Uptime Hamster: 43d 15h 34mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza noescape

noescape

1 incidentes 1 paises 0 sectores threat-actor RU Ultimo: 2026-07-09
Aliases: "Noescape group" o "Noescape ransomware"
Ver en IntelTracker → APTTrail →
NoEscape ransomware emerged in May 2023 as a Ransomware-as-a-Service (RaaS) operation, which functions by providing malicious code and infrastructure to affiliates for a share of ransom payments. It is widely understood to be a rebrand of the defunct Avaddon ransomware group, which ceased operations in 2021. Despite this, NoEscape's operators assert that their malware and infrastructure were built from scratch. The group is assessed with high confidence to be of Eastern European or Russian origin, evidenced by its policy of not targeting Commonwealth of Independent States (CIS) countries and providing free decryption keys to victims in these regions. NoEscape's primary motivation is financial gain, and it distinguishes itself by employing a triple-extortion model that includes encrypting data, exfiltrating sensitive information, and threatening Distributed Denial of Service (DDoS) attacks, in addition to listing victims on a dedicated leak site. The service offers affiliates extensive

Aliases del actor

"Noescape group" o "Noescape ransomware"

Actores similares

Silent Ransom Group / LeakedDataransomware · 0ragroupransomware · 0Global Groupransomware · 0Group Space Bearsransomware · 0unknown ransomware groupransomware · 0NyxarGroupransomware · 0Red Ransomware Groupthreat-actor · 0lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionofflinenoescapemsqxvizdxyl7f7rmg5cdjwp33pg2wpmiaaibilb4btwzttad.onionCTI.FYI
DLS / onionofflinenoescaperjh3gg6oy7rck57fiefyuzmj7kmvojxgvlmwd5pdzizrb7ad.onionCTI.FYI
Webunknownwww.cisa.govOSINT
Tecnicas MITRE
T1471, T1036, T1090, T1047, T1486, T1071.001
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

United Arab EmiratesAustriaAustraliaAzerbaijanBelgiumBurundiBermudaBrazilCanadaSwitzerland

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction

Victimas (1)

Noescape (Unknown / Unmapped Actors)9 Jul 2026
Reference United States
Que es Noescape es un actor APT (Advanced Persistent Threat) cuya identidad y geografía de origen permanecen desconocidas. Con alias como "Noescape gr…