Majinahanashi is a financially motivated ransomware group that surfaced in June 2026, employing double-extortion tactics to encrypt files while threatening the disclosure of stolen data. The group is characterized by its use of unique Windows locker optimizations and a focus on non-English-speaking victims across various regions.
Key insights
•Employs custom ransomware that encrypts files with the .majin extension using AES-256 encryption.
•Utilizes double extortion tactics by demanding ransoms and threatening to publish stolen data on a dedicated Tor leak site.
•Targets primarily non-English-speaking organizations in sectors such as e-commerce, manufacturing, and healthcare.
•Strips away defense mechanisms by modifying registry keys and deleting system recovery options.
•Implements complex network disruption tactics using the Windows Filtering Platform to hinder connectivity during attacks.