Quick Summary
AllegedExecutive Summary
CONDOR SPA, an Italian manufacturing company, has been listed as a victim on the Titan ransomware group’s dark web portal, published on August 20, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. CONDOR SPA operates in the Italian industrial manufacturing sector and is affiliated with the broader Condor Group. This listing places the company among the Italian manufacturing firms that Titan targeted in its August 2026 operational cluster. In the 60 days prior to this listing, Titan has claimed 10 other victims across its leak portal. The group has shown a strong targeting pattern in the Manufacturing, Technology, and Other sectors. Geographically, its victims are concentrated in Italy and India. Other recent Titan listings that closely align with CONDOR SPA’s profile — Italian manufacturing companies — include Elbor S.p.A., Termotecnica Industriale S.r.l., ELCON MEGARAD S.p.A, and TECNOLOGICA S.r.l. CONDOR SPA sits squarely within Titan’s concentrated Italian industrial targeting pattern.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the condor-group.it domain. Three credentials were recovered in the queried sample, all associated with the same masked account handle, accessing an admin login endpoint on the target domain. The same account appeared in both a corporate context and a consumer email provider, a pattern consistent with workstation compromise risk where personal device usage blurs corporate credential boundaries. This mix of access types indicates the credentials were harvested from an employee machine rather than a purely server-side compromise. For ransomware groups such as Titan, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Titan, the pattern — an admin-level endpoint credential exposed alongside consumer email activity from the same device — is consistent with the kill chain typically observed for this class of incident.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.