Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

iah6477 Ransomware Group

Ransomware group profile

5Victims
12Impact score

Description

iah6477 is a financial motivation-driven extortion and ransomware group that surfaced in August 2026. It primarily targets enterprises in the United States, employing double extortion tactics to extract ransom payments while threatening to leak sensitive data online. The group uses sophisticated methods for initial access, including infostealer malware and compromised corporate credentials.

Key insights

  • Targets organizations in the financial services, consumer retail, and technology sectors.
  • Utilizes compromised corporate credentials to gain access to systems.
  • Maintains dark web infrastructure on the Tor network for extortion activities.
  • Exfiltrates large volumes of sensitive data prior to extortion demands.
  • Implements double-extortion tactics by threatening public data leaks.

Threat Level & Status Breakdown

For iah6477 · Based on incidents in selected period

1.1threat level
Aggressiveness3.3/ 10
Lethality0/ 10
Criticality0/ 10

Status Breakdown

Claimed100.0%5
First seenAug 2026
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 28, 2026

Recent activity

Monthly attack count for iah6477 in the selected period

5Total attacks
5peak in Aug
5avg / month
Aug02468

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for iah6477

Collection

T1071

Application Layer Protocol

Defense Evasion

T1562

Impair Defenses

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

Other

T1048

T1048

T1539

T1539

T1553

T1553

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(5)

United StatesManufacturing
Claimed
2 days ago
United StatesManufacturing
Claimed
2 days ago
United StatesRetail & E-Commerceregencycenters.com
Claimed
8 days ago
United StatesFinancial Servicesacima.com
Claimed
8 days ago
NamibiaTechnology
Claimed
8 days ago

Affected countries(2)

Countries where this group has been reported to target or leak victims.