Ransomware needs a way in. Stolen credentials are the cheapest one.
tengu Ransomware Group
Ransomware group profile
Description
Tengu is a ransomware-as-a-service (RaaS) group that emerged in late 2025, known for its hands-on intrusion tactics and double extortion model. They extort victims by first stealing sensitive data before encrypting systems, using Tor for ransom negotiations. The group maintains a strong focus on onboarding skilled affiliates to enhance their operations.
Key insights
- •Initial access typically involves exploiting exposed remote services and valid-account abuse.
- •Tengu utilizes a variety of tools including living-off-the-land binaries and custom utilities for data exfiltration.
- •Their extortion model emphasizes double extortion, with encrypted files tagged with a .tengu extension and threats of data leaks.
- •Tengu employs tactics for defense evasion such as disabling Microsoft Defender and clearing event logs.
- •They leverage Tor-based negotiation portals to communicate with victims during ransom negotiations.
Threat Level & Status Breakdown
For tengu · Based on incidents in selected period
Recent activity
Monthly attack count for tengu in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for tengu
- 8816152e88f7e61a0513761c291c250d71a3a307aebb9be0c3459ccacf77b74e
- 897226af37990fa60f25fea00b0509faa0e78d8bee10875c23b9b6ab0b8faed9
- 91653ba1482bfca55fc18c7bd19bd971
- caef4358921486cea54333bdcde3b61c845deb9c
- c001249e18d30ed109403771854b29d0
- b6d406992411dad0ef80f2b7b61427448bd05540
- e01468756e8407dc41a2205f2e7eb97d223fea3a00c8a27f4830cbb9373d8a99
- 57f1d2cd12856199d68fe0f5322874ad
- 0750489645d263efde56189be97c045cfc8ca890
- fba77450e9135babef898cb7d9b76a52e52615aa59c9bab5281382797e467dde
- d0ffc06381cf9abde735956050751268
- b249800066433c0a8bf23edae719133465247abc
- 3be83d3cefef01d421f2d02136b8e949b3b216239a9a0ada5394ffb55862005b
- 3a1069cd649e22b87cbccf0c36b69f4b
- 097522a52986982b9eefc29f95efdd9d3b6032e7
- 637a1ade3320f80bc9708812de84b767
- 144521ad3baf1fc28ceb4ad26d6fe490ab1b31f4
- 534df73703b26952b1e292dfa5dc4aa22c8c411fd289d8e2fff6b772a0b2a1f6
- da040700e8c0852eaa848fb01138e5b820c6c765
- 197652174622cda52435249bc96a2d82b3613194
- 01c3326ce5beb78a6c106960a3a0868682b97bfa
- 0243692ce6ca522bc1359a3d89d70a229cf76587
- 290e3ec24583a1a3d59bb66be347ab72
- 851b6c0d7c612a0c19cbd8781084dfcc20583ba370e79859f8f999d34323dbaf
- a9d2fec909b88dfff174a70199caacb4
- 96258001bff038cad815bfdaf2caf2188696e88e4286394e6003ea6281c153e5
- aeb5dcc56728a6766e374d161a1b04f1
- 9ca58d87be7823c792eb602a5c766caa7f4de1795aa73973d8bcf29e22eea754
- 65dcfdb32243ec326708f0a0e6424537
- ad42dd9a9117df5a02c6aeecc389e769cdc4c78fd67c480a5e1d29f59bbcbebb
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for tengu
T1070
Indicator Removal
T1218
System Binary Proxy Execution
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1021.001
Remote Desktop Protocol
T1053.005_1
Scheduled Task
Victims(52)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| crown-security.com.tw | Taiwan | Claimed | 5 months ago | |
| Sileno Companies Inc | Switzerland | Claimed | 5 months ago | |
| communitymosaic.co.uk | United Kingdom | Claimed | 5 months ago | |
| Eos Technology srl | Italy | Claimed | 5 months ago | |
| DAINTY CLOUD INC | United States | Claimed | 5 months ago | |
| Al Arif Contracting Co. (L.L.C) | United Arab Emirates | Claimed | 6 months ago | |
| martec.it | Italy | Claimed | 6 months ago | |
| shora.ma | Morocco | Claimed | 6 months ago | |
| femar.it | Italy | Claimed | 6 months ago | |
| 真言宗智山派 成就院 | Japan | Claimed | 6 months ago | |
| 真言宗智山派 成就院 | Japan | Claimed | 6 months ago | |
| Junta Local de Conciliación y Arbitraje | Mexico | Claimed | 6 months ago | |
| PT. Mitra Antar Tangguh | Indonesia | Claimed | 6 months ago | |
| megasilver.com.tw | Taiwan | Claimed | 6 months ago | |
| all Data | Indonesia | Claimed | 6 months ago | |
| We will be back soon | — | Claimed | 6 months ago | |
| b2motorsport.co.il | Israel | Claimed | 6 months ago | |
| Tahkout Group | Algeria | Claimed | 6 months ago | |
| KSP TLM INDONESIA | Indonesia | Claimed | 7 months ago | |
| FRUIT-BONTÉ Agroalimentaire | France | Claimed | 7 months ago |
Page 1 of 3
Affected countries(35)
Countries where this group has been reported to target or leak victims.