Ransomware Group intelligence
EndZone
ActiveTrack EndZone with 2 published victims and 1 known leak locations in a single intelligence view.
Overview
EndZone is tracked by Dark Eye as a ransomware group with 2 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | endzonezgz3sqzmtqg4acp4z7ao7xc6vunfhezjsnfqrm2ksudsredyd.onion |
Top Activity Sectors (2)
- IT 1
- Telecommunications 1
Victims (2)
Search, filter and paginate the victim timeline for EndZone. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Accela.com id32956 View details | United States | IT | — | — | |
|
Revenue: $144.4 million Accela is a comprehensive cloud based software platform used by state and local governments to manage internal agency operations. We have successfully extracted over 50 GB of data from Accela. Data includes over 2 million lines of user data with PII, and 6 million user requests (from their citizen engagement portal where citizens report everyday non-emergencies in/around their neighbourhoods) also with PII. There is a lot of government data, from FBI agents to cops to regular government workers. Speak soon or Leak soon! |
||||||
| Ransomware | AT&T id32957 View details | United States | Telecommunications | — | — | |
|
Revenue: $125.6 billion Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place. Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP! |
||||||