Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Apos ransomware

16 victims listed on the Apos leak site across 9 countries. Most recent disclosure .

Victims
16
0.1% of all tracked
Countries
9
Most: Brazil
Sectors
8
Most: Business Services
First seen
Apr 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Apos and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Apos is a data-broking extortion gang that has targeted numerous companies in over nine different countries since its emergence last year.

Who Apos is

Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or sell stolen information rather than encrypting files, targeting technology, healthcare, manufacturing, telecom, and government sectors across multiple countries.

Recorded activity

Disclosures attributed to Apos in this database run from April 2024 to August 2025, totalling 16 victims — 0.1% of everything tracked here. Apos has listed victims in 9 countries in this database, most often Brazil, followed by United States and Spain. The sectors appearing most in its listings are Business Services, Healthcare, Technology.

YARA detection rules

apos.yar
/*
apos ransomware
*/

rule apos_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.apos"
        description = "Detects apos ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "apos" ascii nocase
        $name2 = "APOS" ascii
        $onion  = "apos.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Apos, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Apos has disclosed 16 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to April 2024.

The group has listed organisations in 9 countries, most often in Brazil (4 victims), followed by United States, Spain, Canada.

By industry, its listings concentrate in Business Services, Healthcare, Technology — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Apos is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Apos victims 16

Organization Disclosed
ACMARK
Ha******.us
infraestructures.cat
ESSpain
Lawton Partners
CACanada
RH
GBUnited Kingdom
wow pictures
AUAustralia
KIU System Solutions
ARArgentina
InternetWay
BRBrazil
Netcom-World
USUnited States
M-1 TOOLWORKS
USUnited States
Auxis
USUnited States
Drogarias Preço Bom
BRBrazil
Algen Healthcare
INIndia
Bitz Softwares
BRBrazil
Drogaria Preco Bom
BRBrazil
Sunlux Group
FRFrance

Frequently asked questions

What is Apos ransomware?

Apos is a ransomware threat group that has claimed 16 victims since its first known activity in April 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Apos attacked?

Apos has claimed 16 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are Brazil, United States, Spain, Canada.

Which countries does Apos target?

Apos has attacked organizations in 9 countries. The top targeted countries are: Brazil, United States, Spain, Canada.

Which industries does Apos target?

Apos most frequently targets the Business Services, Healthcare, Technology sectors based on victim disclosures in our database.

Is Apos still active?

Apos's most recent victim disclosure in our database was on August 15, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.