Ransomware Group intelligence
Icefire
InactiveTrack Icefire with 11 published victims and 2 known leak locations in a single intelligence view.
Overview
Icefire is tracked by Breach House as a ransomware group with 11 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | kf6x3mjeqljqxjznaw65jixin7dpcunfxbbakwuitizytcpzn4iy5bad.onion |
| Leak location 2 | Onion service | Unknown | 7kstc545azxeahkduxmefgwqkrrhq3mzohkzqvrv7aekob7z3iwkqvyd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (11)
Search, filter and paginate the victim timeline for Icefire.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | *.algotrader.com id3985 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.bestservers.pro id3984 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.iperactive.com.ar id3983 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.cco1.com id3982 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.vps-vds.com id3981 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.guneshosting.com id3980 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.kodhosting.com id3979 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.kru.ac.th id3978 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.directfn.net id3977 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.feesh.ch id3976 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *.skifgroup.com id3975 View details | Services | — | ||
|
No additional victim description available. |
|||||