Uptime Hamster: 21d 2h 0mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza IMNCrew

IMNCrew

2 incidentes 1 paises 0 sectores threat-actor Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
IMNCrew is a financially motivated ransomware and extortion group first observed in late March 2025. The group initially focused solely on data exfiltration and extortion, but later evolved to also deploy encryption payloads, using the .imn file extension for encrypted data. They launched their dedicated leak site around April 15, 2025, to publish exfiltrated victim data. Unlike many other emerging ransomware groups, IMNCrew has no confirmed associations with established operations. Their operational style is characterized by being polite and not overly aggressive during ransom negotiations. The group primarily targets small to medium-sized businesses across various sectors.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: IMNCrew
DLS / onionofflineimncrewwfkbjkhr2oylerfm5qtbzfphhmpcfag43xc2kfgvluqtlgoid.onionCTI.FYI
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Indonesia (2)

Paises objetivo (OSINT)

CanadaColombiaCzech RepublicSpainCroatiaIndonesiaItalyMexicoPhilippinesSweden

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankAccommodationManufacturingConstructionPublic AdministrationBeverag & Tobacco ManufacturingEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com