BR

Brotherhood Ransomware

Tracked

Threat actor group tracked in the global ransomware database ยท Last disclosure: Jan 6, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
18
Total Victims
0.1% of all tracked
8
Countries Targeted
9
Sectors Targeted
2025
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Brotherhood and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Ransomware group Brotherhood has targeted 18 organizations across eight nations, infecting sites in sectors like Business Services, Public Sector, and Technology.

Who Brotherhood is

Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.

Recorded activity

Disclosures attributed to Brotherhood in this database run from October 2025 to January 2026, totalling 18 victims โ€” 0.1% of everything tracked here. Brotherhood has listed victims in 8 countries in this database, most often United States, followed by Australia and Canada. The sectors appearing most in its listings are Business Services, Public Sector, Technology.

YARA detection rules

brotherhood.yar
/*
brotherhood ransomware
*/

rule brotherhood_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.brotherhood"
        description = "Detects brotherhood ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "brotherhood" ascii nocase
        $name2 = "BROTHERHOOD" ascii
        $onion  = "brotherhood.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Brotherhood, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Brotherhood is a ransomware threat group that has disclosed 18 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Brotherhood in our dataset dates to October 2025.

Geographically, Brotherhood has targeted organisations in 8 countries. The most frequently targeted nation is United States with 7 victim organisations. Other heavily targeted nations include Australia, Canada, Germany.

Industry-wise, Brotherhood shows a concentration in the Business Services, Public Sector, Technology sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Brotherhood likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 18 most recent of the 18 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 18 of 18)

# Organization Country Sector Date
1 Italgrafica Sistemi konigprint.com ๐Ÿ‡ฎ๐Ÿ‡น Italy Manufacturing Jan 6, 2026
2 hรคussermann stauden gehรถlze gmbh haeussermann.com ๐Ÿ‡ฉ๐Ÿ‡ช Germany Agriculture and Food Production Dec 10, 2025
3 Ingenieurbรผro Laudi www.ib-laudi.de ๐Ÿ‡ฉ๐Ÿ‡ช Germany โ€” Nov 28, 2025
4 Cera Stribley www.c-s.com.au ๐Ÿ‡ฆ๐Ÿ‡บ Australia โ€” Nov 15, 2025
5 Horst Realty www.horstrealty.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Nov 15, 2025
6 Kaener Personal www.kaenerpersonal.ch ๐Ÿ‡จ๐Ÿ‡ญ Switzerland โ€” Nov 15, 2025
7 Ninas Jewellery www.ninasjewellery.com.au ๐Ÿ‡ฆ๐Ÿ‡บ Australia Consumer Services Nov 15, 2025
8 Spoleta Construction spoleta.com ๐Ÿ‡บ๐Ÿ‡ธ United States Construction Nov 15, 2025
9 Citizens' Committee for Children of New York www.cccnewyork.org ๐Ÿ‡บ๐Ÿ‡ธ United States Public Sector Oct 11, 2025
10 Integlia integlia.ca ๐Ÿ‡จ๐Ÿ‡ฆ Canada โ€” Oct 11, 2025
11 Coal Industry Social Welfare Organisation www.ciswo.org.uk ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom Energy Oct 10, 2025
12 Kevmor www.kevmor.com.au ๐Ÿ‡ฆ๐Ÿ‡บ Australia Business Services Oct 10, 2025
13 Momentum Logistics www.momentumlogistics.co.za ๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa Transportation/Logistics Oct 10, 2025
14 Motility Software www.motilitysoftware.com ๐Ÿ‡บ๐Ÿ‡ธ United States Technology Oct 10, 2025
15 Orion Communications and Public Relations www.orioncommunications-pr.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services Oct 10, 2025
16 Sternthal Montigny Greenberg St-Germain www.smgs.ca ๐Ÿ‡จ๐Ÿ‡ฆ Canada Business Services Oct 10, 2025
17 UVJ Technologies www.uvjtech.com ๐Ÿ‡บ๐Ÿ‡ธ United States Technology Oct 10, 2025
18 Woodmen Valley Chapel woodmenvalley.org ๐Ÿ‡บ๐Ÿ‡ธ United States Public Sector Oct 10, 2025

Frequently Asked Questions

What is Brotherhood ransomware?

Brotherhood is a ransomware threat group that has claimed 18 victims since its first known activity in October 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Brotherhood attacked?

Brotherhood has claimed 18 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Australia, Canada, Germany.

Which countries does Brotherhood target?

Brotherhood has attacked organizations in 8 countries. The top targeted countries are: United States, Australia, Canada, Germany.

Which industries does Brotherhood target?

Brotherhood most frequently targets the Business Services, Public Sector, Technology sectors based on victim disclosures in our database.

Is Brotherhood still active?

Brotherhood's most recent victim disclosure in our database was on January 6, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.