Uptime Hamster: 21d 2h 6mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza ups

ups

1 incidentes 1 paises 1 sectores Ultimo: 2026-07-09
Aliases: Gothic Panda, TG-0110, lo que sugiere una operativa bien organizada, Deep Panda, WebMasters, Apt19, KungFu Kittens, Group 13, Sh3llCr3w, PinkPanther, Winnti Group, CactusPete, Tonto Team, Bisonal (malware), Lone Ranger, Dissident groups, otros referencias en inteligencia de amenzas, "Energy technology"
Ver en IntelTracker → APTTrail →

Aliases del actor

Gothic PandaTG-0110lo que sugiere una operativa bien organizadaDeep PandaWebMastersApt19KungFu KittensGroup 13Sh3llCr3wPinkPantherWinnti GroupCactusPeteTonto TeamBisonal (malware)Lone RangerDissident groupsotros referencias en inteligencia de amenzas"Energy technology""G20""NGOs""Dissident Groups"Umbrella RevolutionDissident GroupsListed slide 4Snatch groupSnatch ransomwareSnatch gangaunque su operación específicamotivación siguen siendo investigadasAPT3BuckeyeUPS Team

Actores similares

Eloquent Pandaapt · 0apt-1877teamactor · 1apt-equationgroupactor · 1apt-group5actor · 1apt-hackingteamactor · 1The Gorgon Groupapt · 0Desert Dexter Groupapt · 0DarkStorm Teamapt · 0Predator Pandaapt · 0313 Teamapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownnitter.netDark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion
Forounknownx.comDark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.
Forounknownnitter.netDark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.
DLS / leak siteunknownnitter.netIdo Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.
X/Twitterunknownx.comIdo Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.
DLS / leak siteunknownnitter.netIdo Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
DLS / leak siteunknownnitter.netIdo Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.
DLS / leak siteupnitter.netIdo Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.
DLS / leak siteupnitter.netIdo Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.
DLS / leak siteunknownnitter.netIdo Cohen: Threat Group Update Prinz Eugen has launched a newly redesigned leak site and updated its public profile. According to the group's latest statement, it describes itself as a for-profit organization that "specializes in hacking" while claiming it currently does not operate a Ransomware-as-a-Service (RaaS) program. The group also stated that membership intake is currently closed and limited to existing core members.
DLS / leak siteupnitter.netIdo Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.
DLS / leak siteunknownnitter.netIdo Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: CISAThreatGroups
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: TrendMicroThreatGroups
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: TheDFIRReportGroups
Repositoriounknowngithub.comBushidoUK ToolMatrix ThreatIntel: TrendMicroThreatGroups
DLS / leak siteunknownwww.breachsense.comupstatehomecare.com - Pysa Data Breach
DLS / leak siteunknowngetbootstrap.comupstatehomecare.com - Pysa Data Breach
Repositoriounknowngithub.comupstatehomecare.com - Pysa Data Breach
DLS / leak siteunknownwww.breachsense.comtkemlups.ca - Conti Data Breach
DLS / leak siteunknownduckduckgo.comtkemlups.ca - Conti Data Breach
DLS / leak siteunknownduckduckgo.comtkemlups.ca - Conti Data Breach
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1)

Sectores atacados

Technology (1)

Victimas (1)

UPS (China)9 Jul 2026
Reference China Technology
Que es UPS (China) es un actor APT (Advanced Persistent Threat) asociado a China, conocido por su actividad de ciberataque con múltiples alias y conex…