0mega
0mega is a ransomware group first observed in May 2022, operating with a double extortion model: <br/>* Encrypting victim files (adding the .0mega extension) <br/>* Threatening to leak stolen data if ransom demands are not met. <br/>Ransom notes are named DECRYPT-FILES.txt and include victim-specific details and a Tor-based negotiation portal. <br/>Unlike typical Ransomware-as-a-Service (RaaS) operations, 0mega appears to work as a closed group, selecting a limited number of high-value targets. <br/>The group employs two main tactics: <br/>* Traditional ransomware encryption of on-premise systems. <br/>* Cloud-based extortion, compromising Microsoft 365 Global Admin accounts, creating unauthorized admin users, and exfiltrating data via SharePoint. <br/>Active period: May 2022 – January 2024
Most affected countries
No data yet.
Most affected sectors
No data yet.
Recent victims
No data yet.
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.