underground
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
| Name | Country | Sector | Date |
|---|---|---|---|
| SFA Engineering | KR | Technology | 2025-08-15T14:03:57.684917+00:00 |
| GMORS Co., Ltd | TW | Manufacturing | 2025-06-25T09:41:20.003218+00:00 |
| Afa Systems Ltd. | CA | Technology | 2025-04-16T12:55:00.212515+00:00 |
| shengyusteel.com | TW | Manufacturing | 2025-04-16T12:53:45.678509+00:00 |
| semex.com | CA | Agriculture and Food Production | 2025-04-16T12:52:15.668886+00:00 |
| Simmtech Co., Ltd. | KR | Technology | 2024-12-16T13:58:25.740059+00:00 |
| hcsgcorp.com | US | Healthcare | 2024-10-25T13:23:10.927257+00:00 |
| Casio Computer Co., Ltd | JP | Technology | 2024-10-10T07:38:43.242671+00:00 |
| ramservices.com | US | Business Services | 2024-07-03T13:48:07.475213+00:00 |
| Ethypharm | FR | Healthcare | 2024-07-01T16:54:50.394949+00:00 |
| A-Line Staffing Solutions | US | Healthcare | 2024-06-17T16:24:21.043675+00:00 |
| belcherpharma.com | US | Healthcare | 2024-06-12T15:56:49.516959+00:00 |
| CentralSecurities.com | US | Financial Services | 2024-06-11T05:28:38.560252+00:00 |
| www.belcherpharma.com | US | Healthcare | 2024-05-17T18:44:32.187550+00:00 |
| kc.co.kr | KR | Technology | 2024-05-03T08:23:30.888871+00:00 |
| bulldogbag.com | CA | Manufacturing | 2024-05-01T14:14:37.825389+00:00 |
| frenckengroup.com | SG | Manufacturing | 2024-05-01T14:13:43.215817+00:00 |
| synology.com | DE | Technology | 2024-05-01T14:12:41.106723+00:00 |
| tpa-group.sk | SK | Business Services | 2024-05-01T14:11:27.968531+00:00 |
| Triathlon.group | DE | Transportation/Logistics | 2024-05-01T14:10:09.055259+00:00 |
| awwg.com | ES | Business Services | 2024-05-01T14:09:12.101215+00:00 |
| KyungChang | — | Manufacturing | 2024-05-01T14:08:00.718847+00:00 |
| Y. Hata & Co., Ltd. | US | Agriculture and Food Production | 2024-05-01T14:07:12.791127+00:00 |
| Skender Construction | US | Business Services | 2024-05-01T14:06:26.594344+00:00 |
| Creative Business Interiors | US | Business Services | 2024-05-01T14:05:26.904859+00:00 |
| cochraneglobal.com | AE | Technology | 2024-05-01T14:04:52.774711+00:00 |
Data from ransomware.live