← All ransomware groups

Ransomware group profile · #122 by claimed victims

Arvinclub ransomware

Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via a TOR site and Telegram rather than deploying file-encrypting ransomware, targeting government, education, and banking sectors globally including Iranian government entities.

Active First seen Sep 2021
35Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
5Countries hit
2Leak-site URLs tracked, 0 online
15 Oct 2023Latest claim recorded

Victimology

Who Arvinclub claims to have breached, from 35 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Agriculture and Food Production4
Education4
Technology4
Financial Services4
Retail & E-Commerce3
Manufacturing3
Other3
Government & Defense3

Top countries

Iran8
Colombia3
United Kingdom1
Russia1
India1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Islamic Azad University Electronic Campus ec.iau.ir Education IR 15 Oct 2023
Jahesh Innovation jahesh.co Technology CO 14 Oct 2023
Kimia Tadbir Kiyan ktkco.ir Manufacturing IR 13 Oct 2023
Islamic Azad University of Shiraz shiraz.iau.ir Education IR 8 Oct 2023
Pasouk biological company pasouk.ir Agriculture and Food Production IR 2 Oct 2023
Shirin Travel Agency anonissfireenterfdks2u53jqevumbu6hjm35ioorsa7eq5bsjlucad.onion Hospitality 1 Oct 2023
Aban Tether & OK exchange Financial Services 2 Sep 2023
sti company sticompany.co Other CO 23 Aug 2023
Sabalan Azmayesh sabalanmedical.ir Healthcare IR 9 Aug 2023
Parsian Bitumen parsianbitumen.com Agriculture and Food Production 7 Aug 2023
Draje food industrial group draje.ir Agriculture and Food Production IR 6 Aug 2023
seaside-kish co Not Found 4 Aug 2023

All 35 Arvinclub victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Arvinclub is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Arvinclub ransomware still active?
Arvinclub is tracked as active. The most recent leak-site claim VULONE recorded is dated 15 October 2023.
How many victims has Arvinclub claimed?
VULONE has recorded 35 leak-site victim claims attributed to Arvinclub since September 2021, across 5 countries and 13 sectors.
Which industries does Arvinclub target?
The sectors most often named on the Arvinclub leak site are Agriculture and Food Production, Education, Technology.
Which countries are most affected by Arvinclub?
Most Arvinclub victims recorded by VULONE are located in Iran, Colombia, United Kingdom.
Where does VULONE get Arvinclub victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].