← All ransomware groups

Ransomware group profile · #123 by claimed victims

AuditTeam ransomware

AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and Southeast Asia across technology and manufacturing sectors, operating a data leak site consistent with double-extortion methodology.

Active First seen Apr 2026
35Victims claimed on leak sites
20Victims in the last 30 days
21Victims in the last 90 days
14Countries hit
0Leak-site URLs tracked
14 Sep 2026Latest claim recorded

Victimology

Who AuditTeam claims to have breached, from 35 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 5AprMay 2026: 6Jun 2026: 4Jul 2026: 0JulAug 2026: 4Sep 2026: 16

Top sectors

Technology6
Transportation2
Manufacturing2
Other1
Retail & E-Commerce1
Financial Services1
Government & Defense1

Top countries

Russia16
South Korea3
Colombia2
Germany2
Senegal2
Turkiye1
India1
Thailand1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Ne***ox Technology RU 14 Sep 2026
Paid Victim F9CF4B639CAC1B18 Not Found RU 13 Sep 2026
Paid Victim FDC699DE3A112669 Not Found DE 13 Sep 2026
vi***in Transportation IN 13 Sep 2026
TE***PB Not Found RU 12 Sep 2026
ki***jp Not Found JP 10 Sep 2026
my***ru Technology RU 10 Sep 2026
mo***al Not Found DE 9 Sep 2026
dg***kr Not Found KR 9 Sep 2026
go***et Technology KR 9 Sep 2026
kr***rg Not Found AR 9 Sep 2026
bu***en Not Found RU 8 Sep 2026

All 35 AuditTeam victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for AuditTeam is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is AuditTeam ransomware still active?
AuditTeam is tracked as active. The most recent leak-site claim VULONE recorded is dated 14 September 2026. 20 victims were claimed in the last 30 days.
How many victims has AuditTeam claimed?
VULONE has recorded 35 leak-site victim claims attributed to AuditTeam since April 2026, across 14 countries and 8 sectors.
Which industries does AuditTeam target?
The sectors most often named on the AuditTeam leak site are Technology, Transportation, Manufacturing.
Which countries are most affected by AuditTeam?
Most AuditTeam victims recorded by VULONE are located in Russia, South Korea, Colombia.
Where does VULONE get AuditTeam victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].