Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

majinahanashi Ransomware Group

Ransomware group profile

37Victims
JapanSource country
60Impact score

Description

Majinahanashi is a financially motivated ransomware group that surfaced in June 2026, employing double-extortion tactics to encrypt files while threatening the disclosure of stolen data. The group is characterized by its use of unique Windows locker optimizations and a focus on non-English-speaking victims across various regions.

Key insights

  • •Employs custom ransomware that encrypts files with the .majin extension using AES-256 encryption.
  • •Utilizes double extortion tactics by demanding ransoms and threatening to publish stolen data on a dedicated Tor leak site.
  • •Targets primarily non-English-speaking organizations in sectors such as e-commerce, manufacturing, and healthcare.
  • •Strips away defense mechanisms by modifying registry keys and deleting system recovery options.
  • •Implements complex network disruption tactics using the Windows Filtering Platform to hinder connectivity during attacks.

Threat Level & Status Breakdown

For majinahanashi · Based on incidents in selected period

Status Breakdown

Data Leaked44.7%17
Claimed55.3%21
First seenJul 2026
Last seenSep 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedOct 6, 2026

Recent activity

Monthly attack count for majinahanashi in the selected period

37Total attacks
18peak in Sep
12.3avg / month
↑ 10 vs first month
JulAugSep05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for majinahanashi

  1. 914ff51fb60247cf13897b1bc950a190
  2. 6f9e1371427be15a840c2de5eb1719a466af2016
  3. bd91d786841f5259430c1c90b454d9f8bf510186fe4d32a0998bd9b5a7916467
  4. e6ec7749e3d0f750fa53b5a7619d1e5af57673d236338b3a020d0f534ec5c15d
  5. d213bccd00f98d8af608186035bc8bf814e13364
  6. 7ee443b0530bb9fe4c36c0faafdeb6bc
  7. 20294fe9ec6b7763a8fd58f23be53be7
View full IOC feed10 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for majinahanashi

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

T1080

Taint Shared Content

Other

T1045

T1045

T1569

T1569

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution