Ransomware group profile · #480 by claimed victims
Hotarus ransomware
Hotarus Corp is a ransomware group that came to attention in early 2021 after attacking Ecuador's Ministry of Finance and Banco Pichincha — the country's largest private bank — deploying PHP-based ransomware and claiming to have stolen tens of millions of customer records.
Tactics, techniques and procedures
ATT&CK technique mapping for Hotarus is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Hotarus ransomware still active?
How many victims has Hotarus claimed?
Which industries does Hotarus target?
Which countries are most affected by Hotarus?
Where does VULONE get Hotarus victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].