Ransomware Intelligence

tengu

Ransomware group profile

53Victims
64Impact score

Description

Tengu is a ransomware-as-a-service (RaaS) group that emerged in late 2025, known for its hands-on intrusion tactics and double extortion model. They extort victims by first stealing sensitive data before encrypting systems, using Tor for ransom negotiations. The group maintains a strong focus on onboarding skilled affiliates to enhance their operations.

Key insights

  • Initial access typically involves exploiting exposed remote services and valid-account abuse.
  • Tengu utilizes a variety of tools including living-off-the-land binaries and custom utilities for data exfiltration.
  • Their extortion model emphasizes double extortion, with encrypted files tagged with a .tengu extension and threats of data leaks.
  • Tengu employs tactics for defense evasion such as disabling Microsoft Defender and clearing event logs.
  • They leverage Tor-based negotiation portals to communicate with victims during ransom negotiations.

Threat Level & Status Breakdown

For tengu · Based on incidents in selected period

2.2threat level
Aggressiveness5/ 10
Lethality0.1/ 10
Criticality1.4/ 10

Status Breakdown

Data Leaked1.9%1
Claimed98.1%52
First seenOct 2025
Last seenMar 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for tengu in the selected period

53Total attacks
28peak in Jan
8.8avg / month
↓ 2 vs first month
OctNovDecJanFebMar07142128

Intelligence

IOCs, YARA/Sigma rules, and related families for tengu

  1. b400c58e7e227361cc689078ce9163c4
  2. 3b18e9da970fa7d336b08c5df04668b7
  3. 511a4780cbd9ed2280b432afc6cbfd1a
  4. 62c6ba7f5356663c46b8918b6a0994fc
  5. b8c81e1e17adcaf9e84d76401697b7e5
View full IOC feed25 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for tengu

Defense Evasion

T1070

Indicator Removal

T1218

System Binary Proxy Execution

Execution

T1059.001

PowerShell

T1059.003

Windows Command Shell

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021.001

Remote Desktop Protocol

Persistence

T1053.005_1

Scheduled Task

Victims(53)

CompanyDomainCountryIndustryStatusDiscovered
crown-security.com.twTW TaiwanTechnology
Claimed
3 months ago
Sileno Companies Incsileno.comCH SwitzerlandManufacturing
Claimed
3 months ago
Communitymosaic.co.ukcommunitymosaic.co.ukGB United KingdomEnergy & Utilities
Claimed
3 months ago
Eos Technology srleostechnology.netIT ItalyEducation
Claimed
3 months ago
DAINTY CLOUD INCdaintycloud.comUS United StatesTechnology
Claimed
3 months ago
Al Arif Contracting Co. (L.L.C)alarifgroups.aeAE United Arab EmiratesOther
Claimed
3 months ago
martec.itmartec.itIT ItalyTechnology
Claimed
3 months ago
www.shora.mashora.maMA MoroccoHospitality
Claimed
3 months ago
femar.itfemar.itIT ItalyProfessional Services
Claimed
4 months ago
真言宗智山派 成就院JP JapanManufacturing
Claimed
4 months ago
真言宗智山派 成就院jyojyuin.o.oo7.jpJP JapanProfessional Services
Claimed
4 months ago
Junta Local de Conciliación y Arbitrajecdmx.gob.mxMX MexicoGovernment & Defense
Claimed
4 months ago
PT. Mitra Antar Tangguhmitratangguh.co.idID IndonesiaProfessional Services
Claimed
4 months ago
megasilver.com.twmegasilver.com.twTW TaiwanTechnology
Claimed
4 months ago
all DataID IndonesiaTechnology
Claimed
4 months ago
We will be back soonTechnology
Claimed
4 months ago
b2motorsport.co.ilb2motorsport.co.ilIL IsraelRetail & E-Commerce
Claimed
4 months ago
Tahkout GroupDZ AlgeriaManufacturing
Claimed
4 months ago
KSP TLM INDONESIAcooptlmindonesia.comID IndonesiaFinancial Services
Claimed
4 months ago
FRUIT-BONTÉ Agroalimentairemda-agro.comFR FranceOther
Claimed
4 months ago

Page 1 of 3