#APT73
Btw, kedy ste si naposledy menili heslo na centrum_sk? :)
www.ransomware.live/id/Y2VudHJ1b...
Victim: centrum.sk – apt73
Ransomware.live discovered on 2026-04-27 that centrum.sk has been claimed by Apt73 ransomware group
www.ransomware.live
August 31, 2026 at 12:20 PM
🚨 nuova rivendicazione #ransomware Italia 🚨

🏴‍☠️ gruppo #APT73 BASHE
🧬 Flazio S.R.L. | San Giovanni la Punta (CT)
🎯 settore: K - Telecom/IT
🔗 flazio.com
🗓️ 01 luglio 2026

📄 sample: sì
▪️ dati esfiltrati dichiarati: -
▪️ dati esfiltrati pubblicati: -
⏲️ scadenza: 10 luglio 2026

#ransomNews #cyberthreats
July 2, 2026 at 6:33 PM
Armenia's elections.mia.gov.am was hit by a ransomware claim from WOLVES OF TURAN, linked to APT73, with extortion messaging targeting a public sector victim. #Armenia #Ransomware #APT73
Ransom! elections.mia.gov.am from WOLVES OF TURAN (JUN-2026)
Elections.mia.gov.am, in Armenia, was targeted in a ransomware claim by “WOLVES OF TURAN,” attributed to threat actor APT73. The attackers’ contact and extortion messaging referenced their operation against the victim, impacting Armenia #Armenia
www.hendryadrian.com
June 2, 2026 at 11:30 PM
New post from #Eraleign (Apt73) : Elections.Mia.Gov.Am From Wolves Of Turan
More at : https://www.ransomlook.io/group/Eraleign%20(Apt73) #Ransomware
June 2, 2026 at 12:48 PM
According to Ransomware.live, apt73 ransomware group has added haca.ma (🇲🇦) to its victims.
April 27, 2026 at 4:51 PM
Ransomware disrupted services and encrypted data at Thailand's National Astronomical Research Institute, with activity attributed to APT73. Operations in #Thailand were affected. #NARIT #APT73
Ransom! narit.or.th (MAY-2026)
Narit.or.th in Thailand was impacted by ransomware activity attributed to the threat actor APT73, associated with The National Astronomical Research Institute of Thailand. The attack resulted in disruption of services and data encryption, affecting operations in #Thailand
www.hendryadrian.com
May 21, 2026 at 7:00 PM
According to https://ransomware.live, apt73 ransomware group has added www.polleninformation.at to its victims.
November 27, 2024 at 8:41 PM
According to Ransomware.live, apt73 ransomware group has added elections.mia.gov.am from WOLVES OF TURAN (🇦🇲) to its victims.
June 2, 2026 at 12:50 PM
#lockbit3 has listed multiple ransomware gangs as affiliates: qlin, blacksuit, play, blackbasta, dragonforce, apt73, monti, fsociety, cl0p, bianlian, danon, incransom.

We may argue, after many law enforcement proceedings, some of the criminal organizations decided to stand in a joint row.
May 15, 2024 at 8:19 PM
📢 Ransomware Alert: 🇬🇧

Hargreaves Lansdown (hl.co.uk), a Financial Services Company based in Canada, has reportedly fallen victim to Eraleig(APT73) Ransomware group.
January 16, 2026 at 9:01 PM
♻️ rebranded #ransomware group updated on Ransomfeed: Bashe

Bashe is a rebrand of #apt73; supposedly a spin-off or a splinter cell from #lockbit, threat actor had a calculated approach to ransomware.

In 2024 APT73 claimed 31 victims:
ransomfeed.it/stats.php?pa...

#ransomfeed #security #infosec
October 25, 2024 at 2:48 PM
Ransomware claim: APT73 allegedly targeted DG Cement, a major cement producer in Algeria. The incident was discovered on 2026-07-06 and affects the manufacturing sector. #Algeria #Ransomware #Manufacturing
Ransom! dgcement.com (JUL-2026)
The ransomware claim alleges that threat actor APT73 targeted dgcement.com, the website of D.G. Khan Cement Company Limited (DG Cement), a major cement producer in Algeria. The impacted country(s) is: #Algeria
www.hendryadrian.com
July 6, 2026 at 3:15 PM
APT73 has deployed ransomware against hl.co.uk, owned by Hargreaves Lansdown in the UK. The breach highlights ongoing threats to financial service domains. Incident detected April 27, 2026. #RansomwareAttack #HargreavesLansdown #UnitedKingdom
Ransom! hl.co.uk (APR-2026)
APT73 claims to have compromised the hl.co.uk domain in the United Kingdom by deploying ransomware against Hargreaves Lansdown. The hl.co.uk domain is owned by Hargreaves Lansdown (legal name "Hargreaves Lansdown Asset Manage....") #UnitedKingdom
www.hendryadrian.com
April 27, 2026 at 7:45 PM
-Tons of malicious Chrome extension
-New Kurd Hacker Forum
-APT73 rebrands as Bashe RaaS
-The carding ecosystem in 2026 is morphing
-BADIIS infects 1.8k servers
-Trend Micro introduces new APT naming scheme
-New ChainedShark APT
-Russian TV broadcasts its own disinfo
February 16, 2026 at 10:26 AM
𝗔𝗰𝘁𝗼𝗿: #apt73 / #bashe
𝗩𝗶𝗰𝘁𝗶𝗺: Nanolive SA | @NanoLiveLtd | nanolive.ch
𝗖𝗼𝘂𝗻𝘁𝗿𝘆: Switzerland 🇨🇭
𝗦𝗮𝗺𝗽𝗹𝗲: no
𝗘𝘅𝗳𝗶𝗹𝘁𝗿𝗮𝘁𝗲𝗱 𝗱𝗮𝘁𝗮: 13.05 GB
𝗗𝗲𝗮𝗱𝗹𝗶𝗻𝗲: -

🔗 ransomfeed.it/index.php?pa...

#ransomfeed #security #infosec
October 25, 2024 at 2:40 PM
𝗔𝗰𝘁𝗼𝗿: #apt73
𝗩𝗶𝗰𝘁𝗶𝗺: Borrer Executive Search | borrerexecutive.com
𝗖𝗼𝘂𝗻𝘁𝗿𝘆: Switzerland 🇨🇭
𝗦𝗮𝗺𝗽𝗹𝗲: yes
𝗘𝘅𝗳𝗶𝗹𝘁𝗿𝗮𝘁𝗲𝗱 𝗱𝗮𝘁𝗮: 2.50 GB
𝗗𝗲𝗮𝗱𝗹𝗶𝗻𝗲: June 24, 2024

🔗 ransomfeed.it/index.php?pa...

#ransomfeed #security #infosec
June 14, 2024 at 6:07 AM
The provided screenshot with a data sample appears to include names, phone numbers, addresses, ages, genders, types of credit cards, such as Gold or Diamond, and timestamps from March 2024.
BASHE ransomware gang claims ICICI bank, leaves three days to pay the ransom
Hackers from the BASHE ransomware gang, also known as APT73, have added ICICI Bank, a major financial institution in India, to their victim site on the dark web and left three days to pay the ransom.
cnews.link
January 28, 2025 at 2:49 PM
BASHE Ransomware Allegedly Leaked ICICI Bank Customers Data gbhackers.com/bashe-ransom...
BASHE Ransomware Allegedly Leaked ICICI Bank Customers Data
Indian financial giant ICICI Bank as the notorious BASHE ransomware group, also known as Eraleign (APT73), claims responsibility for a significant data breach.
gbhackers.com
January 26, 2025 at 10:22 AM
A DarkWeb Threat Actor Claim Targets Armenia’s Election Infrastructure as WOLVES OF TURAN Escalates Public Sector Ransomware Pressure + Video

Edit Introduction A new cybersecurity incident has drawn attention to the growing risks facing government institutions worldwide after the ransomware group…
A DarkWeb Threat Actor Claim Targets Armenia’s Election Infrastructure as WOLVES OF TURAN Escalates Public Sector Ransomware Pressure + Video
Edit Introduction A new cybersecurity incident has drawn attention to the growing risks facing government institutions worldwide after the ransomware group WOLVES OF TURAN reportedly claimed responsibility for an attack targeting Armenia's election-related infrastructure. According to threat monitoring reports circulating on social media, the group, which has been linked by researchers to the advanced threat cluster known as APT73, posted extortion-related messages directed at a public sector victim associated with Armenia's Ministry of Internal Affairs election platform.
undercodenews.com
June 3, 2026 at 2:10 AM
New post from #Eraleign (Apt73) : Metrabyte.Cloud
More at : https://www.ransomlook.io/group/Eraleign%20(Apt73) #Ransomware
July 24, 2026 at 9:59 AM
According to Ransomware.live, apt73 ransomware group has added metrabyte.cloud (🇩🇪) to its victims.
July 24, 2026 at 9:52 AM
Cyber Extortion Surge: Qilin and APT73 Add New Victims in Fresh Dark Web Ransomware Claims – Dark Web recent claims + Video

Introduction: Rising Noise from the Dark Web Intelligence Channels The cyber threat landscape continues to intensify as ransomware groups maintain a steady rhythm of victim…
Cyber Extortion Surge: Qilin and APT73 Add New Victims in Fresh Dark Web Ransomware Claims – Dark Web recent claims + Video
Introduction: Rising Noise from the Dark Web Intelligence Channels The cyber threat landscape continues to intensify as ransomware groups maintain a steady rhythm of victim announcements across dark web leak sites and threat intelligence feeds. According to recent monitoring data, new claims attributed to the ransomware group “Qilin” and another actor identified as “APT73” have surfaced, listing additional organizations as compromised targets.
undercodenews.com
July 6, 2026 at 3:58 PM
According to Ransomware.live, apt73 ransomware group has added dgcement.com (🇩🇿) to its victims.
July 6, 2026 at 1:21 PM
According to Ransomware.live, apt73 ransomware group has added azarestan.com (🇮🇷) to its victims.
July 6, 2026 at 12:51 PM
New post from #Eraleign (Apt73) : Dgcement.Com
More at : https://www.ransomlook.io/group/Eraleign%20(Apt73) #Ransomware
July 6, 2026 at 1:55 PM