// THREAT ACTOR
MIGA_
DormantMIGA is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of MIGA — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 6
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
q7gmt7pbo4rrt27ydkiv2kxd7cimhztq2x7hzd557jthhu5zp6ujieid.onionMakeIsraelGreatAgain snapshot · 2025-09-29 20:19
Recent victims
The 50 most recent victims claimed by MIGA. Total in the index: 6.
| Date listed | Victim | Description |
|---|---|---|
| 2025-09-24 | curaleaf.com | |
| 2025-09-24 | unyleya.com.br | |
| 2025-09-24 | discoverasr.com+wechat.com | |
| 2025-09-24 | kixat.com | |
| 2025-09-24 | arteza.com | |
| 2025-09-24 | resideo.com |