Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

0mega ransomware

1 victims listed on the 0mega leak site across 1 countries. Most recent disclosure .

Victims
1
0% of all tracked
Countries
1
Most: United States
Sectors
1
Most: Business Services
First seen
Jan 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for 0mega and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Who 0mega is

0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.

Recorded activity

Disclosures attributed to 0mega in this database run from January 2024 to January 2024, totalling 1 victims — 0% of everything tracked here. 0mega has listed victims in 1 countries in this database, most often United States. The sectors appearing most in its listings are Business Services.

How 0mega is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference
Account Access Removal T1531 Impact

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place. In Windows, Net utility, <codeSet-LocalUser</code and <codeSet-ADAccountPassword</code PowerShell cmdlets may be used by adversaries to modify user accounts. Accounts could also be disabled by Group Policy. In Linux, the <codepasswd</code utility may be used to change passwords.

MITRE ATT&CK reference
Automated Collection T1119 Collection

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. This functionality could also be built into remote access tools.

Mitigations: Remote Data Storage, Encrypt Sensitive Information

MITRE ATT&CK reference
Exfiltration Over C2 Channel T1041 Exfiltration

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Mitigations: Network Intrusion Prevention, Data Loss Prevention

MITRE ATT&CK reference
Data Encrypted for Impact T1486 Impact

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Mitigations: Data Backup, Behavior Prevention on Endpoint

MITRE ATT&CK reference
Inhibit System Recovery T1490 Impact

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options. Operating systems may contain features that can help fix corrupted systems, such as a backup catalog, volume shadow copies, and automatic repair features. Adversaries may disable or delete system recovery features to augment the effects of Data Destruction and Data Encrypted for Impact. Furthermore, adversaries may disable recovery notifications, then corrupt backups.

Mitigations: Operating System Configuration, Data Backup, Execution Prevention, User Account Management

MITRE ATT&CK reference

MITRE ATT&CK techniques attributed to 0mega across its recorded activity. They describe the group overall, not any single incident.

YARA detection rules

0mega.yar
/*
0mega ransomware
*/

rule 0mega_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.0mega"
        description = "Detects 0mega ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "0mega" ascii nocase
        $name2 = "0MEGA" ascii
        $onion  = "0mega.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for 0mega, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

0mega has disclosed 1 victims on its leak site, 0% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.

The group has listed organisations in 1 countries, most often in United States (1 victims).

By industry, its listings concentrate in Business Services — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, 0mega is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

0mega victims 1

Organization Disclosed
Four Hands LLC
USUnited States

Frequently asked questions

What is 0mega ransomware?

0mega is a ransomware threat group that has claimed 1 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has 0mega attacked?

0mega has claimed 1 victims in our database, representing 0% of all tracked ransomware attacks. The most targeted countries are United States.

Which countries does 0mega target?

0mega has attacked organizations in 1 countries. The top targeted countries are: United States.

Which industries does 0mega target?

0mega most frequently targets the Business Services sectors based on victim disclosures in our database.

Is 0mega still active?

0mega's most recent victim disclosure in our database was on January 25, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.