Ransomware needs a way in. Stolen credentials are the cheapest one.
lamashtu Ransomware Group
Ransomware group profile
Description
Lamashtu is an emerging data extortion group that primarily focuses on financial gain through large-scale exposure of sensitive organizational data. They utilize a unique centralized leak platform to publish victim disclosures and employ peer-to-peer methods for wide dissemination of compromised information. Their dual-impact extortion strategy combines ransom demands with threats of continued public data availability, increasing risk for victims.
Key insights
- •Operates a centralized leak platform for data exposure rather than traditional ransomware.
- •Uses peer-to-peer torrent-based distribution for disseminating stolen data.
- •Employs a dual-impact extortion model, threatening both ransom and public exposure of data.
- •Targets a variety of sectors including health care, real estate, and manufacturing.
- •First observed in April 2026, highlighting its recent emergence as a threat group.
- •Demands ransom payments while simultaneously threatening ongoing exposure of sensitive data.
Threat Level & Status Breakdown
For lamashtu · Based on incidents in selected period
No victim data for this group in the selected period.
Recent activity
Monthly attack count for lamashtu in the selected period
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for lamashtu
T1486
T1486
T1490
T1490
T1041
T1041
T1021
T1021
T1562
T1562
T1071.001
T1071.001
T1048
T1048
T1005
T1005
T1070.001
T1070.001
T1105
T1105
Affected countries(21)
Countries where this group has been reported to target or leak victims.