Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

TiMc Ransomware Group

Ransomware group profile

6Victims
40Impact score

Description

TiMc is a ransomware group that surfaced in April 2026, focusing on financial gain through double extortion tactics. They are known for exfiltrating large amounts of sensitive data and threatening public exposure to coerce victims into paying ransoms.

Key insights

  • •Utilizes a double extortion model involving data exfiltration and ransom demands.
  • •Targets a diverse range of organizations across multiple countries.
  • •Specializes in stealing high-value data such as Personally Identifiable Information and proprietary source code.
  • •Compromises critical infrastructure including Domain Controllers and File Servers for extensive data access.
  • •Threatens to publish extensive data on leak sites to increase pressure on victims.

Threat Level & Status Breakdown

For TiMc · Based on incidents in selected period

1.8threat level
Aggressiveness0.8/ 10
Lethality0/ 10
Criticality5/ 10

Status Breakdown

Claimed100.0%6
First seenApr 2026
Last seenSep 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedOct 8, 2026

Recent activity

Monthly attack count for TiMc in the selected period

6Total attacks
3peak in Apr
3avg / month
AprSep00.751.52.253

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for TiMc

Other

T1486

T1486

T1490

T1490

T1041

T1041

T1021

T1021

T1071.001

T1071.001

T1080

T1080

T1562

T1562

T1005

T1005

T1048

T1048

T1078

T1078

T1565

T1565

T1030

T1030

Victims(3)

ArgentinaHealthcaredebene.com
Claimed
6 months ago
United StatesTechnologyseidor.com
Claimed
6 months ago
United StatesHealthcareoncologica.com
Claimed
6 months ago

Affected countries(4)

Countries where this group has been reported to target or leak victims.