cheers
First seen May 29, 2022Active15 claimed victims
The claims below are reproduced as posted by cheers on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks against VMware ESXi servers, running a double-extortion leak site with four documented victims.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| DYNAM JAPAN HOLDINGS CO., LTD | September 14, 2022 | ransomware_live | — |
| An Japan Game Halls Operator | September 1, 2022 | ransomware_live | — |
| An British Financial Company -Public | August 18, 2022 | ransomware_live | — |
| An Turkey Certified Public Accountancy Firms -Unpay | August 9, 2022 | ransomware_live | — |
| An Insurance Company -Paid | August 9, 2022 | ransomware_live | — |
| An Insurance Company | July 19, 2022 | ransomware_live | — |
| An International Shipping Company - Paid | July 18, 2022 | ransomware_live | — |
| An British Financial Company -Unpay | July 18, 2022 | ransomware_live | — |
| An International Shipping Company - Unpay | July 1, 2022 | ransomware_live | — |
| https:// | June 30, 2022 | ransomware_live | — |
| Sembcorp Marine - Unpay | June 28, 2022 | ransomware_live | — |
| An International Maritime Company - Unpay | May 29, 2022 | ransomware_live | — |
| An Belgium Hospital - Unpay | May 29, 2022 | ransomware_live | — |
| An Financial Company - Paid | May 29, 2022 | ransomware_live | — |
| An Technology Company - Paid | May 29, 2022 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).