Active · 412 victims
Emerging group targeting SMBs with double extortion and ESXi-focused encryption.
Last observed: May 27, 2026