← All ransomware groups

Ransomware group profile · #126 by claimed victims

Lamashtu ransomware

Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Romania, and Thailand across energy, pharmaceutical, and film sectors; it has not yet been confirmed as operating actual file-encrypting ransomware rather than pure data-theft extortion.

Active First seen Apr 2026
34Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
17Countries hit
1Leak-site URLs tracked, 1 online
17 Jun 2026Latest claim recorded

Victimology

Who Lamashtu claims to have breached, from 34 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 17AprMay 2026: 15Jun 2026: 2Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing8
Professional Services5
Agriculture and Food Production4
Retail & E-Commerce4
Hospitality3
Healthcare2
Energy & Utilities2
Transportation2

Top countries

Malaysia5
France4
Thailand3
Germany3
Mexico3
India2
Egypt2
Italy2

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Great Foods greatfoods.com.eg Agriculture and Food Production EG 17 Jun 2026
PatayaFood patayafood.com Agriculture and Food Production TH 10 Jun 2026
Shanpoornam Metals shanpoornammetals.com Manufacturing MY 29 May 2026
H-W-G & Acros Sport h-w-g.com Retail & E-Commerce DE 26 May 2026
ROTH‑TECHNIK AUSTRIA rothtechnik.eu Manufacturing AT 19 May 2026
MSC Group msmelt.com Transportation MY 18 May 2026
Parle Agro parleagro.com Agriculture and Food Production IN 16 May 2026
NaRaYa naraya.com Retail & E-Commerce TH 12 May 2026
Saharuang saharuang.com Other TH 12 May 2026
Depósito Dental Universitario ddu.mx Healthcare MX 11 May 2026
Sistemas Electrónicos y de Telecomunicaciones sertes.com.mx Technology MX 11 May 2026
Acros Sport GmbH acros-components.com Manufacturing DE 8 May 2026

All 34 Lamashtu victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Lamashtu is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Lamashtu ransomware still active?
Lamashtu is tracked as active. The most recent leak-site claim VULONE recorded is dated 17 June 2026.
How many victims has Lamashtu claimed?
VULONE has recorded 34 leak-site victim claims attributed to Lamashtu since April 2026, across 17 countries and 10 sectors.
Which industries does Lamashtu target?
The sectors most often named on the Lamashtu leak site are Manufacturing, Professional Services, Agriculture and Food Production.
Which countries are most affected by Lamashtu?
Most Lamashtu victims recorded by VULONE are located in Malaysia, France, Thailand.
Where does VULONE get Lamashtu victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].