// THREAT ACTOR
GROOVE_
DormantGROOVE is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of GROOVE — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2021 13
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
ws3dh6av66sjbxxkjpw5ao3wqzmtejnkzheswm4dz5rrwvular7xvkqd.onionУтечки | Groove snapshot · 2021-10-30 10:50
Recent victims
The 50 most recent victims claimed by GROOVE. Total in the index: 13.
| Date listed | Victim | Description |
|---|---|---|
| 2021-10-30 | Я не пью виски но с ним бы выпил | |
| 2021-10-23 | episcopalretirement.com Возможна утечка | |
| 2021-10-23 | Про русских в США | |
| 2021-10-23 | therecord.media 30k USD | |
| 2021-10-22 | hagerstownpd.org | |
| 2021-10-22 | trivalleypc.com | |
| 2021-09-13 | robinwoodortho.com | |
| 2021-09-10 | Одно интервью | |
| 2021-09-10 | Украина и экстрадиции в США | |
| 2021-09-09 | ludofact.de 50 GB data stolen | |
| 2021-09-09 | Мысли о смысле | |
| 2021-09-09 | Запатченные fortinet точки входа | |
| 2021-09-09 | Мы можем просто договориться |