// THREAT ACTOR
RAZNATOVIC_
DormantRAZNATOVIC is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of RAZNATOVIC — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2024 1
- 2023 5
Leak site mirrors
4 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
f6amq3izzsgtna4vw24rpyhy3ofwazlgex2zqdssavevvkklmtudxjad.onionsnapshot · 2024-06-07 22:03 -
f6amq3izzsgtna4vw24rpyhy3ofwazlgex2zqdssavevvkklmtudxjad.onion404 Not Found snapshot · 2024-06-07 22:03 -
ransomed.vcThe resource cannot be found. snapshot · 2026-04-04 08:41 -
ransomed.vcScreenConnect Remote Support Software snapshot · 2026-04-04 08:23
Recent victims
The 50 most recent victims claimed by RAZNATOVIC. Total in the index: 6.
| Date listed | Victim | Description |
|---|---|---|
| 2024-01-07 | Flash-Motors Last Warning | This is our final warning, if you do not provide us the required payme… |
| 2023-12-26 | Regarding FM | Hello dear FM, did you think we will let you chill because of the holi… |
| 2023-12-26 | FM *censored* | Hello dear FM, did you think we will let you chill because of the holi… |
| 2023-12-12 | TechKids aka MindX | Data contains 600 million lines, almost 20gb. 5 files. … |
| 2023-12-12 | SKF.com | Maybe Next time you will learn paying a ransomw will cost you less 🙂 … |
| 2023-12-12 | Colonial Pipeline | Colonial Pipiline files, hey rob lee? Remember us! W… |