Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

wallstreet Ransomware Group

Ransomware group profile

17Victims
RussiaSource country
58Impact score

Description

Wallstreet is a nascent cyber extortion and ransomware group that emerged in early 2026, focusing on financial gain through data theft and extortion. They utilize double-extortion tactics, targeting various sectors with sensitive data breaches to pressure victims into compliance. Their primary operations are conducted via a Tor-based data leak site.

Key insights

  • Gains access through compromised credentials and remote-access services like VPN and RDP.
  • Utilizes exfiltration tactics to steal sensitive corporate and personal data before public exposure.
  • Employs direct extortion, threatening to leak stolen data unless ransom is paid.
  • Targets organizations in healthcare, municipal law enforcement, manufacturing, and automotive sectors.
  • Operates internationally, with notable activity in the United States and Ecuador.

Threat Level & Status Breakdown

For wallstreet · Based on incidents in selected period

3.7threat level
Aggressiveness6.3/ 10
Lethality0/ 10
Criticality5/ 10

Status Breakdown

Claimed100.0%17
First seenJun 2026
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 17, 2026

Recent activity

Monthly attack count for wallstreet in the selected period

17Total attacks
8peak in Sep
4.3avg / month
↑ 7 vs first month
JunJulAugSep02468

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for wallstreet

Defense Evasion

T1562.001

Disable or Modify Tools

T1070.001

Clear Windows Event Logs

Discovery

T1083

File and Directory Discovery

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021.001

Remote Desktop Protocol

T1080

Taint Shared Content

T1039

Data from Network Shared Drive

Other

T1133

T1133

T1048

T1048

T1567

T1567

Persistence

T1078

Valid Accounts

Victims(17)

IranManufacturingroshdsanatniroo.com
Claimed
2 days ago
United StatesEducationodysseyschools.com
Claimed
2 days ago
United StatesEnergy & Utilitiesgoldstonoil.com
Claimed
8 days ago
United StatesHealthcareondemandoccupationalmedicine.com
Claimed
8 days ago
United StatesOtherncbchurch.org
Claimed
8 days ago
United StatesRetail & E-Commerceafbasket.com
Claimed
15 days ago
United StatesOtherormondbeach.org
Claimed
16 days ago
United StatesEducationtesidea.com
Claimed
17 days ago
United StatesHealthcarecedarcomem.com
Claimed
18 days ago
United StatesEducationandoverma.gov
Claimed
19 days ago
United StatesManufacturingbhbentonite.com
Claimed
about 1 month ago
United StatesTechnologytradna.com
Claimed
about 1 month ago
United StatesHealthcarebcmh.org
Claimed
3 months ago
United StatesManufacturinggoldstandardautomotive.com
Claimed
3 months ago
Ecuadorasisken.com
Claimed
3 months ago
United StatesGovernment & Defenseedgewood-fl.gov
Claimed
3 months ago
IndiaManufacturingomaxauto.com
Claimed
3 months ago

Affected countries(6)

Countries where this group has been reported to target or leak victims.