desolator
First seen August 30, 2025Active4 claimed victims
The claims below are reproduced as posted by desolator on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| LEVEL | August 31, 2025 | ransomware_live | — |
| Construcciones Sala | August 28, 2025 | ransomware_live | — |
| Construseñales S.A. | August 28, 2025 | ransomware_live | — |
| Tri Thuc Software | August 27, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).