Quick Summary
AllegedExecutive Summary
Promantra, Inc, a technology and business process services firm based in the United States, has been listed as an alleged victim by the MetaEncryptor ransomware group. The listing appeared on the group’s dark web portal on September 17, 2026. This incident follows a period where infostealer malware collected employee credentials from Promantra, Inc. between July and September of the same year. While the direct connection between the credential harvesting and the ransomware listing is not confirmed, the nature of the collected data raises significant security concerns. MetaEncryptor has been actively targeting organizations, claiming 16 victims in the 60 days prior to this listing. The group’s operational pattern suggests a focus on specific sectors rather than mass-market attacks, with a known preference for Manufacturing, Healthcare, and Professional Services firms. Their primary targets are geographically concentrated in the United States, Japan, and Canada. Promantra’s profile aligns with MetaEncryptor’s typical targeting, alongside other recent alleged victims such as AECOM, Beckman Coulter, Inc., Hologic, Inc., and SIFCO Industries INC.
Technical Analysis
SOCRadar’s Dark Web Monitoring flagged a listing for Promantra, Inc. by the MetaEncryptor ransomware group. Analysis of a 25-record sample of infostealer-harvested credentials associated with Promantra, Inc. (promantra[.]us) revealed an unusual concentration of corporate email addresses. All 25 records contained corporate email addresses, a deviation from typical samples which often include a mix of personal and corporate credentials. The harvested credentials included employee access to organizational systems, specifically noting 11 credentials linked to Microsoft identity infrastructure and a direct VPN endpoint at vpn.promantra[.]us. Additionally, 14 corporate users had credentials exposed for third-party SaaS platforms, including Box tenant subdomains and healthcare portal services. The freshness window for these credentials spans from July 6, 2026, to September 15, 2026, indicating a period of over two months where credentials were not rotated. This extended period of unrotated credentials, coupled with the direct VPN access and Microsoft SSO credentials, presents a significant concern. Such access methods are commonly exploited by ransomware groups for initial entry and subsequent deployment. The timeframe between credential harvest and the leak-site listing suggests a plausible operational timeline for reconnaissance and potential attack execution. The direct VPN endpoint is a critical area of concern. The combination of VPN access and Microsoft SSO credentials creates a common pathway for ransomware attacks. The unrotated state of these credentials over an extended period increases the risk of exploitation. Therefore, all @promantra.us credentials associated with VPN, Microsoft, and Box endpoints should be considered compromised. Auditing session logs from July 6, 2026, onwards is recommended to establish a baseline for forensic analysis.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.