DA

Datacarry Ransomware

Tracked

Threat actor group tracked in the global ransomware database ยท Last disclosure: Dec 6, 2025

Ransomware-as-a-Service (RaaS) Double Extortion Target: Consumer Services
16
Total Victims
0.1% of all tracked
12
Countries Targeted
8
Sectors Targeted
2025
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Datacarry and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Datacarry is a ransomware operation responsible for extorting data from at least sixteen victims across twelve countries, targeting sectors like consumer services, transportation/logistics, and agriculture.

Who Datacarry is

DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.

Recorded activity

Disclosures attributed to Datacarry in this database run from May 2025 to December 2025, totalling 16 victims โ€” 0.1% of everything tracked here. Datacarry has listed victims in 12 countries in this database, most often Sweden, followed by Italy and Spain. The sectors appearing most in its listings are Consumer Services, Transportation/Logistics, Agriculture and Food Production.

Indicators of compromise

  • d86163423afa32bb0b793ad909d6b357
  • b1cf41363401fe5671e24fd55ee89b0c177140c482a8dab1b9891db509df52f6
  • bb62196338dab7b26993f27e3a8ad917d848508ad8cd4646c9fe836b1140c3e4
  • 176.65.141.201
  • 154.216.19.224
  • [email protected]

Showing a sample of 1 MD5, 2 SHA256, 2 IP, 1 EMAIL on file. Hashes and network indicators published for Datacarry. Leak-site addresses are deliberately excluded. Indicators age quickly โ€” treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

datacarry.yar
/*
datacarry ransomware
*/

rule datacarry_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.datacarry"
        description = "Detects datacarry ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "datacarry" ascii nocase
        $name2 = "DATACARRY" ascii
        $onion  = "datacarry.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Datacarry, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Datacarry is a ransomware threat group that has disclosed 16 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Datacarry in our dataset dates to May 2025.

Geographically, Datacarry has targeted organisations in 12 countries. The most frequently targeted nation is Sweden with 2 victim organisations. Other heavily targeted nations include Italy, Spain, Belgium.

Industry-wise, Datacarry shows a concentration in the Consumer Services, Transportation/Logistics, Agriculture and Food Production sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Datacarry likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 16 most recent of the 16 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 16 of 16)

# Organization Country Sector Date
1 Camomilla camomilla.com ๐Ÿ‡ฎ๐Ÿ‡น Italy Consumer Services Dec 6, 2025
2 UAM ๐Ÿ‡ช๐Ÿ‡ธ Spain Transportation/Logistics Nov 21, 2025
3 Miljรถdata (1 day left) ๐Ÿ‡ธ๐Ÿ‡ช Sweden Agriculture and Food Production Sep 13, 2025
4 Miljรถdata miljodata.se ๐Ÿ‡ธ๐Ÿ‡ช Sweden Agriculture and Food Production Sep 13, 2025
5 Peggy Sage peggysage.com ๐Ÿ‡ซ๐Ÿ‡ท France Consumer Services Aug 15, 2025
6 Mรณn Sant Benet monsantbenet.com ๐Ÿ‡ช๐Ÿ‡ธ Spain Hospitality and Tourism Jun 12, 2025
7 Vยฒ Development vsquared2.com ๐Ÿ‡ฌ๐Ÿ‡ท Greece Construction Jun 4, 2025
8 Alliance Healthcare IT alliancehealthcareit.com ๐Ÿ‡ฎ๐Ÿ‡น Italy Healthcare May 29, 2025
9 ALB Forex alb.com ๐Ÿ‡น๐Ÿ‡ท Turkey Financial Services May 26, 2025
10 alles Lรฆgehus alleslaegehus.dk ๐Ÿ‡ฉ๐Ÿ‡ฐ Denmark Healthcare May 26, 2025
11 Balcia Insurance balcia.com ๐Ÿ‡ฑ๐Ÿ‡ป Latvia Financial Services May 26, 2025
12 Executive Jet Support ejs.aero ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom Transportation/Logistics May 26, 2025
13 FrontierCo frontierco.co.za ๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa Consumer Services May 26, 2025
14 La Maison Liรฉgeoise maisonliegeoise.be ๐Ÿ‡ง๐Ÿ‡ช Belgium Consumer Services May 26, 2025
15 Mammut Sports Group mammut.com ๐Ÿ‡จ๐Ÿ‡ญ Switzerland Consumer Services May 26, 2025
16 ร‰tude Bordet etudebordet.com ๐Ÿ‡ง๐Ÿ‡ช Belgium Business Services May 26, 2025

Frequently Asked Questions

What is Datacarry ransomware?

Datacarry is a ransomware threat group that has claimed 16 victims since its first known activity in May 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Datacarry attacked?

Datacarry has claimed 16 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are Sweden, Italy, Spain, Belgium.

Which countries does Datacarry target?

Datacarry has attacked organizations in 12 countries. The top targeted countries are: Sweden, Italy, Spain, Belgium.

Which industries does Datacarry target?

Datacarry most frequently targets the Consumer Services, Transportation/Logistics, Agriculture and Food Production sectors based on victim disclosures in our database.

Is Datacarry still active?

Datacarry's most recent victim disclosure in our database was on December 6, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.