Quick Summary
AllegedExecutive Summary
Megawork, a business services company based in Brazil, has been identified as a victim on the RansomHouse ransomware group’s dark web portal, with the listing dated July 16, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. Operating within the Business Services sector, Megawork is now part of RansomHouse’s recent activity pattern, which has impacted organizations across various regions and industries. In the 60 days leading up to this listing, RansomHouse claimed an additional five victims. The group predominantly targets the Business Services, Financial Services, and Construction sectors, with a significant concentration of victims in Brazil, the United Kingdom, and Italy. Recent victims showing a similar profile to Megawork include Fidelity Services Group, Bonacio, Promepla, and Ma Pak Leung Company Limited, reinforcing Megawork’s alignment with the group’s typical targeting strategy of Business Services organizations in Brazil.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a potential initial access pathway for the megawork.com.br domain. The queried data indicated three relevant records: one employee credential associated with an organization-owned system and two corporate usernames found on third-party services. Specifically, these included a corporate account on the organization’s webmail portal, with the same login credentials being reused on a cloud file-sharing platform. This pattern suggests a single affected user rather than broad credential harvesting, given the password reuse across these services. The records fall within a freshness window from December 2025 to February 2026. For ransomware groups like RansomHouse, credentials harvested by infostealers serve as a common initial access vector. Threat actors or initial access brokers often acquire fresh logs from underground marketplaces, validate the corporate credentials, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, thereby facilitating ransomware deployment. While the stealer-log evidence does not definitively confirm the use of these specific credentials by RansomHouse, the observed pattern is consistent with the typical attack kill chain for such incidents. The exposed accounts and endpoints should therefore be treated as high-priority targets for credential rotation and security review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.