Tengu

Inactive
Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.
49 Victims
Oct 23, 2025 First Discovered
Mar 7, 2026 Last Discovered
193 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
Shisa Ransomware Blog
longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion
Intelligence
Victims (49)

Detailed victim list temporarily unavailable

This group has 49 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.