Ms13089

Active
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
5 Victims
Dec 18, 2025 First Discovered
Aug 15, 2026 Last Discovered
32 Days Inactive
0% Infostealer
1/1 Sites Online
Known Locations (1)
MS13-089 Blog
msleakjir7pxbe6onlqe5uwgvdmy6nq4mnwfy7ojswbhnleenm77vgad.onion
Victims (5)

Detailed victim list temporarily unavailable

This group has 5 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.