Underground Ransomware
TrackedThreat actor group tracked in the global ransomware database Β· Last disclosure: Aug 15, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Underground and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Underground ransomware has targeted 26 companies across eleven countries since July and has conducted double extortion attacks.
Who Underground is
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
Recorded activity
Disclosures attributed to Underground in this database run from May 2024 to August 2025, totalling 26 victims β 0.1% of everything tracked here. Underground has listed victims in 11 countries in this database, most often United States, followed by Canada and South Korea. The sectors appearing most in its listings are Technology, Manufacturing, Healthcare.
YARA detection rules
underground.yar
/*
Underground ransomware
*/
rule Underground_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.underground"
description = "Detects Underground ransomware ransom note"
date = "2026-05-04"
severity = 7
score = 70
strings:
$s1 = "underground" ascii nocase
$s2 = "!readme.txt" ascii nocase
$s3 = "underground.onion" ascii nocase
condition:
2 of them
}
Community-contributed rules for Underground, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Underground is a ransomware threat group that has disclosed 26 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Underground in our dataset dates to May 2024.
Geographically, Underground has targeted organisations in 11 countries. The most frequently targeted nation is United States with 9 victim organisations. Other heavily targeted nations include Canada, South Korea, Germany.
Industry-wise, Underground shows a concentration in the Technology, Manufacturing, Healthcare sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime β conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Underground likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 26 most recent of the 26 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 26 of 26)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | SFA Engineering sfa.co.kr | π°π· South Korea | Technology | Aug 15, 2025 |
| 2 | GMORS Co., Ltd gmors.com | πΉπΌ Taiwan | Manufacturing | Jun 25, 2025 |
| 3 | Afa Systems Ltd. afasystemsinc.com | π¨π¦ Canada | Technology | Apr 16, 2025 |
| 4 | semex.com semex.com | π¨π¦ Canada | Agriculture and Food Production | Apr 16, 2025 |
| 5 | shengyusteel.com shengyusteel.com | πΉπΌ Taiwan | Manufacturing | Apr 16, 2025 |
| 6 | Simmtech Co., Ltd. simmtech.com | π°π· South Korea | Technology | Dec 16, 2024 |
| 7 | hcsgcorp.com hcsgcorp.com | πΊπΈ United States | Healthcare | Oct 25, 2024 |
| 8 | Casio Computer Co., Ltd casio.co.jp | π―π΅ Japan | Technology | Oct 10, 2024 |
| 9 | ramservices.com ramservices.com | πΊπΈ United States | Business Services | Jul 3, 2024 |
| 10 | Ethypharm ethypharm.com | π«π· France | Healthcare | Jul 1, 2024 |
| 11 | A-Line Staffing Solutions alinestaffing.com | πΊπΈ United States | Healthcare | Jun 17, 2024 |
| 12 | belcherpharma.com belcherpharma.com | πΊπΈ United States | Healthcare | Jun 12, 2024 |
| 13 | CentralSecurities.com centralsecurities.com | πΊπΈ United States | Financial Services | Jun 11, 2024 |
| 14 | www.belcherpharma.com belcherpharma.com | πΊπΈ United States | Healthcare | May 17, 2024 |
| 15 | kc.co.kr kc.co.kr | π°π· South Korea | Technology | May 3, 2024 |
| 16 | awwg.com awwg.com | πͺπΈ Spain | Business Services | May 1, 2024 |
| 17 | bulldogbag.com bulldogbag.com | π¨π¦ Canada | Manufacturing | May 1, 2024 |
| 18 | cochraneglobal.com cochraneglobal.com | π¦πͺ UAE | Technology | May 1, 2024 |
| 19 | Creative Business Interiors creativebusinessinteriors.com | πΊπΈ United States | Business Services | May 1, 2024 |
| 20 | frenckengroup.com frenckengroup.com | πΈπ¬ Singapore | Manufacturing | May 1, 2024 |
| 21 | KyungChang | β | Manufacturing | May 1, 2024 |
| 22 | Skender Construction skender.com | πΊπΈ United States | Business Services | May 1, 2024 |
| 23 | synology.com synology.com | π©πͺ Germany | Technology | May 1, 2024 |
| 24 | tpa-group.sk tpa-group.sk | πΈπ° Slovakia | Business Services | May 1, 2024 |
| 25 | Triathlon.group triathlon.group | π©πͺ Germany | Transportation/Logistics | May 1, 2024 |
| 26 | Y. Hata & Co., Ltd. yhata.com | πΊπΈ United States | Agriculture and Food Production | May 1, 2024 |
Frequently Asked Questions
What is Underground ransomware?
Underground is a ransomware threat group that has claimed 26 victims since its first known activity in May 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Underground attacked?
Underground has claimed 26 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Canada, South Korea, Germany.
Which countries does Underground target?
Underground has attacked organizations in 11 countries. The top targeted countries are: United States, Canada, South Korea, Germany.
Which industries does Underground target?
Underground most frequently targets the Technology, Manufacturing, Healthcare sectors based on victim disclosures in our database.
Is Underground still active?
Underground's most recent victim disclosure in our database was on August 15, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.