Ransomware Intelligence

benzona

Ransomware group profile

14Victims

Description

No description available for this group.

Threat Level & Status Breakdown

For benzona · Based on incidents in selected period

2.7threat level
Aggressiveness3.5/ 10
Lethality0/ 10
Criticality4.8/ 10
First seenNov 2025
Last seenJan 2026
Avg ransom
Payment rate

Recent activity

Monthly attack count for benzona in the selected period

14Total attacks
6peak in Jan
4.7avg / month
↑ 1 vs first month
NovDecJan02468

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for benzona

Defense Evasion

T1562

Impair Defenses

T1027

Obfuscated Files or Information

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(14)

CompanyDomainCountryIndustryStatusDiscovered
casamedica.com.gtcasamedica.com.gtGT GuatemalaHealthcare
Unknown
4 months ago
empreinte-hotel.comempreinte-hotel.comFR FranceHospitality
Unknown
5 months ago
*a*ame*i*a.com.g*
Unknown
5 months ago
ccbrt.orgccbrt.orgTZ TanzaniaHealthcare
Unknown
5 months ago
em***int*-ho***.comem***int*-ho***.comNA Namibia
Unknown
5 months ago
cc***.or.*zNA Namibia
Unknown
5 months ago
taminsho.comtaminsho.comIR IranHealthcare
Unknown
6 months ago
platinumone.inplatinumone.inIN IndiaTechnology
Unknown
6 months ago
SUNNYGO.COM.TWsunnygo.com.twTW TaiwanRetail & E-Commerce
Unknown
6 months ago
suzuki-ploiesti.rosuzuki-ploiesti.roRO RomaniaManufacturing
Unknown
6 months ago
poliserv.ropoliserv.roRO RomaniaProfessional Services
Unknown
6 months ago
mazda-ploiesti.romazda-ploiesti.roRO RomaniaManufacturing
Unknown
6 months ago
dacia-ploiesti.rodacia-ploiesti.roRO RomaniaTransportation
Unknown
6 months ago
sevci.orgsevci.orgCI Ivory CoastHealthcare
Unknown
6 months ago

Affected countries(9)

Countries where this group has been reported to target or leak victims.