Ransomware Group intelligence
Emperador
ActiveTrack Emperador with 67 published victims and 1 known leak locations in a single intelligence view.
Overview
Emperador is tracked by Dark Eye as a ransomware group with 67 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 8 44.4%
- Pending 9 50.0%
- Deleted 1 5.6%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 2h ago | emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Emperador, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: emporador executes PowerShell scripts to automate credential access and system reconnaissance.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: emporador persists via Registry Run Keys to ensure recurring execution after reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: emporador disables security tools by terminating or modifying antivirus and monitoring utilities.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: emporador deletes Volume Shadow Copies and backup directories to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: emporador performs remote system discovery to identify additional victims within the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: emporador discovers system network connections to locate exposed services for exploitation.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1083 File and Directory Discovery Discovery
What they do: emporador uses file and directory discovery to enumerate user data and system paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: emporador moves laterally through SMB/Windows Admin Shares to compromise additional hosts.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: emporador encrypts victim files using its ransomware payload to hold data hostage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: emporador inhibits system recovery by corrupting restore points and disabling backup services.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (67)
Search, filter and paginate the victim timeline for Emperador. Showing 1–67 of 67.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Navitrans id32799 View details | United States | Transportation / Travel / Logistics | pending | ||
|
Navitrans is a leading Colombian distributor and service provider specializing in commercial trucks and heavy machinery, offering a comprehensive range of products and services including vehicle sales, spare parts distribution, and maintenance and repair services through a nationwide network of workshops. This post includes sensitive data about prices, financing, and other operational information. [Size: 223.2 MB | Sector: Manufacturing, Transportation] |
||||||
| Ransomware | Nexbex Solutions Private Limited id32786 View details | India | IT | pending | ||
|
Nexbex Solutions Private Limited operates within the information technology sector, based in India, providing technology-focused services and solutions to clients. As documented in this threat-intelligence index, the entity is classified as a ransomware victim associated with the emperador threat actor. The listing reflects cybersecurity intelligence concerning this organization's involvement with the identified threat actor without disclosing unverified incident details. This entry serves to inform security teams and analysts about the entity's status within the ransomware threat landscape. The classification underscores the importance of monitoring such entities for potential risk assessment and incident response planning. |
||||||
| Ransomware | Nexbex Solutions Private Limited id32786 View details | India | IT | pending | ||
|
Nexbex Solutions Private Limited is a technology consulting and software engineering firm incorporated in November 2023, headquartered in Malappuram, Kerala (India). Classified as an emerging private company, it operates with a paid-up capital of 10 million Indian rupees (₹10 Lakhs) and a compact team, generating estimated annual revenue of less than $1.2 million USD. Its core business focuses on computer programming, custom mobile application development (such as its corporate loyalty platforms Nexi Paints and Grace Petroleum), and digital solutions for retail automation, e-commerce, and smart lead management for growing small and medium-sized enterprises. We have access to all their databases with their clients' sensitive data, which include names, emails, phone numbers, addresses, etc. 600 MB. Domains: club7ms.com, rayssportsnetwork.com, hwzthat.com, etc. Subdomains Type staging, edmontoneagles, masc, psca, live, kkr, victoriapark, staging.victoriapark, spartans, blaze, ramblers, eagle admin.bookings-staging, backend.academy, admin.spike.booking, etc. We have the source code for all 200+ of their projects. 10 GB +. going up. [Size: 600.0 MB | Sector: Technology] |
||||||
| Ransomware | Nexbex Solutions Private Limited id32788 View details | India | IT | pending | ||
|
Nexbex Solutions Private Limited operates within the IT sector, providing technology-focused services and solutions to clients. As a ransomware victim, the entity is documented within this threat-intelligence index in association with the threat actor emperador. The listing type identifies Nexbex Solutions Private Limited as having been impacted by ransomware activity linked to this specific threat actor. This entry serves to inform security analysts and stakeholders about affected entities within the IT domain, contributing to broader threat landscape awareness without disclosing unverified incident details or specifics of the attack. |
||||||
| Ransomware | Nexbex Solutions Private Limited id32786 View details | India | IT | pending | ||
|
Nexbex Solutions Private Limited is a technology consulting and software engineering firm incorporated in November 2023, headquartered in Malappuram, Kerala (India). Classified as an emerging private company, it operates with a paid-up capital of 10 million Indian rupees (₹10 Lakhs) and a compact team, generating estimated annual revenue of less than $1.2 million USD. Its core business focuses on computer programming, custom mobile application development (such as its corporate loyalty platforms Nexi Paints and Grace Petroleum), and digital solutions for retail automation, e-commerce, and smart lead management for growing small and medium-sized enterprises. We have access to all their databases with their clients' sensitive data, which include names, emails, phone numbers, addresses, etc. 600 MB. Domains: club7ms.com, rayssportsnetwork.com, hwzthat.com, etc. Subdomains Type staging, edmontoneagles, masc, psca, live, kkr, victoriapark, staging.victoriapark, spartans, blaze, ramblers, eagle admin.bookings-staging, backend.academy, admin.spike.booking, etc. We have the source code for all 200+ of their projects. 10 GB +. going up. [Size: 600.0 MB | Sector: Technology] |
||||||
| Ransomware | EASY JOB S.A.S. id32730 View details | Colombia | Services | pending | ||
|
easyjobsas.com operates within the Services sector and is geographically associated with Colombia. The entity functions as a professional services provider, offering services relevant to its operational domain. Within the threat-intelligence catalog, easyjobsas.com is formally categorized as a ransomware victim linked to the emperador threat actor. This classification reflects its documented presence in intelligence records tied to this specific adversary group. The entry serves as a reference point for monitoring security implications across the Services sector in the specified geographic region. |
||||||
| Ransomware | EASY JOB S.A.S. id32730 View details | Colombia | Services | pending | ||
|
Colombian Company. Audit and Tax Audit with more than 5 years of experience Calle 17 sur 44 - 159 Oficina 1501 EDIFICIO CLAROSCURO, Medellín Colombia. Llámanos o escríbenos: 310 447 2013 - 313 796 9917 The archives contain personal data of employees and customers of the company, tax documents, databases and other important documents 17000 documents [Size: 2.7 GB | Sector: Finance] |
||||||
| Ransomware | EASY JOB S.A.S. id32789 View details | Colombia | Services | pending | ||
|
easyjobsas.com operates within the Services sector and is associated with the threat actor emperador in this ransomware victim listing. The entity's location is Colombia (country code CO), aligning with its service-oriented business profile. This catalog entry documents the association without disclosing specific incident details, as confirmed by the threat-intelligence index methodology. The listing type identifies easyjobsas.com as a ransomware victim connected to emperador, providing neutral context for threat analysts and security teams monitoring active campaigns. All information reflects verified index data and avoids speculation regarding breach mechanics or impact. |
||||||
| Ransomware | EASY JOB S.A.S. id32730 View details | Colombia | Services | pending | ||
|
Colombian Company. Audit and Tax Audit with more than 5 years of experience Calle 17 sur 44 - 159 Oficina 1501 EDIFICIO CLAROSCURO, Medellín Colombia. Llámanos o escríbenos: 310 447 2013 - 313 796 9917 The archives contain personal data of employees and customers of the company, tax documents, databases and other important documents 17000 documents [Size: 2.7 GB | Sector: Finance] |
||||||
| Ransomware | Bosnia and Herzegovina Mine Action Center id32710 View details | Bosnia and Herzegovina | NGOs / Associations | pending | ||
|
The Bosnia and Herzegovina Mine Action Center is an organization operating within the NGO and associations sector in Bosnia and Herzegovina. It provides specialized mine action services, supporting demining operations, safety protocols, and humanitarian coordination related to hazardous land remediation. As a ransomware victim entity, it is documented within the threat-intelligence index under association with the threat actor emperador. The listing reflects the cybersecurity context of this organization without disclosing unverified incident details, data scope, or operational specifics. This entry serves catalog and analytical purposes for monitoring threat actor activity across vulnerable sectors. |
||||||
| Ransomware | Bosnia and Herzegovina Mine Action Center id32710 View details | Bosnia and Herzegovina | NGOs / Associations | pending | ||
|
important documents [Size: 1.7 GB | Sector: Other] |
||||||
| Ransomware | Bosnia and Herzegovina Mine Action Center id32790 View details | Bosnia and Herzegovina | NGOs / Associations | pending | ||
|
The Bosnia and Herzegovina Mine Action Center is an organization operating within the NGO and associations sector in Bosnia and Herzegovina. It provides mine action support, safety coordination, and related humanitarian or operational services focused on hazardous mine environments and community protection. As a ransomware victim listing, this entity is documented within the threat-intelligence index in connection with the threat actor emperador. The record reflects its association with this actor and its status as a victim entity without disclosing unverified technical, financial, or data-specific incident details. This entry supports threat-intel cataloging for sector-aware analysis of ransomware impacts across international organizations. |
||||||
| Ransomware | Bosnia and Herzegovina Mine Action Center id32710 View details | Bosnia and Herzegovina | NGOs / Associations | pending | ||
|
important documents [Size: 1.7 GB | Sector: Other] |
||||||
| Ransomware | Universal Starch-Chem Allied Ltd id32708 View details | India | Manufacturing / Engineering | pending | ||
|
Universal Starch-Chem Allied Ltd operates within the manufacturing and engineering sector, with operations associated with India. The entity represents a business organization whose security posture was impacted by a cyber incident. According to threat-intelligence index records, Universal Starch-Chem Allied Ltd is classified as a ransomware victim associated with the emperador threat actor or source. This listing reflects the entity's documented relationship to this threat actor within the intelligence catalog. No specific incident details, such as data stolen, ransom demands, or confirmed breach metrics, are asserted here, maintaining factual neutrality. |
||||||
| Ransomware | Universal Starch-Chem Allied Ltd id32708 View details | India | Manufacturing / Engineering | pending | ||
|
important documents [Size: 3.5 GB | Sector: Other] |
||||||
| Ransomware | Universal Starch-Chem Allied Ltd id32791 View details | India | Manufacturing / Engineering | pending | ||
|
Universal Starch-Chem Allied Ltd operates within the Manufacturing and Engineering sector, with operational presence in India. The entity is documented in the threat-intelligence index as a ransomware victim, specifically associated with the emperador threat actor. This listing type indicates a cybersecurity incident where the organization was targeted by ransomware activity attributable to emperador. The entry provides neutral context regarding the company's sector, geographic location, and its classification within the intelligence dataset. Universal Starch-Chem Allied Ltd was listed as a ransomware victim associated with emperador. |
||||||
| Ransomware | Universal Starch-Chem Allied Ltd id32708 View details | India | Manufacturing / Engineering | pending | ||
|
important documents [Size: 3.5 GB | Sector: Other] |
||||||
| Ransomware | BAYMER id32709 View details | United States | Healthcare / Pharma | pending | ||
|
Baymer operates within the United States healthcare and medicine sector, providing medical services and technology solutions focused on clinical workflows and patient care support. As a ransomware victim, Baymer is documented within this threat-intelligence index under association with the Emperador threat actor. The listing reflects the entity's exposure within the cybersecurity landscape and its categorization by sector, geographic location, and attack context. This entry serves to catalog the relationship between Baymer and the Emperador threat actor without disclosing unverified incident details. The record supports threat-intelligence analysis for healthcare organizations facing ransomware risks. |
||||||
| Ransomware | BAYMER id32709 View details | United States | Healthcare / Pharma | pending | ||
|
Important documents [Size: 1.4 GB | Sector: Other] |
||||||
| Ransomware | BAYMER id32792 View details | United States | Healthcare / Pharma | pending | ||
|
Baymer operates within the healthcare and medicine sector based in the United States, providing medical technology and related services to support clinical workflows and patient care. As a ransomware victim, Baymer is documented within this threat-intelligence index due to its association with the Emperador threat actor. This listing type contextualizes the entity's exposure within cybersecurity threat landscapes affecting critical infrastructure sectors. The entry reflects verified intelligence linking Baymer to Emperador activity without disclosing unconfirmed breach details, operational impacts, or speculative claims. Understanding such associations aids security teams in threat modeling, sector-specific defense strategies, and awareness of evolving ransomware campaigns targeting healthcare organizations. |
||||||
| Ransomware | BAYMER id32709 View details | United States | Healthcare / Pharma | pending | ||
|
Important documents [Size: 1.4 GB | Sector: Other] |
||||||
| Ransomware | Judicial Branch of the Province of Jujuy id32591 View details | Argentina | Public Sector | pending | ||
|
The Judicial Branch of the Province of Jujuy is a public-sector entity located in the Indian state of Jujuy, functioning within the judicial administration of the province. It provides core legal and judicial services, including civil and criminal case adjudication, legal oversight, and public legal representation for residents within its jurisdiction. As a Public Sector organization in AR, it operates within sensitive governmental infrastructure and delivers essential services to the community. This entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor emperador. The listing reflects the observed relationship between this judicial institution and the identified ransomware campaign without disclosing unverified incident details. |
||||||
| Ransomware | Judicial Branch of the Province of Jujuy id32591 View details | Argentina | Public Sector | pending | ||
|
The official website of the Judicial Branch of Jujuy, Argentina. It provides court information, digital case management, mediation services, legal rulings, and judicial news for legal professionals and the public. Now i have your wordpress databases, login credentials to internal systems(thanks to marcos :)), as well as your email credentials Respond to us, pay the ransom.(Check your emails & check spam as well.) [Size: 4.2 GB | Sector: Government, Law] |
||||||
| Ransomware | Judicial Branch of the Province of Jujuy id32794 View details | Argentina | Public Sector | pending | ||
|
The Judicial Branch of the Province of Jujuy is a public sector entity located in the state of Jujuy within the country of Argentina (AR). Its core functions encompass judicial administration, legal adjudication, court operations, and enforcement of regional and national laws within the province. As a critical component of the public administration infrastructure, this branch provides essential legal services and maintains governance frameworks for its jurisdiction. According to the threat-intelligence index, this entity was formally listed as a ransomware victim associated with the emperador threat actor. This listing reflects its documented involvement within the observed cyber incident, underscoring vulnerabilities within public sector digital environments targeted by this specific adversary group. |
||||||
| Ransomware | Judicial Branch of the Province of Jujuy id32591 View details | Argentina | Public Sector | pending | ||
|
The official website of the Judicial Branch of Jujuy, Argentina. It provides court information, digital case management, mediation services, legal rulings, and judicial news for legal professionals and the public. Now i have your wordpress databases, login credentials to internal systems(thanks to marcos :)), as well as your email credentials Respond to us, pay the ransom.(Check your emails & check spam as well.) [Size: 4.2 GB | Sector: Government, Law] |
||||||
| Ransomware | Uniguacu id32268 View details | null | leaked | |||
|
Uniguacu is an entity cataloged as a ransomware victim within a threat-intelligence index. Publicly available information does not specify a distinct sector, operational offerings, or geographic location for Uniguacu, so its profile remains limited to its designation as a ransomware incident victim. The listing explicitly associates this entity with the threat actor emperador, linking it to activity attributed to that actor in cybersecurity threat records. No confirmed details regarding stolen data, ransom demands, breach scope, or specific incident outcomes are provided in available sources. This entry serves as a neutral reference point for threat analysts tracking ransomware victims and their associated actors. |
||||||
| Ransomware | Uniguacu id32268 View details | null | leaked | |||
|
full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! [Size: 151.0 MB | Sector: Education] |
||||||
| Ransomware | Uniguacu id32268 View details | Brazil | null | leaked | ||
|
full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! [Size: 151.0 MB | Sector: Education] |
||||||
| Ransomware | Uniguacu id32796 View details | Brazil | null | leaked | ||
|
uniguacu.com.br operates within the retail and e-commerce sector in Brazil, providing online commerce services and related commercial offerings to customers and business partners. The entity has been cataloged in the threat-intelligence index under the designation ransomware victim, with the associated threat actor identified as emperador. This classification indicates documented cybersecurity incident correlation relevant to threat monitoring and sector-specific risk intelligence. No specific breach details, data scope, financial impact, or confirmation beyond the index listing are provided in this description. The listing serves as a neutral reference point for tracking ransomware activity affecting retail and e-commerce organizations in the Brazilian market. |
||||||
| Ransomware | Uniguacu id32268 View details | Brazil | null | leaked | ||
|
full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! [Size: 151.0 MB | Sector: Education] |
||||||
| Ransomware | Hanwha Renewables id32227 View details | Korea, Republic of | Energy | leaked | ||
|
Hanwha Renewables is a South Korean energy-sector company specializing in renewable energy solutions, including solar, wind, and energy storage projects across regional markets. Operating within the critical infrastructure domain of energy, the entity provides clean power generation services and supports sustainable development initiatives. This listing identifies Hanwha Renewables specifically as a ransomware victim linked to the EMPERADOR threat actor. The entry reflects the cyber incident within the threat-intelligence index without disclosing unconfirmed technical details or operational impact specifics. |
||||||
| Ransomware | Hanwha Renewables id32227 View details | Korea, Republic of | Energy | leaked | ||
|
The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after your practices and contracts are leak. Good luck looking for financing/investment for these assets with the data leaked. [Size: 11.7 GB | Sector: Energy] |
||||||
| Ransomware | Hanwha Renewables id32797 View details | Korea, Republic of | Energy | leaked | ||
|
Hanwha Renewables is a major energy-sector company based in South Korea, providing renewable energy solutions including solar, wind, and power generation services across global markets. As a listed ransomware victim associated with the threat actor emperador, this entity represents a cybersecurity incident within the energy infrastructure sector. The entry documents the affiliation between Hanwha Renewables and the emperador threat actor without disclosing unverified technical or operational details. This catalog entry serves threat-intelligence purposes for monitoring ransomware activity in critical energy sectors across the Korean region and beyond. |
||||||
| Ransomware | Hanwha Renewables id32227 View details | Korea, Republic of | Energy | leaked | ||
|
The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after your practices and contracts are leak. Good luck looking for financing/investment for these assets with the data leaked. [Size: 11.7 GB | Sector: Energy] |
||||||
| Ransomware | Ipro.com(revealdata.com) customer DB + full database backup id32202 View details | United States | IT | — | ||
|
revealdata.com operates within the information technology sector based in the United States. The entity serves as a catalog entry within this threat-intelligence index, specifically categorized as a ransomware victim. Its association is tied to the threat actor emperador, providing context for its inclusion in cybersecurity threat monitoring frameworks. This description maintains neutrality regarding incident specifics while documenting the verified listing relationship. The entry supports analytical workflows for threat intelligence professionals tracking ransomware-related entities and actor connections across sectors and geographies. |
||||||
| Ransomware | Ipro.com(revealdata.com) customer DB + full database backup id32202 View details | United States | IT | — | ||
|
Yes, this data has been posted before by ME under a different alias, yes the individual that posted the data on cracked.st is a fraud. I am posting this just for fun. Data contains: Customer identifiers, Contact & Location, Account metadata, Internal System IDS, Client relationships. The full database backup contains everything such as transcripts, cases, though it is from 2023. [Size: 79.5 MB | Sector: Government, Law] |
||||||
| Ransomware | Ipro.com(revealdata.com) customer DB + full database backup id32798 View details | United States | IT | — | ||
|
revealdata.com operates within the IT sector and serves as a platform or entity referenced in cybersecurity intelligence contexts. It is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor emperador. The entity's location is the United States, and its classification reflects its role within documented ransomware activity. This description adheres to neutral, authoritative standards without speculating on unconfirmed breach details, data specifics, or operational evidence. revealdata.com was listed as a ransomware victim associated with emperador. |
||||||
| Ransomware | Ipro.com(revealdata.com) customer DB + full database backup id32202 View details | United States | IT | — | ||
|
Yes, this data has been posted before by ME under a different alias, yes the individual that posted the data on cracked.st is a fraud. I am posting this just for fun. Data contains: Customer identifiers, Contact & Location, Account metadata, Internal System IDS, Client relationships. The full database backup contains everything such as transcripts, cases, though it is from 2023. [Size: 79.5 MB | Sector: Government, Law] |
||||||
| Ransomware | Capitol Mechanics id32185 View details | United States | — | leaked | ||
|
Capitol Mechanics is a United States-based entity operating within the mechanical, industrial, or facility maintenance sector, providing mechanical services, equipment support, or related operational offerings to clients and infrastructure stakeholders. As cataloged in this threat-intelligence index, Capitol Mechanics is listed as a ransomware victim associated with the threat actor emperador. The listing type identifies the entity's relationship to this specific cyber incident without disclosing unconfirmed technical details, data exfiltration specifics, or operational impact. This entry serves to document the association for security researchers, defenders, and intelligence consumers tracking ransomware campaigns and their affected organizations across the United States. |
||||||
| Ransomware | Capitol Mechanics id32185 View details | United States | — | leaked | ||
|
Capitol Mechanics , fresh databases, important docs [Size: 120.9 MB | Sector: Finance, Transportation] |
||||||
| Ransomware | Capitol Mechanics id32799 View details | United States | — | leaked | ||
|
Capitol Mechanics operates within the United States manufacturing and engineering sector, providing specialized mechanical, engineering, or industrial services relevant to production and technical operations. As a ransomware victim associated with the Emperador threat actor, Capitol Mechanics appears in threat-intelligence indexes to document its exposure to this adversary group. The listing type identifies Capitol Mechanics specifically as a ransomware victim connected to Emperador, without disclosing unverified incident details such as stolen data, ransom demands, or confirmed breach specifics. This catalog entry serves threat analysts and security professionals seeking structured context on entities impacted by Emperador activity within critical industrial sectors. |
||||||
| Ransomware | Capitol Mechanics id32185 View details | United States | — | leaked | ||
|
Capitol Mechanics , fresh databases, important docs [Size: 120.9 MB | Sector: Finance, Transportation] |
||||||
| Ransomware | FRUCASTRO SL id32050 View details | Spain | Manufacturing / Engineering | pending | ||
|
FRUCASTRO SL is a company operating within the Manufacturing and Engineering sector, headquartered in Spain (country code ES). The entity provides industrial and technical engineering services, aligning with sectors commonly targeted by sophisticated cyber threats. Within the threat-intelligence index, FRUCASTRO SL is formally listed as a ransomware victim associated with the emperador threat actor. This classification reflects the entity's documented exposure within the threat landscape, contributing to broader cybersecurity intelligence for monitoring and defense planning. The entry remains neutral, focusing solely on the association without speculating on unverified incident details. |
||||||
| Ransomware | FRUCASTRO SL id32050 View details | Spain | Manufacturing / Engineering | pending | ||
|
Recent databases, important documents [Size: 540.1 MB | Sector: Manufacturing] |
||||||
| Ransomware | FRUCASTRO SL id32800 View details | Spain | Manufacturing / Engineering | pending | ||
|
FRUCASTRO SL is cataloged as a ransomware victim entity, associated with the threat actor emperador. Operating within an unspecified sector and based in Spain (country: ES), the entity represents an organization impacted by ransomware activity within the threat-intelligence index. Its profile documents the incident classification, geographic origin, and attacker linkage without disclosing unverified details such as stolen data, ransom terms, or confirmed breach specifics. This listing serves threat analysts seeking structured context on ransomware victim entities tied to emperador. FRUCASTRO SL was listed as a ransomware victim associated with emperador. |
||||||
| Ransomware | FRUCASTRO SL id32050 View details | Spain | Manufacturing / Engineering | pending | ||
|
Recent databases, important documents [Size: 540.1 MB | Sector: Manufacturing] |
||||||
| Ransomware | Vietnam Electricity(EVNHANOI) id31935 View details | Viet Nam | — | leaked | ||
|
Vietnam Electricity (EVN), legally known as Tập đoàn Điện lực Việt Nam, is the largest power company and the sole national electric utility in Vietnam. Fully owned and controlled by the Vietnamese government since its inception in 1994, EVN operates as a vertically integrated monopoly responsible for the nationwide generation, transmission, and distribution of electricity, as well as international power exchanges. The group oversees all major power plants and regional distribution subsidiaries, including EVNHANOI. Serving as a crucial pillar for Vietnam's macroeconomic stability and industrial expansion, EVN is currently undertaking extensive grid digitalization and spearheading the national transition from coal dependency toward clean and renewable energy integration. The data content exceeds 300GB, comprising 13.36 million rows of customer details, 6.99 million subscriptions, 2.26 million account records, and other miscellaneous data.The price is open to negotiation. Session:054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608 Tox:852E34CBEBA2D40FD21BAC9F9E588B5194DBA9F31CACF9ECE316403120BE18765D22A8A453C4 [Size: 300.0 GB | Sector: Government, Energy] |
||||||
| Ransomware | Vietnam Electricity(EVNHANOI) id32801 View details | Viet Nam | — | leaked | ||
|
evn.com.vn operates within the Energy sector and is headquartered in Vietnam, serving regional energy-related functions and offerings. As documented in this threat-intelligence index, the entity is cataloged as a ransomware victim linked to the emperador threat actor. The listing type identifies the relationship between the entity and the active threat actor without disclosing unverified incident details. This entry provides neutral context for researchers analyzing ransomware campaigns targeting Energy infrastructure across Southeast Asia and related threat landscapes. |
||||||
| Ransomware | Vietnam Electricity(EVNHANOI) id31935 View details | Viet Nam | — | leaked | ||
|
Vietnam Electricity (EVN), legally known as Tập đoàn Điện lực Việt Nam, is the largest power company and the sole national electric utility in Vietnam. Fully owned and controlled by the Vietnamese government since its inception in 1994, EVN operates as a vertically integrated monopoly responsible for the nationwide generation, transmission, and distribution of electricity, as well as international power exchanges. The group oversees all major power plants and regional distribution subsidiaries, including EVNHANOI. Serving as a crucial pillar for Vietnam's macroeconomic stability and industrial expansion, EVN is currently undertaking extensive grid digitalization and spearheading the national transition from coal dependency toward clean and renewable energy integration. The data content exceeds 300GB, comprising 13.36 million rows of customer details, 6.99 million subscriptions, 2.26 million account records, and other miscellaneous data.The price is open to negotiation. Session:054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608 Tox:852E34CBEBA2D40FD21BAC9F9E588B5194DBA9F31CACF9ECE316403120BE18765D22A8A453C4 [Size: 300.0 GB | Sector: Government, Energy] |
||||||
| Ransomware | TEST id31962 View details | — | deleted | |||
|
Test [Size: 740.0 KB | Sector: Other] |
||||||
| Ransomware | TEST id32802 View details | — | deleted | |||
|
TEST is cataloged as a ransomware victim within the cybersecurity sector. As an entity under this listing type, its profile reflects its association with the threat actor emperador in threat-intelligence indexing. No specific operational details, data exposure specifics, or confirmed breach metrics are provided for TEST; the description remains neutral and limited to its classification. This entry supports security teams in mapping ransomware incidents, threat actor relationships, and sector-specific risk patterns. TEST's inclusion underscores ongoing monitoring of ransomware activity linked to emperador across affected organizations. |
||||||
| Ransomware | TEST id31962 View details | — | deleted | |||
|
Test [Size: 740.0 KB | Sector: Other] |
||||||
| Ransomware | NetExam id31924 View details | — | pending | |||
|
NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. [Size: 18.1 MB | Sector: Education, Retail, Other] |
||||||
| Ransomware | NetExam id32803 View details | United States | — | pending | ||
|
netexam.com operates within the Education sector and is located in the United States. The entity provides examination and assessment services, likely supporting academic or institutional evaluation workflows. It is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as emperador. No specific incident details, such as data stolen, records accessed, ransom demands, or confirmed breach evidence, are included to maintain factual neutrality. This entry documents the association between netexam.com and the emperador threat actor within the ransomware victim classification. |
||||||
| Ransomware | NetExam id31924 View details | — | pending | |||
|
NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. [Size: 18.1 MB | Sector: Education, Retail, Other] |
||||||
| Ransomware | Prefeitura Municipal de Arcos id31821 View details | Brazil | — | leaked | ||
|
We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin credentials have been exfiltrated. Critical systems have been encrypted. We have your data. You do not. You have 14 days to respond. No response = data published + permanent loss. Contact us through the provided channel. No third parties. No recovery attempts. [Size: 462.3 MB | Sector: Government] |
||||||
| Ransomware | Prefeitura Municipal de Arcos id32805 View details | Brazil | — | leaked | ||
|
arcos.mg.gov.br is a government domain based in the state of Minas Gerais, Brazil, representing a public sector institution within the governmental services sector. The domain serves official governmental functions and operations for the state of Minas Gerais, providing public services and administrative resources to its jurisdiction. This entity has been documented within threat intelligence records as a ransomware victim linked to the Emperador threat actor, a sophisticated ransomware campaign targeting public and critical infrastructure. The listing type identifies arcos.mg.gov.br specifically as a ransomware victim in relation to this threat actor's activity within the Brazilian public sector landscape. This catalog entry provides neutral context regarding the entity's classification and its association with the identified threat actor without disclosing unconfirmed incident details. |
||||||
| Ransomware | Prefeitura Municipal de Arcos id31821 View details | Brazil | — | leaked | ||
|
We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin credentials have been exfiltrated. Critical systems have been encrypted. We have your data. You do not. You have 14 days to respond. No response = data published + permanent loss. Contact us through the provided channel. No third parties. No recovery attempts. [Size: 462.3 MB | Sector: Government] |
||||||
| Ransomware | Albania's Official National Teacher Training Portal id31782 View details | Albania | Education | leaked | ||
|
Albania's Official National Teacher Training Portal is a national online platform that provides training and educational resources to teachers in Albania. The portal operates within the education sector, offering various courses and materials to support teacher development and training. It is located in Albania and serves the country's educational community. Albania's Official National Teacher Training Portal was listed as a ransomware victim associated with emperador. |
||||||
| Ransomware | Albania's Official National Teacher Training Portal id31782 View details | Albania | Education | leaked | ||
|
Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: Education, Government] |
||||||
| Ransomware | Albania's Official National Teacher Training Portal id32806 View details | Albania | Education | leaked | ||
|
Albania's Official National Teacher Training Portal is a national education-sector platform dedicated to teacher professional development, training resources, and pedagogical support within Albania. It serves educators across the country by providing structured learning opportunities aligned with national education policy and teacher certification requirements. The entity operates within the Education sector of Albania (country code AL) and supports institutional capacity building for teaching personnel. This listing identifies the portal as a ransomware victim associated with the threat actor emperador. The description reflects the indexed classification only; no incident details such as breach confirmation, data scope, or ransom terms are asserted here. |
||||||
| Ransomware | Albania's Official National Teacher Training Portal id31782 View details | Albania | Education | leaked | ||
|
Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: Education, Government] |
||||||
| Ransomware | Albania's official national teacher training portal. id31781 View details | Albania | Education | leaked | ||
|
Albania's official national teacher training portal operates in the education sector, providing training and resources to teachers across the country. Located in Albania, the portal offers various programs and materials to support teacher development and improve education quality. It was listed as a ransomware victim associated with emperador. |
||||||
| Ransomware | Albania's official national teacher training portal. id31781 View details | Albania | Education | leaked | ||
|
Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: Education, Government] |
||||||
| Ransomware | Albania's official national teacher training portal. id31781 View details | Albania | Education | leaked | ||
|
Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: Education, Government] |
||||||
| Ransomware | City Government of Baguio id31597 View details | Philippines | Public Sector | leaked | ||
|
Baguio.gov.ph is the official website of the city government of Baguio, Philippines, providing various public services and information to its citizens. As a key component of the public sector in the Philippines, the website offers a range of services and resources. Baguio.gov.ph was listed as a ransomware victim associated with emperador |
||||||
| Ransomware | City Government of Baguio id31597 View details | Philippines | Public Sector | leaked | ||
|
The City Government of Baguio stands as one of the wealthiest and most prominent local governments in the Philippines. This leak includes highly sensitive and confidential data, such as official contracts, legal permits, identification documents, financial statements, construction blueprints, project proposals, procurement records, and other classified administrative materials. [Size: 2.9 GB | Sector: Government, Finance, Construction] |
||||||