Ransomware needs a way in. Stolen credentials are the cheapest one.
EndZone Ransomware Group
Ransomware group profile
7Victims
Description
No description available for this group.
Threat Level & Status Breakdown
For EndZone Β· Based on incidents in selected period
3.2threat level
Data Leaked28.6%2
Negotiating14.3%1
Claimed57.1%4
First seenSep 2026
Last seenOct 2026
Avg ransomβ
Payment rateβ
Recent activity
Monthly attack count for EndZone in the selected period
7Total attacks
5peak in Sep
3.5avg / month
β 3 vs first month
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for EndZone
Defense Evasion
T1562
Impair Defenses
Execution
T1059
Command and Scripting Interpreter
T1047
Windows Management Instrumentation
Impact
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
Lateral Movement
T1021
Remote Services
Other
T1583
T1583
Persistence
T1078
Valid Accounts
Victims(7)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Philander Smith University | United States | Claimed | about 21 hours ago | |
| WARNING | β | Negotiating | 1 day ago | |
| eTeam | United States | Data Leaked | 13 days ago | |
| Trump Mobile | United States | Claimed | 14 days ago | |
| Momentum | United States | Claimed | 16 days ago | |
| Accela | United States | Data Leaked | 19 days ago | |
| AT&T | United States | Claimed | 19 days ago |
Affected countries(1)
Countries where this group has been reported to target or leak victims.