Ransomware needs a way in. Stolen credentials are the cheapest one.
pear Ransomware Group
Ransomware group profile
Description
The PEAR group, known for its ransomware operations, specializes in data exfiltration and extortion since its emergence in July 2025. They aim to steal sensitive information and threaten to release it unless a ransom is paid, using techniques that obscure their identity and intentions. Operating with a low-noise, high-pressure approach, they manipulate victims by posing as legitimate penetration testers during negotiations.
Key insights
- •PEAR operates as a ransom group focusing on data theft rather than encryption.
- •Common initial access methods include credential abuse, phishing, and exploiting unsecured VPNs.
- •The group maintains an average dwell time of approximately 41 days in compromised networks.
- •Communication methods associated with PEAR include contact via Tox and pseudonymous email.
- •They threaten to publish exfiltrated data on their leak site if ransom negotiations fail.
Threat Level & Status Breakdown
For pear · Based on incidents in selected period
Recent activity
Monthly attack count for pear in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for pear
- onionmail.org
- pearsmob5sn44ismokiusuld34pnfwi6ctgin3qbvonpoob4lh3rmtqd.onion
- peargxn3oki34c4savcbcfqofjjwjnnyrlrbszfv6ujlx36mhrh57did.onion
- xq5m6ofel63h57by46algju25g37zkdwoxxt7ij45b6obo4mxzc3h6id.onion
- xsomiaq5awxh3zkzn334s3dgwuvngy6z2to7265exgovnkwk66hjypid.onion
- 5qynbyjl4u6vbtnmpokslaxaknyicdvty7vn2qgxmaty3lb7wwxpkbid.onion
- etus2tmakckdlkyjpevoyciuao7er5fj3qm26aev3nch4fusptefiayd.onion
- q2bg7ljsrpmy6736qqmpwsnqqm3w6d3hhrokohytnmldbom7sthp4sad.onion
- m3wwhkus4dxbnxbtihexlyd2cv63qrvex6jiebc4vqe22kg2z3udebid.onion
- e7a6zgqfijn2ko6lzkz53tysjpnf22fxj4h2f3saufrmsts5pbul5eid.onion
- glheoet37vdimgho57tqj76v7fnebnbqxn65bounxyt6hduilkso4yyd.onion
- psvrn6ahevi6dgf55bzc26q3gjc7s6n7vcth34rmkl2y7e7dijhjfiqd.onion
- yxwomyfmexm3bfcuumnugrzwluol5qwsw6pmne7jklgmzthkp35l2jqd.onion
- aw6wb6lmqbtp5po7qrmvmujulbxw4eeeolpg3byva2bgoj44psdugmid.onion
- csxilwnl7orv6rwfjen5ye3tefk5shjtr4tysuykgxjsyngpvoqrvbid.onion
- 757ylxaeemidrhrmmuz6rkxw5jlk65oqou3lvi6evxtrr2nhm5ytmrqd.onion
- diyr2bnty7iktyxfd4kz65uigcfappjvux73dpgkkeocp3fmlgnuzyyd.onion
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for pear
T1486
T1486
T1490
T1490
T1078
T1078
T1021
T1021
T1562
T1562
T1047
T1047
T1021.001
T1021.001
T1059
T1059
T1389
T1389
T1105
T1105
T1071.001
T1071.001
Victims(84)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Foss Inc. | United States | Claimed | 7 days ago | |
| Kovo Healthtech Corp | United States | Claimed | 14 days ago | |
| EdgeChem Jamaica Limited | Jamaica | Claimed | 15 days ago | |
| Next Level Urgent Care | United States | Claimed | 23 days ago | |
| Island Networks | Jamaica | Claimed | 27 days ago | |
| Mogren, Glessner & Ahrens | United States | Claimed | 27 days ago | |
| First Commerce LLC | United States | Claimed | 28 days ago | |
| Clifton Architectural Glass and Metal | United States | Claimed | 28 days ago | |
| Medical Arts Chemists and Surgicals | United States | Claimed | 29 days ago | |
| Practi-Cal | United States | Claimed | 29 days ago | |
| Austin Plastic Surgery Institute | United States | Claimed | 29 days ago | |
| Club One Casino | United States | Claimed | 29 days ago | |
| Metropolitan Construction Systems | United States | Claimed | about 2 months ago | |
| Faro | Canada | Claimed | 2 months ago | |
| Sonitor | United States | Claimed | about 2 months ago | |
| CNW Electronics Pte Ltd | Singapore | Claimed | 3 months ago | |
| AC Beverage, Inc. | United States | Claimed | 3 months ago | |
| Sociedad Latina | United States | Claimed | 3 months ago | |
| TNT CPA's | United States | Claimed | 2 months ago | |
| ORA-ELBA Group | France | Claimed | 3 months ago |
Page 1 of 5
Affected countries(45)
Countries where this group has been reported to target or leak victims.