Beast

Active
Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.
73 Victims
Dec 19, 2023 First Discovered
Aug 29, 2026 Last Discovered
18 Days Inactive
0% Infostealer
1/2 Sites Online
Known Locations (2)
BEAST LEAKS | Index
beast6azu4f7fxjakiayhnssybibsgjnmy77a6duufqw5afjzfjhzuqd.onion
Index of /
ooie6tet7ggcmlgvtmyvok4s6vha6ecwczssbchbyxrg2r6v2m6zkkad.onion
Tools Used
CredentialTheft
Automim, LaZagne, Mimikatz
DiscoveryEnum
Advanced IP Scanner, Advanced Port Scanner, Everything.exe, SoftPerfect NetScan
Exfiltration
MEGA, WinSCP
LOLBAS
PsExec
Networking
Klink, OpenSSH
RMM-Tools
AnyDesk
Intelligence
Victims (73)

Detailed victim list temporarily unavailable

This group has 73 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.