a ransomware group first observed in June 2026 with an assessed primary motivation of financial gain, operating against a limited but targeted victim set of five known organizations. Based on available data, the group has concentrated its operations against South Korea, with targeting patterns spanning the Financial Services, Manufacturing, and Healthcare sectors, suggesting a deliberate focus on high-value industries where operational disruption and data sensitivity may increase victim willingness to pay. Due to the group's recent emergence and limited victim count, no comprehensive public reporting from CISA, FBI, Mandiant, or equivalent threat intelligence authorities has been documented at this time, and attribution regarding country of origin, RaaS affiliation, specific tooling, or initial access vectors cannot be responsibly stated beyond what the available telemetry reflects. No notable high-profile campaigns, record ransom demands, or law enforcement actions against ULose have been publicly recorded, which is consistent with a nascent or low-volume threat actor that may be in early operational stages, deliberately maintaining a low profile, or operating beneath the threshold that typically triggers formal advisories. The group's current status remains active as of its first observed date, though its trajectory, longevity, and potential rebranding activity should be monitored given the sensitive nature of its targeted sectors.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.