BreachCensus

icefire

First seen August 20, 2022Active11 claimed victims

The claims below are reproduced as posted by icefire on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability in IBM Aspera Faspex (CVE-2022-47986), targeting media and entertainment organizations in Turkey, Iran, Pakistan, and the UAE using double-extortion tactics.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
*.skifgroup.comAugust 20, 2022ransomware_live
*.feesh.chAugust 20, 2022ransomware_live
*.directfn.netAugust 20, 2022ransomware_live
*.kru.ac.thAugust 20, 2022ransomware_live
*.kodhosting.comAugust 20, 2022ransomware_live
*.guneshosting.comAugust 20, 2022ransomware_live
*.vps-vds.comAugust 20, 2022ransomware_live
*.cco1.comAugust 20, 2022ransomware_live
*.iperactive.com.arAugust 20, 2022ransomware_live
*.bestservers.proAugust 20, 2022ransomware_live
*.algotrader.comAugust 20, 2022ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).