cmd organization
Ransomware group profile
Description
CMD Organization is a new ransomware group that surfaced in May 2026, claiming to be an IT security firm while engaging in ransomware activities. Their unique auction-based extortion model incentivizes financial gain through public listings of stolen data, setting them apart from traditional groups.
Key insights
- •Utilizes an auction-based extortion model to maximize ransom payments.
- •Exploits vulnerabilities in public-facing applications for initial access.
- •Focuses on data extraction from information repositories.
- •Employs tactics like double extortion and public data leaks on dark web platforms.
- •Operates using a combination of onion sites and clearnet domains.
Threat Level & Status Breakdown
For cmd organization · Based on incidents in selected period
Recent activity
Monthly attack count for cmd organization in the selected period
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for cmd organization
T1213
Data from Information Repositories
T1071
Application Layer Protocol
T1562
Impair Defenses
T1059
Command and Scripting Interpreter
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1021
Remote Services
T1190
T1190
T1041
T1041
T1037
T1037
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
Victims(17)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| Lake Washington School District | — | US United States | Education | Unknown | 3 days ago | |
| Lee Law Offices | — | US United States | Professional Services | Unknown | 4 days ago | |
| Capital Family Physicians | — | US United States | Healthcare | Unknown | 5 days ago | |
| Hospice Savannah | — | US United States | Healthcare | Unknown | 6 days ago | |
| North Dallas Shared Ministries | — | US United States | Government & Defense | Unknown | 9 days ago | |
| Stonehenge Therapeutic Community | — | US United States | Healthcare | Unknown | 16 days ago | |
| Holy Name of Jesus | — | US United States | Other | Unknown | 17 days ago | |
| Raise the Bottom | — | US United States | Healthcare | Unknown | 19 days ago | |
| WholeHealth Chicago | — | US United States | Healthcare | Unknown | 19 days ago | |
| Houston Eye Associates | — | US United States | Healthcare | Unknown | 20 days ago | |
| Goodstone Group | — | — | Hospitality | Unknown | 20 days ago | |
| Ira & Larry Goldberg Coins & Collectibles | — | — | Retail & E-Commerce | Unknown | 20 days ago | |
| Advanced Software Products Group | — | — | Technology | Unknown | 23 days ago | |
| PennEastern Architects | — | US United States | Professional Services | Unknown | 27 days ago | |
| Cytek Biosciences | — | US United States | Healthcare | Unknown | about 1 month ago | |
| JG Stewart Construction | — | — | Other | Unknown | about 1 month ago | |
| Zampell | — | — | Energy & Utilities | Unknown | about 1 month ago |
Affected countries(5)
Countries where this group has been reported to target or leak victims.