// THREAT ACTOR
RANSOMEDVC2_
ActiveRANSOMEDVC2 is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of RANSOMEDVC2 — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 4
Leak site mirrors
2 mirrors tracked, 1 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
ransomed.bizTest Page for the HTTP Server on AlmaLinux snapshot · 2026-08-06 21:31 -
ransomed.vcScreenConnect Remote Support Software snapshot · 2026-03-27 04:07
Recent victims
The 50 most recent victims claimed by RANSOMEDVC2. Total in the index: 4.
| Date listed | Victim | Description |
|---|---|---|
| 2025-08-05 | kixat.com | $13M Kixat is a shopping platform that offers a personalized way fo… |
| 2025-07-10 | Medusa | Medusa ransomware gang uncovered; Sponsored by Ran… |
| 2025-07-09 | snapav.com / resideo.com | $1.1 Billion Snap AV / Resideo has suffered a major data breach. Desp… |
| 2025-07-09 | unyleya.edu.br | $150 Million Unyleya is an educational group that has been developing… |