Datacarry Ransomware
TrackedThreat actor group tracked in the global ransomware database ยท Last disclosure: Dec 6, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Datacarry and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Datacarry is a ransomware operation responsible for extorting data from at least sixteen victims across twelve countries, targeting sectors like consumer services, transportation/logistics, and agriculture.
Who Datacarry is
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.
Recorded activity
Disclosures attributed to Datacarry in this database run from May 2025 to December 2025, totalling 16 victims โ 0.1% of everything tracked here. Datacarry has listed victims in 12 countries in this database, most often Sweden, followed by Italy and Spain. The sectors appearing most in its listings are Consumer Services, Transportation/Logistics, Agriculture and Food Production.
Indicators of compromise
- d86163423afa32bb0b793ad909d6b357
- b1cf41363401fe5671e24fd55ee89b0c177140c482a8dab1b9891db509df52f6
- bb62196338dab7b26993f27e3a8ad917d848508ad8cd4646c9fe836b1140c3e4
- 176.65.141.201
- 154.216.19.224
- [email protected]
Showing a sample of 1 MD5, 2 SHA256, 2 IP, 1 EMAIL on file. Hashes and network indicators published for Datacarry. Leak-site addresses are deliberately excluded. Indicators age quickly โ treat a match as a starting point for investigation, and an absence of matches as no assurance.
YARA detection rules
datacarry.yar
/*
datacarry ransomware
*/
rule datacarry_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.datacarry"
description = "Detects datacarry ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "datacarry" ascii nocase
$name2 = "DATACARRY" ascii
$onion = "datacarry.onion" ascii nocase
condition:
any of them
}
Community-contributed rules for Datacarry, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Datacarry is a ransomware threat group that has disclosed 16 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Datacarry in our dataset dates to May 2025.
Geographically, Datacarry has targeted organisations in 12 countries. The most frequently targeted nation is Sweden with 2 victim organisations. Other heavily targeted nations include Italy, Spain, Belgium.
Industry-wise, Datacarry shows a concentration in the Consumer Services, Transportation/Logistics, Agriculture and Food Production sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Datacarry likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 16 most recent of the 16 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 16 of 16)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Camomilla camomilla.com | ๐ฎ๐น Italy | Consumer Services | Dec 6, 2025 |
| 2 | UAM | ๐ช๐ธ Spain | Transportation/Logistics | Nov 21, 2025 |
| 3 | Miljรถdata (1 day left) | ๐ธ๐ช Sweden | Agriculture and Food Production | Sep 13, 2025 |
| 4 | Miljรถdata miljodata.se | ๐ธ๐ช Sweden | Agriculture and Food Production | Sep 13, 2025 |
| 5 | Peggy Sage peggysage.com | ๐ซ๐ท France | Consumer Services | Aug 15, 2025 |
| 6 | Mรณn Sant Benet monsantbenet.com | ๐ช๐ธ Spain | Hospitality and Tourism | Jun 12, 2025 |
| 7 | Vยฒ Development vsquared2.com | ๐ฌ๐ท Greece | Construction | Jun 4, 2025 |
| 8 | Alliance Healthcare IT alliancehealthcareit.com | ๐ฎ๐น Italy | Healthcare | May 29, 2025 |
| 9 | ALB Forex alb.com | ๐น๐ท Turkey | Financial Services | May 26, 2025 |
| 10 | alles Lรฆgehus alleslaegehus.dk | ๐ฉ๐ฐ Denmark | Healthcare | May 26, 2025 |
| 11 | Balcia Insurance balcia.com | ๐ฑ๐ป Latvia | Financial Services | May 26, 2025 |
| 12 | Executive Jet Support ejs.aero | ๐ฌ๐ง United Kingdom | Transportation/Logistics | May 26, 2025 |
| 13 | FrontierCo frontierco.co.za | ๐ฟ๐ฆ South Africa | Consumer Services | May 26, 2025 |
| 14 | La Maison Liรฉgeoise maisonliegeoise.be | ๐ง๐ช Belgium | Consumer Services | May 26, 2025 |
| 15 | Mammut Sports Group mammut.com | ๐จ๐ญ Switzerland | Consumer Services | May 26, 2025 |
| 16 | รtude Bordet etudebordet.com | ๐ง๐ช Belgium | Business Services | May 26, 2025 |
Frequently Asked Questions
What is Datacarry ransomware?
Datacarry is a ransomware threat group that has claimed 16 victims since its first known activity in May 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Datacarry attacked?
Datacarry has claimed 16 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are Sweden, Italy, Spain, Belgium.
Which countries does Datacarry target?
Datacarry has attacked organizations in 12 countries. The top targeted countries are: Sweden, Italy, Spain, Belgium.
Which industries does Datacarry target?
Datacarry most frequently targets the Consumer Services, Transportation/Logistics, Agriculture and Food Production sectors based on victim disclosures in our database.
Is Datacarry still active?
Datacarry's most recent victim disclosure in our database was on December 6, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.