Uptime Hamster: 31d 4h 10mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza spook

spook

2 incidentes 1 paises 1 sectores ransomware Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Spook is a ransomware group that emerged in late September 2021 and operated for a brief period, concluding its activity by October 2021. The group utilizes ransomware samples generated by the Thanos builder, a tool sold on underground forums, and shares significant code similarities with the Prometheus ransomware family. Spook's primary motivation is financial gain, achieved through a double extortion model that involves encrypting victim data and threatening its public release. A distinctive characteristic of Spook is its practice of publishing details of all compromised organizations on its leak site, irrespective of whether the ransom demands are met. The group's activities indicate a focus on manufacturing, financial, and retail sectors.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownspookuhvfyxzph54ikjfwf2mwmxt572krpom7reyayrmxbkizbvkpaid.onionspook
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: spook
Tecnicas MITRE
T1486, T1078, T1105, T1562
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAustriaBelgiumBrazilChinaSpainFranceUnited KingdomHungaryIran, Islamic Republic of

Sectores atacados

Manufacturing (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com