Ransomware group
Underground ransomware: victims and leak site activity
The Underground ransomware group has listed 26 victims on its leak site since May 2024; its latest post is from 15 August 2025. Most affected countries: United States, Canada and South Korea. Most targeted sector: Technology.
Total posts
26
First seen
2024-05-01
Latest post
2025-08-15
Countries hit
11
About Underground
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
Most targeted countries
- United States 9
- Canada 3
- South Korea 3
- Germany 2
- Taiwan 2
- United Arab Emirates 1
- Spain 1
- France 1
- Japan 1
- Singapore 1
Most targeted sectors
- Technology 7
- Healthcare 5
- Manufacturing 5
- Professional Services 5
- Agriculture and Food Production 2
- Financial Services 1
- Transportation 1