Icefire

Inactive
IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability in IBM Aspera Faspex (CVE-2022-47986), targeting media and entertainment organizations in Turkey, Iran, Pakistan, and the UAE using double-extortion tactics.
11 Victims
Aug 20, 2022 First Discovered
Aug 20, 2022 Last Discovered
1488 Days Inactive
0% Infostealer
0/2 Sites Online
Known Locations (2)
Leakage List
kf6x3mjeqljqxjznaw65jixin7dpcunfxbbakwuitizytcpzn4iy5bad.onion
Leakage List
7kstc545azxeahkduxmefgwqkrrhq3mzohkzqvrv7aekob7z3iwkqvyd.onion
Intelligence
Victims (11)

Detailed victim list temporarily unavailable

This group has 11 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.