Benzona

Inactive
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
14 Victims
Nov 26, 2025 First Discovered
Jan 30, 2026 Last Discovered
229 Days Inactive
0% Infostealer
0/2 Sites Online
Known Locations (2)
Benzona Ransomware
benzona6x5ggng3hx52h4mak5sgx5vukrdlrrd3of54g2uppqog2joyd.onion
Support Chat
rwsu75mtgj5oiz3alkfpnxnopcbiqed6wllyoffpuruuu6my6imjzuqd.onion
Intelligence
Victims (14)

Detailed victim list temporarily unavailable

This group has 14 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.