← All ransomware groups
Tengu logo

Ransomware group profile · #97 by claimed victims

Tengu ransomwarealso Shisa

Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.

Active First seen Oct 2025
49Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
25Countries hit
7Leak-site URLs tracked, 0 online
7 Mar 2026Latest claim recorded

Victimology

Who Tengu claims to have breached, from 49 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 6OctNov 2025: 2Dec 2025: 1Jan 2026: 28JanFeb 2026: 8Mar 2026: 4Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Technology10
Manufacturing9
Agriculture and Food Production5
Government & Defense5
Professional Services4
Hospitality4
Retail & E-Commerce3
Other2

Top countries

India5
United States4
Morocco4
Mexico3
Italy3
Indonesia3
United Kingdom2
France2

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Sileno Companies Inc sileno.com Hospitality CH 7 Mar 2026
Communitymosaic.co.uk communitymosaic.co.uk Government & Defense GB 4 Mar 2026
Eos Technology srl eostechnology.net Technology IT 4 Mar 2026
DAINTY CLOUD INC daintycloud.com Technology US 1 Mar 2026
Al Arif Contracting Co. (L.L.C) alarifgroups.ae Manufacturing AE 25 Feb 2026
martec.it martec.it Technology IT 25 Feb 2026
www.shora.ma shora.ma Professional Services MA 20 Feb 2026
femar.it femar.it Professional Services IT 18 Feb 2026
真言宗智山派 成就院 jyojyuin.o.oo7.jp Other JP 18 Feb 2026
Junta Local de Conciliación y Arbitraje cdmx.gob.mx Government & Defense MX 10 Feb 2026
PT. Mitra Antar Tangguh mitratangguh.co.id Professional Services ID 10 Feb 2026
megasilver.com.tw megasilver.com.tw Technology TW 4 Feb 2026

All 49 Tengu victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Tengu is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Tengu ransomware still active?
Tengu is tracked as active. The most recent leak-site claim VULONE recorded is dated 7 March 2026.
How many victims has Tengu claimed?
VULONE has recorded 49 leak-site victim claims attributed to Tengu since October 2025, across 25 countries and 13 sectors.
Which industries does Tengu target?
The sectors most often named on the Tengu leak site are Technology, Manufacturing, Agriculture and Food Production.
Which countries are most affected by Tengu?
Most Tengu victims recorded by VULONE are located in India, United States, Morocco.
Where does VULONE get Tengu victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].