Quick Summary
AllegedExecutive Summary
Orova ransomware group targeted Arich Enterprise Co., Ltd., a Taiwanese enterprise, listing the company on its leak site on August 25, 2026. SOCRadar’s Dark Web Monitoring service identified the listing, which featured exposed administrative credentials and evidence of an access window open since at least March 2026. Arich Enterprise Co., Ltd., with its corporate portals, internal EIP systems, and operational presence in Taiwan, presents a profile that aligns with Orova’s documented targeting patterns in East Asia. The availability of administrative credentials and accessible internal systems likely made the company an attractive target for ransomware actors. In the preceding 60 days before Arich Enterprise’s listing, Orova claimed approximately 41 other victims, with a significant concentration in the United States, Taiwan, and Hong Kong. The ransomware group’s primary target sectors include Healthcare, Professional Services, and a broad category often labeled as “Other.” Recent victims comparable to Arich Enterprise include KINGSSON, Ultra Fame, DBM Reflex, and DL HOLDINGS GROUP, indicating that Arich’s targeting does not represent a deviation from Orova’s established modus operandi.
Technical Analysis
The SOCRadar Dark Web Monitoring service queried the domain arich[.]com[.]tw, which returned three records. Two of these records contained employee credentials that were authenticated against the organization’s internal infrastructure. Specifically, credentials with administrative-pattern usernames were found for the EIP subdomain (eip.arich[.]com[.]tw) and the primary corporate domain (arich[.]com[.]tw), with timestamps ranging from March to May 2026. The presence of administrative interface credentials is a critical risk, as these provide direct access to core systems without requiring privilege escalation, making them highly desirable for ransomware operators. A third recovered record linked a corporate user to an internal portal located at ez.arich[.]com[.]tw. This record also included an India geolocation tag, which could signify a compromised remote-access session or a marker of lateral movement within the network. The overall telemetry indicates a significant corporate intrusion risk, with the identified credentials and access points being valid from March 1 to May 18, 2026. Infostealer logs are identified as the probable initial access vector for Orova. Threat actors typically obtain validated credentials from underground marketplaces, often facilitated by initial access brokers. These credentials are then used to authenticate against administrative interfaces and VPN portals before deploying ransomware. The recovery of unrotated administrative credentials, remaining active over a two-month period, suggests an access-maintenance phase by the threat actor prior to potential ransomware deployment. Organizations are advised to rotate all administrative account credentials immediately and to conduct thorough audits of access logs for eip.arich[.]com[.]tw and arich[.]com[.]tw, specifically reviewing activity from March 2026 onward.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.