Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

lamashtu Ransomware Group

Ransomware group profile

34Victims
62Impact score

Description

Lamashtu is an emerging data extortion group that primarily focuses on financial gain through large-scale exposure of sensitive organizational data. They utilize a unique centralized leak platform to publish victim disclosures and employ peer-to-peer methods for wide dissemination of compromised information. Their dual-impact extortion strategy combines ransom demands with threats of continued public data availability, increasing risk for victims.

Key insights

  • Operates a centralized leak platform for data exposure rather than traditional ransomware.
  • Uses peer-to-peer torrent-based distribution for disseminating stolen data.
  • Employs a dual-impact extortion model, threatening both ransom and public exposure of data.
  • Targets a variety of sectors including health care, real estate, and manufacturing.
  • First observed in April 2026, highlighting its recent emergence as a threat group.
  • Demands ransom payments while simultaneously threatening ongoing exposure of sensitive data.

Threat Level & Status Breakdown

For lamashtu · Based on incidents in selected period

No victim data for this group in the selected period.

First seenApr 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 16, 2026

Recent activity

Monthly attack count for lamashtu in the selected period

34Total attacks
17peak in Apr
11.3avg / month
↓ 15 vs first month
AprMayJun05101520

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for lamashtu

Other

T1486

T1486

T1490

T1490

T1041

T1041

T1021

T1021

T1562

T1562

T1071.001

T1071.001

T1048

T1048

T1005

T1005

T1070.001

T1070.001

T1105

T1105