← Back to Ransomware Chk

Onepercent

Inactive
OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using phishing with IcedID trojans, Cobalt Strike, and double-extortion, threatening a "one percent leak" of data before escalating to a full dump or sale to REvil; the FBI issued a formal flash advisory in August 2021.
0 Victims
0% Infostealer
0/1 Sites Online
Known Locations (1)
5mvifa3xq5m7sou3xzaajfz7h6eserp5fnkwotohns5pgbb5oxty3zad.onion
Tools Used
CredentialTheft
BetterSafetyKatz, Mimikatz, SharpKatz
Exfiltration
RClone
Offsec
Cobalt Strike, SharpSploit
Victims (0)

Detailed victim list temporarily unavailable

This group has 0 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.