← All ransomware groups

Ransomware group profile · #125 by claimed victims

Spook ransomware

Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on the Thanos builder), conducting double-extortion attacks against global targets with a concentration in manufacturing and unusually publishing all victim names regardless of ransom payment.

Active First seen Oct 2021
35Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
0Countries hit
1Leak-site URLs tracked, 0 online
19 Oct 2021Latest claim recorded

Victimology

Who Spook claims to have breached, from 35 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing10
Professional Services7
Retail & E-Commerce5
Transportation3
Agriculture and Food Production3
Financial Services2
Technology1
Hospitality1

Top countries

No country data yet.

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
North Island Not Found 19 Oct 2021
All County Surveying Inc Professional Services 19 Oct 2021
Page Automation Manufacturing 19 Oct 2021
Toos Asphalt Company Manufacturing 18 Oct 2021
Grupo Vía Transportation 18 Oct 2021
NOF CORPORATION Manufacturing 16 Oct 2021
Apex Filling Systems Manufacturing 16 Oct 2021
Princess Yachts International Retail & E-Commerce 13 Oct 2021
Neofidelys Financial Services 12 Oct 2021
Paris Society Hospitality 12 Oct 2021
VKP Not Found 11 Oct 2021
Ferretti International Manufacturing 11 Oct 2021

All 35 Spook victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Spook is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Spook ransomware still active?
Spook is tracked as active. The most recent leak-site claim VULONE recorded is dated 19 October 2021.
How many victims has Spook claimed?
VULONE has recorded 35 leak-site victim claims attributed to Spook since October 2021, across 0 countries and 10 sectors.
Which industries does Spook target?
The sectors most often named on the Spook leak site are Manufacturing, Professional Services, Retail & E-Commerce.
Which countries are most affected by Spook?
Country data for Spook victims is not yet available.
Where does VULONE get Spook victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].