MO

Moneymessage Ransomware

Active

Threat actor group tracked in the global ransomware database Β· Last disclosure: Aug 28, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Healthcare
17
Total Victims
0.1% of all tracked
6
Countries Targeted
8
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Moneymessage and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Moneymessage is a threat actor targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in millions for data stolen by publishing it on their blog if unpaid.

Who Moneymessage is

Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US.

Recorded activity

Disclosures attributed to Moneymessage in this database run from January 2024 to August 2026, totalling 17 victims β€” 0.1% of everything tracked here. Moneymessage has listed victims in 6 countries in this database, most often United States, followed by Argentina and Russia. The sectors appearing most in its listings are Healthcare, Public Sector, Business Services.

YARA detection rules

moneymessage.yar
/*
Money Message ransomware
*/

rule MoneyMessage_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.moneymessage"
        description = "Detects Money Message ransomware note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = "money_message.log" ascii nocase
        $s2 = "money message" ascii nocase
        $s3 = ".money_message" ascii
        $s4 = "MoneyMessage" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Moneymessage, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Moneymessage is a ransomware threat group that has disclosed 17 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Moneymessage in our dataset dates to January 2024.

Geographically, Moneymessage has targeted organisations in 6 countries. The most frequently targeted nation is United States with 11 victim organisations. Other heavily targeted nations include Argentina, Russia, United Kingdom.

Industry-wise, Moneymessage shows a concentration in the Healthcare, Public Sector, Business Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime β€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Moneymessage likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 17 most recent of the 17 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 17 of 17)

# Organization Country Sector Date
1 ProCare πŸ‡ΊπŸ‡Έ United States Healthcare Aug 28, 2026
2 Yourway Transportation πŸ‡ΊπŸ‡Έ United States Transportation Jul 25, 2026
3 Indigo Energy indigoenergy.com πŸ‡ΊπŸ‡Έ United States Energy & Utilities Jul 23, 2026
4 Envision Unlimited β€” β€” Jul 9, 2026
5 X-Copper Professional xcopper.com πŸ‡ΊπŸ‡Έ United States Manufacturing Jul 2, 2026
6 Forestdale πŸ‡¬πŸ‡§ United Kingdom Business Services May 11, 2026
7 Family Partnerships of Central Florida fpocf.org πŸ‡ΊπŸ‡Έ United States Public Sector Jan 28, 2026
8 Bucks County Opportunity Council, INC. bcoc.org πŸ‡ΊπŸ‡Έ United States Public Sector Aug 4, 2025
9 Young Adjustment Company youngadjustment.com πŸ‡ΊπŸ‡Έ United States Business Services Jul 15, 2025
10 The Tech Interactive thetech.org πŸ‡ΊπŸ‡Έ United States Education May 1, 2025
11 Marina Family Medical marinafamilymedical.com.au πŸ‡¦πŸ‡Ί Australia Healthcare Jan 18, 2025
12 National Atomic Energy Commission cnea.gob.ar πŸ‡¦πŸ‡· Argentina Public Sector Dec 18, 2024
13 Kazyon kazyon.com πŸ‡·πŸ‡Ί Russia Business Services Dec 13, 2024
14 The Egyptian Tax Authority (ETA) eta.gov.eg πŸ‡ͺπŸ‡¬ Egypt Public Sector Nov 17, 2024
15 First Baptist Medical Center fbmchealth.com πŸ‡ΊπŸ‡Έ United States Healthcare Jun 19, 2024
16 Insurance Agency Marketing Services iamsinc.com πŸ‡ΊπŸ‡Έ United States Financial Services May 16, 2024
17 Anna Jaques Hospital ajh.org πŸ‡ΊπŸ‡Έ United States Healthcare Jan 19, 2024

Frequently Asked Questions

What is Moneymessage ransomware?

Moneymessage is a ransomware threat group that has claimed 17 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Moneymessage attacked?

Moneymessage has claimed 17 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Argentina, Russia, United Kingdom.

Which countries does Moneymessage target?

Moneymessage has attacked organizations in 6 countries. The top targeted countries are: United States, Argentina, Russia, United Kingdom.

Which industries does Moneymessage target?

Moneymessage most frequently targets the Healthcare, Public Sector, Business Services sectors based on victim disclosures in our database.

Is Moneymessage still active?

Moneymessage's most recent victim disclosure in our database was on August 28, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.