ULose is a ransomware operator with no recorded disclosures in the past 60 days. Darkfield has indexed 5 public victims claimed by this operator between June 9, 2026. ULose is a ransomware group first observed in June 2026 with an assessed primary motivation of financial gain, operating against a limited but targeted victim set of five known organizations. Based on available data, the group has concentrated its operations against South Korea, with targeting patterns spanning the Financial Services, Manufacturing, and Healthcare sectors, suggesting a deliberate focus on high-value industries where operational disruption and data sensitivity may increase victim willingness to pay. Due to the group's recent emergence and limited victim count, no comprehensive public reporting from CISA, FBI, Mandiant, or equivalent threat intelligence authorities has been documented at this time, and attribution regarding country of origin, RaaS affiliation, specific tooling, or initial access vectors cannot be responsibly stated beyond what the available telemetry reflects. No notable high-profile campaigns, record ransom demands, or law enforcement actions against ULose have been publicly recorded, which is consistent with a nascent or low-volume threat actor that may be in early operational stages, deliberately maintaining a low profile, or operating beneath the threshold that typically triggers formal advisories. The group's current status remains active as of its first observed date, though its trajectory, longevity, and potential rebranding activity should be monitored given the sensitive nature of its targeted sectors.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status changes from active to dormant when no new disclosure appears for 60 days. Without a disclosure date, activity is unknown. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.