Overview
Sarcoma is a prolific ransomware group operating a leak site with a large victim portfolio spanning multiple industries and geographies. They employ double extortion — stealing data before encrypting systems and threatening to publish if ransom demands go unpaid.
Tactics, Techniques & Procedures
Double extortion, custom ransomware payload, data exfiltration prior to encryption
Primary Targets
Manufacturing, Healthcare, Professional Services
Indicators of Compromise
- Custom ransomware binary
- Cobalt Strike post-exploitation
- Rclone for data exfiltration
MITRE ATT&CK Techniques
T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1059 Command and Scripting Interpreter
Quick Reference
| Status | ACTIVE |
| Type | Ransomware / Data Extortion |
| First Seen | 2023 |
| Victims Tracked | 40 |
Dark Web Presence
http://sarcomawmawlhov7o5mdhz4eszxxlkyaoiyiy2b5iwxnds2dmb4jakad.onion
Under Attack?
If you believe sarcoma has targeted your organisation, contact Binary Response immediately.
Emergency Response Dark Web Monitoring →