Quick Summary
AllegedExecutive Summary
On August 4, 2026, a new ransomware group named Orova launched its leak site, immediately listing four Taiwanese companies, including Ultra Fame. SOCRadar’s Dark Web Monitoring service detected this listing on the same day, marking the beginning of Orova’s publicly tracked activity. Ultra Fame is identified in the dataset as a Taiwan-based company, and while its specific sector is unconfirmed, its appearance alongside other Taiwanese firms suggests a possible shared initial access vector, potentially an access broker or a common exposed technology rather than independent intrusions. Orova has claimed 23 other victims within the 60 days preceding this initial August 4 batch, with their activity concentrated in the United States, Hong Kong, and Taiwan. The targeted industries predominantly include healthcare, manufacturing, and financial services, although many victims are listed without a specific sector. This initial wave of attacks, with its strong regional focus on Taiwan and industry diversification, represents Orova’s strategic debut in the cybercrime landscape.
Technical Analysis
SOCRadar’s investigation into Ultra Fame’s presence in stealer-log telemetry yielded no direct results for the subdomain en[.]ufame[.]com[.]tw. This result is logged with a “no_exposure_in_sample” status and a “limited-coverage” flag. It is critical to note that this specific query targeted only the English-language subdomain, not Ultra Fame’s primary corporate domain or other potential local-language hosts. Therefore, any credential exposure indexed under different domains would not have been detected by this particular scan. The absence of evidence in this limited sample does not rule out a compromise. Infostealer-harvested credentials are a common initial access vector for ransomware groups like Orova. Threat actors or access brokers often purchase compromised credentials from underground marketplaces, validate them, and then use them to gain access to systems via platforms such as Microsoft 365, VPNs, or remote-access portals, subsequently deploying ransomware. Given that the initial SOCRadar query only examined a subdomain and represented a paginated, limited sample, further investigation is warranted. It is recommended to re-run the correlation against the root corporate domain to ascertain any potential credential exposure. Continued dark web monitoring and proactive credential hygiene checks, including password rotation and multi-factor authentication review for all corporate accounts, are advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.