Quick Summary
AllegedExecutive Summary
The Rubber Group, a custom rubber and polymer manufacturer based in the United States, was listed on Global Secret Group’s dark web portal on August 17, 2026. The company serves industrial, automotive, and specialty applications across North America. This listing was identified through SOCRadar’s Dark Web Monitoring service. While the listing appeared back-to-back with another US company, 4M Realty Company, on the same day, neither incident has been independently verified. The Rubber Group’s profile as a US-based small manufacturer with specialized industrial production and potentially limited public-facing infrastructure aligns with typical targeting patterns for ransomware groups. Global Secret Group claimed 9 other victims in the 60 days prior to this listing, predominantly targeting the Other, Manufacturing, and Financial Services sectors. The group has shown a geographic concentration in the United States and Greece. Previous victims listed by the group include Columbia University Information (Dental), Coggins Insurance Agency, and Cook Remodeling. The Rubber Group fits precisely into the threat actor’s observed targeting profile, indicating a consistent pattern of activity.
Technical Analysis
SOCRadar’s stealer-log telemetry returned no records for the domain rubber-group[.]com within the queried data slice. However, this absence of direct correlation does not confirm that the organization is unaffected. Manufacturing firms, particularly those with less consumer-facing infrastructure, are often underrepresented in stealer-log datasets. Credentials for such entities may exist in adjacent query pages, under alternate corporate domains, or be associated with employee personal email aliases, making them harder to detect in limited scans. Global Secret Group operators are known to validate credentials obtained through infostealer campaigns against common access points like Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. Therefore, continued monitoring of rubber-group[.]com across multiple telemetry sources is advisable to detect any potential compromise or exfiltration activities.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.