Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

secp0 Ransomware Group

Ransomware group profile

7Victims
RussiaSource country
53Impact score

Description

Secp0 is a ransomware group that first emerged in February 2025, known for leveraging double-extortion tactics by encrypting data and threatening public disclosure unless a ransom is paid. The group primarily targets Linux systems and ESXi environments with customized malware developed using C/C++. Their unique focus includes creating accessible data formats for their extorted information.

Key insights

  • Targets Linux systems and ESXi environments with custom ELF binaries.
  • Initial access often gained through compromised accounts and exploiting vulnerabilities like CVE-2023-20269.
  • Employs double-extortion tactics, encrypting files and stealing sensitive information for extortion.
  • Ransomware uses ChaCha20 encryption with ECDH key exchange and appends '.secp0' to encrypted files.
  • Utilizes Bash one-liners for execution and deployment of the ransomware loader.
  • Claims to develop software for publishing datasets in more user-friendly formats.
  • Maintains persistence by abusing valid accounts to evade detection.

Threat Level & Status Breakdown

For secp0 · Based on incidents in selected period

1threat level
Aggressiveness2.8/ 10
Lethality0/ 10
Criticality0/ 10

Status Breakdown

Claimed100.0%7
First seenMar 2026
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 21, 2026

Recent activity

Monthly attack count for secp0 in the selected period

7Total attacks
5peak in Mar
2.3avg / month
↓ 4 vs first month
MarAprSep02468

Intelligence

IOCs, YARA/Sigma rules, and related families for secp0

  1. secp0-support.net
  2. 2a6w667vebiebciji7vm3vj43svegvozoqypttdgojzgdcbnfsu5wiid.onion
  3. bhn2xz5jer2xeibxjzhgfp7qclttnbvkkvd4hvlmjbnz66jxq7yzn6ad.onion
  4. secp0-support.cfd
  5. secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onion
View full IOC feed5 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for secp0

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1585

T1585

T1562

T1562

T1059

T1059

T1021

T1021

T1046

T1046

T1485

T1485

T1531

T1531

T1203

T1203

Victims(7)

United StatesProfessional Services
Claimed
about 4 hours ago
United StatesTechnology
Claimed
5 months ago
Professional Services
Claimed
7 months ago
Claimed
7 months ago
Other
Claimed
7 months ago
JamaicaOther
Claimed
7 months ago