Ransomware Group intelligence

Underground

Inactive

Track Underground with 26 published victims and 2 known leak locations in a single intelligence view.

Victims 26 Known published victims in this dataset
First discovered 2024-05-01 Earliest victim discovery date
Last discovered 2025-08-15 Latest victim discovery date
Inactive since 253 days Days since the latest known victim
Top country United States 6 victims
Known locations 2 Leak or negotiation infrastructure tracked

Overview

Underground is tracked by Breach House as a ransomware group with 26 published victims.

United States is currently the most targeted country in this dataset.

2 known leak locations are currently associated with this group.

Top Countries

Interactive distribution based on the currently visible victims list.

Top Countries
Distribution

    Known Leak Locations (2)

    Label Type Availability Links
    Leak location 1 Onion service Unknown undgrddapc4reaunnrdrmnagvdelqfvmgycuvilgwb5uxm25sxawaoqd.onion
    Leak location 2 Onion service Unknown 47glxkuxyayqrvugfumgsblrdagvrah7gttfscgzn56eyss5wg3uvmqd.onion

    Top Activity Sectors

    No sector intelligence available.

    Research Sources

    No external research sources linked yet.

    Victims (26)

    Search, filter and paginate the victim timeline for Underground.

    Type Target Discovered Country Business Category Intel Link
    Ransomware SFA Engineering id21754 View details Korea, Republic of Manufacturing / Engineering
    Ransomware GMORS Co., Ltd id20819 View details Taiwan, Province of China Manufacturing / Engineering
    Ransomware Afa Systems Ltd. id19191 View details Canada Services
    Ransomware shengyusteel.com id19190 View details Taiwan, Province of China Manufacturing / Engineering
    Ransomware semex.com id19189 View details Canada Other
    Ransomware Simmtech Co., Ltd. id16104 View details Korea, Republic of IT
    Ransomware hcsgcorp.com id14983 View details United States Services
    Ransomware Casio Computer Co., Ltd id14712 View details Japan IT
    Ransomware ramservices.com id13246 View details Services
    Ransomware Ethypharm id13218 View details France Other
    Ransomware A-Line Staffing Solutions id13053 View details Services
    Ransomware belcherpharma.com id12972 View details United States Healthcare / Pharma
    Ransomware CentralSecurities.com id12951 View details Other
    Ransomware www.belcherpharma.com id12602 View details United States Healthcare / Pharma
    Ransomware kc.co.kr id12261 View details Korea, Republic of Other
    Ransomware bulldogbag.com id12227 View details Canada Other
    Ransomware frenckengroup.com id12226 View details Singapore Services
    Ransomware synology.com id12225 View details Germany Other
    Ransomware tpa-group.sk id12224 View details Slovakia Services
    Ransomware Triathlon.group id12223 View details Germany Services
    Ransomware awwg.com id12222 View details Spain Other
    Ransomware KyungChang id12221 View details Other
    Ransomware Y. Hata & Co., Ltd. id12220 View details United States Services
    Ransomware Skender Construction id12219 View details United States Construction / Real Estate
    Ransomware Creative Business Interiors id12218 View details United States Communication / Marketing
    Ransomware cochraneglobal.com id12217 View details United Arab Emirates Services