Ransomware Group intelligence

Apt73

Inactive

Track Apt73 with 79 published victims and 11 known leak locations in a single intelligence view.

Victims 79 Known published victims in this dataset
First discovered 2024-04-22 Earliest victim discovery date
Last discovered 2025-02-25 Latest victim discovery date
Inactive since 426 days Days since the latest known victim
Top country United Kingdom 14 victims
Known locations 11 Leak or negotiation infrastructure tracked

Overview

Apt73 is tracked by Breach House as a ransomware group with 79 published victims.

United Kingdom is currently the most targeted country in this dataset.

11 known leak locations are currently associated with this group.

Top Countries

Interactive distribution based on the currently visible victims list.

Top Countries
Distribution

    Known Leak Locations (11)

    Label Type Availability Links
    Leak location 1 Web location Unknown eraleignews.com
    Leak location 2 Onion service Unknown wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
    Leak location 3 Onion service Unknown fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion
    Leak location 4 Onion service Unknown apt73grpjgjwykrenq7vnjejue76vosdzptdvmonv7vyqnsyokrw57ad.onion
    Leak location 5 Onion service Unknown bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
    Leak location 6 Onion service Unknown basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
    Leak location 7 Onion service Unknown basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
    Leak location 8 Onion service Unknown basherykagbxoaiaxkgqhmhd5gbmedwb3di4ig3ouovziagosv4n77qd.onion
    Leak location 9 Onion service Unknown basherykagbxoaiaxkgqhmhd5gbmedwb3di4ig3ouovziagosv4n77qd.onion
    Leak location 10 Onion service Unknown bashete63b3gcijfofpw6fmn3rwnmyi5aclp55n6awcfbexivexbhyad.onion
    Leak location 11 Onion service Unknown bashex7mokreyoxl6wlswxl4foi7okgs7or7aergnuiockuoq35yt3ad.onion

    Top Activity Sectors

    No sector intelligence available.

    Research Sources

    No external research sources linked yet.

    Victims (79)

    Search, filter and paginate the victim timeline for Apt73.

    Type Target Discovered Country Business Category Intel Link
    Ransomware tni.mil.id id17783 View details Indonesia Other
    Ransomware autogedal.ro id17616 View details Romania Transportation / Travel
    Ransomware boostheat.com id17231 View details France Manufacturing / Engineering
    Ransomware mistralsolutions.com id17174 View details India Services
    Ransomware India car owners id17173 View details India Telecommunications
    Ransomware coel.com.mx id17125 View details Mexico Communication / Marketing
    Ransomware realtaxcanada.com id17121 View details Canada Finance / Legal / Insurance
    Ransomware ome.tv id17014 View details Türkiye Other
    Ransomware icicibank.com id16739 View details India Finance / Legal / Insurance
    Ransomware malindoair.com id16727 View details Malaysia Transportation / Travel
    Ransomware fol-23.fr id16704 View details France NGOs / Associations
    Ransomware betclic.com id16666 View details Malta Public Sector
    Ransomware pnp.co.za id16557 View details South Africa Retail / E-commerce
    Ransomware federalbank.co.in (PART1) id16313 View details India Finance / Legal / Insurance
    Ransomware n4telecom.com.br id16293 View details Brazil Telecommunications
    Ransomware linebank.co.id id16292 View details Indonesia Finance / Legal / Insurance
    Ransomware federalbank.co.in id16206 View details India Finance / Legal / Insurance
    Ransomware bri.co.id id16163 View details Indonesia Finance / Legal / Insurance
    Ransomware www.prixet.com id16108 View details Spain Communication / Marketing
    Ransomware www.minerasancristobal.com id15984 View details Bolivia, Plurinational State of Finance / Legal / Insurance
    Ransomware leadboxhq.com id15952 View details United States Communication / Marketing
    Ransomware melhorcompraclube.com.br id15931 View details Brazil Communication / Marketing
    Ransomware www.bms.com id15926 View details United States Healthcare / Pharma
    Ransomware bankily.mr id15925 View details Mauritania Finance / Legal / Insurance
    Ransomware azpay.me id15878 View details Azerbaijan Communication / Marketing
    Ransomware www.aliorbank.pl id15867 View details Poland Finance / Legal / Insurance
    Ransomware www.certifiedinfosec.com id15846 View details United States IT
    Ransomware www.siapenet.gov.br id15813 View details Brazil Finance / Legal / Insurance
    Ransomware www.sansirostadium.com id15770 View details Italy Other
    Ransomware www.polleninformation.at id15686 View details Austria Other
    Ransomware www.sella.eng.br id15660 View details Brazil Communication / Marketing
    Ransomware www.netromsoftware.ro id15629 View details Romania IT
    Ransomware www.protectasecurity.pe id15591 View details Peru Communication / Marketing
    Ransomware rao.hr id15590 View details Austria Communication / Marketing
    Ransomware sfr.fr id15589 View details France Telecommunications
    Ransomware gureco.pl id15588 View details Poland Communication / Marketing
    Ransomware lgpunjab.gov.in id15587 View details India Public Sector
    Ransomware nanolive.ch 2.0 id15285 View details Switzerland Services
    Ransomware emefarmario.com.br id15238 View details Brazil Agriculture / Food
    Ransomware liftkits4less.com id15230 View details United States Communication / Marketing
    Ransomware www.lamaisonducitron.com id15229 View details France Retail / E-commerce
    Ransomware www.baldinger-ag.ch id15228 View details Switzerland Other
    Ransomware www.assurified.com id15226 View details Netherlands Construction / Real Estate
    Ransomware www.botiga.com.uy id15225 View details Uruguay Retail / E-commerce
    Ransomware www.trinitesolutions.com id15041 View details Netherlands Services
    Ransomware www.scopeset.de id15040 View details Germany Services
    Ransomware sokkakreatif.com id15039 View details Indonesia Telecommunications
    Ransomware www.legilog.fr id15038 View details France Services
    Ransomware pkaufmann.com id14947 View details United States Communication / Marketing
    Ransomware modplan.co.uk id14946 View details United Kingdom Manufacturing / Engineering
    Ransomware hpecds.com id14945 View details United States Communication / Marketing
    Ransomware thompsoncreek.com id14941 View details Canada Communication / Marketing
    Ransomware www.northernsafety.com id14940 View details United States Telecommunications
    Ransomware mgfsourcing.com id14939 View details United States Retail / E-commerce
    Ransomware appen.com id14938 View details Australia Education
    Ransomware filmai.in id14937 View details India Other
    Ransomware drizly.com id14936 View details United States Retail / E-commerce
    Ransomware robinhood.com id14935 View details United States Other
    Ransomware thebeautyclick.co.uk id14934 View details United Kingdom Communication / Marketing
    Ransomware trans-logik.com id14933 View details United Kingdom Communication / Marketing
    Ransomware www.talonsolutions.co.uk id14932 View details United Kingdom Services
    Ransomware Sandro Forte Financial Support id14931 View details United Kingdom Finance / Legal / Insurance
    Ransomware Susan Fischgrund id14930 View details United States Other
    Ransomware nanolive.ch id14929 View details Switzerland Services
    Ransomware rylandpeters.com id13942 View details United Kingdom Retail / E-commerce
    Ransomware www.pindrophearing.co.uk id13919 View details United Kingdom Other
    Ransomware globacap.com id13910 View details United Kingdom Communication / Marketing
    Ransomware www.gannons.co.uk id13017 View details United Kingdom Finance / Legal / Insurance
    Ransomware Borrer Executive Search id13008 View details Switzerland Finance / Legal / Insurance
    Ransomware www.bigalsfoodservice.co.uk id13007 View details United Kingdom Agriculture / Food
    Ransomware apex.uk.net id12955 View details United Kingdom Manufacturing / Engineering
    Ransomware AlphaNovaCapital id12954 View details Hong Kong Communication / Marketing
    Ransomware AMI Global Assistance id12953 View details United Kingdom Services
    Ransomware brightwayconsultants.co.uk id12688 View details United Kingdom Communication / Marketing
    Ransomware fortify.pro id12384 View details Canada Communication / Marketing
    Ransomware www.servicepower.com id12250 View details United Kingdom Energy
    Ransomware www.credio.eu id12249 View details Czechia Services
    Ransomware melting-mind.de id12174 View details Germany Services
    Ransomware www.trifecta.com id12112 View details United States Other