icefire
First seen August 20, 2022Active11 claimed victims
The claims below are reproduced as posted by icefire on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability in IBM Aspera Faspex (CVE-2022-47986), targeting media and entertainment organizations in Turkey, Iran, Pakistan, and the UAE using double-extortion tactics.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| *.skifgroup.com | August 20, 2022 | ransomware_live | — |
| *.feesh.ch | August 20, 2022 | ransomware_live | — |
| *.directfn.net | August 20, 2022 | ransomware_live | — |
| *.kru.ac.th | August 20, 2022 | ransomware_live | — |
| *.kodhosting.com | August 20, 2022 | ransomware_live | — |
| *.guneshosting.com | August 20, 2022 | ransomware_live | — |
| *.vps-vds.com | August 20, 2022 | ransomware_live | — |
| *.cco1.com | August 20, 2022 | ransomware_live | — |
| *.iperactive.com.ar | August 20, 2022 | ransomware_live | — |
| *.bestservers.pro | August 20, 2022 | ransomware_live | — |
| *.algotrader.com | August 20, 2022 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).