nasirsecurity is an obscure ransomware group first observed in October 2025 with very limited documented activity, appearing to operate with financial motivations based on a single recorded victim. The group's origin and potential affiliations remain unknown, with insufficient public data to determine whether they operate as part of a Ransomware-as-a-Service model or as an independent entity. Their attack methodology, encryption techniques, and initial access vectors have not been publicly documented by major cybersecurity firms or law enforcement agencies, though their targeting appears geographically focused on Israel within the technology sector. No notable high-profile campaigns, significant ransom demands, or law enforcement actions have been publicly reported in connection with this group by CISA, FBI, Mandiant, or other reputable security researchers. Given the extremely limited victim count and lack of subsequent reporting, the current operational status of nasirsecurity remains unclear, though their minimal footprint suggests either very recent emergence, limited capabilities, or potential early-stage operations. The group has been linked to 1 public disclosures across our corpus. First observed on a leak site on October 12, 2025. The operation is currently inactive.
Also tracked as: nasir security.
Sector and geography
This disclosure adds to ransomware activity in the Technology sector, which has 2,524 disclosures indexed across all operators we track. Geographically, Taldor is reported in Israel, a country with 78 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.