Spook

Inactive
Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on the Thanos builder), conducting double-extortion attacks against global targets with a concentration in manufacturing and unusually publishing all victim names regardless of ransom payment.
35 Victims
Oct 4, 2021 First Discovered
Oct 19, 2021 Last Discovered
1793 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Spook
spookuhvfyxzph54ikjfwf2mwmxt572krpom7reyayrmxbkizbvkpaid.onion
Victims (35)

Detailed victim list temporarily unavailable

This group has 35 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.