Underground

Active
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
26 Victims
May 29, 2023 First Discovered
Aug 15, 2025 Last Discovered
397 Days Inactive
0% Infostealer
1/2 Sites Online
Known Locations (2)
SignIn | Chat
undgrddapc4reaunnrdrmnagvdelqfvmgycuvilgwb5uxm25sxawaoqd.onion
All data | Underground store
47glxkuxyayqrvugfumgsblrdagvrah7gttfscgzn56eyss5wg3uvmqd.onion
Intelligence
Victims (26)

Detailed victim list temporarily unavailable

This group has 26 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.