Quick Summary
AllegedExecutive Summary
Dharma Group, an organization based in Italy, has been listed as a victim on the dark web portal of the Everest ransomware group. The listing, published on August 5, 2026, was identified by SOCRadar’s Dark Web Monitoring service. While Dharma Group’s specific industry is not detailed in SOCRadar’s dataset, the company is noted as the sole Italian entity among Everest’s recent victims. This incident highlights the continuous threat posed by ransomware groups targeting businesses globally. In the 60 days leading up to this listing, Everest had claimed 18 other victims. The group’s targeting patterns predominantly affect the technology, professional services, and energy and utilities sectors. Its victim base is primarily located in the United States, India, and the United Arab Emirates. Recent Everest listings that show parallels with Dharma Group’s profile, such as generically classified or European entities, include AKM Enterprises INC, Keysight, Stadler Rail, and Mansfield Family Dentistry. Italy is not among the group’s top three geographic targets during this period, making Dharma Group’s inclusion a less typical occurrence for Everest’s recent activity.
Technical Analysis
SOCRadar’s query against its stealer-log telemetry for the domain “dharmagroup.it” returned no records within the queried sample. It is crucial to understand that a null result does not confirm the absence of a compromise. The telemetry query covered only a paginated portion of the data, and potential credentials may exist under alternate or subsidiary corporate domains. Furthermore, credentials harvested using personal email aliases would not be associated with the corporate domain in this type of query. Organizations that operate through multiple, distinct subsidiaries are particularly susceptible to these blind spots in domain-scoped analyses. For ransomware groups like Everest, infostealer-harvested credentials represent a well-documented method for gaining initial access. Threat actors or initial access brokers typically acquire fresh credential logs from underground marketplaces. These logs are then validated and used to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, paving the way for ransomware deployment. The absence of evidence in this specific query does not preclude this attack scenario. It is possible that compromised credentials appeared in datasets not covered by this analysis, were used and subsequently rotated before being indexed, or were harvested under personal email addresses. Consequently, threat intelligence teams should prioritize continuous monitoring and proactive credential hygiene checks rather than interpret a null query as a sign of no compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.