UN

Underground Ransomware

Tracked

Threat actor group tracked in the global ransomware database Β· Last disclosure: Aug 15, 2025

Ransomware-as-a-Service (RaaS) Double Extortion Target: Technology
26
Total Victims
0.1% of all tracked
11
Countries Targeted
7
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Underground and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Underground ransomware has targeted 26 companies across eleven countries since July and has conducted double extortion attacks.

Who Underground is

Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.

Recorded activity

Disclosures attributed to Underground in this database run from May 2024 to August 2025, totalling 26 victims β€” 0.1% of everything tracked here. Underground has listed victims in 11 countries in this database, most often United States, followed by Canada and South Korea. The sectors appearing most in its listings are Technology, Manufacturing, Healthcare.

YARA detection rules

underground.yar
/*
Underground ransomware
*/

rule Underground_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.underground"
        description = "Detects Underground ransomware ransom note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = "underground" ascii nocase
        $s2 = "!readme.txt" ascii nocase
        $s3 = "underground.onion" ascii nocase

    condition:
        2 of them
}

Community-contributed rules for Underground, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Underground is a ransomware threat group that has disclosed 26 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Underground in our dataset dates to May 2024.

Geographically, Underground has targeted organisations in 11 countries. The most frequently targeted nation is United States with 9 victim organisations. Other heavily targeted nations include Canada, South Korea, Germany.

Industry-wise, Underground shows a concentration in the Technology, Manufacturing, Healthcare sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime β€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Underground likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 26 most recent of the 26 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 26 of 26)

# Organization Country Sector Date
1 SFA Engineering sfa.co.kr πŸ‡°πŸ‡· South Korea Technology Aug 15, 2025
2 GMORS Co., Ltd gmors.com πŸ‡ΉπŸ‡Ό Taiwan Manufacturing Jun 25, 2025
3 Afa Systems Ltd. afasystemsinc.com πŸ‡¨πŸ‡¦ Canada Technology Apr 16, 2025
4 semex.com semex.com πŸ‡¨πŸ‡¦ Canada Agriculture and Food Production Apr 16, 2025
5 shengyusteel.com shengyusteel.com πŸ‡ΉπŸ‡Ό Taiwan Manufacturing Apr 16, 2025
6 Simmtech Co., Ltd. simmtech.com πŸ‡°πŸ‡· South Korea Technology Dec 16, 2024
7 hcsgcorp.com hcsgcorp.com πŸ‡ΊπŸ‡Έ United States Healthcare Oct 25, 2024
8 Casio Computer Co., Ltd casio.co.jp πŸ‡―πŸ‡΅ Japan Technology Oct 10, 2024
9 ramservices.com ramservices.com πŸ‡ΊπŸ‡Έ United States Business Services Jul 3, 2024
10 Ethypharm ethypharm.com πŸ‡«πŸ‡· France Healthcare Jul 1, 2024
11 A-Line Staffing Solutions alinestaffing.com πŸ‡ΊπŸ‡Έ United States Healthcare Jun 17, 2024
12 belcherpharma.com belcherpharma.com πŸ‡ΊπŸ‡Έ United States Healthcare Jun 12, 2024
13 CentralSecurities.com centralsecurities.com πŸ‡ΊπŸ‡Έ United States Financial Services Jun 11, 2024
14 www.belcherpharma.com belcherpharma.com πŸ‡ΊπŸ‡Έ United States Healthcare May 17, 2024
15 kc.co.kr kc.co.kr πŸ‡°πŸ‡· South Korea Technology May 3, 2024
16 awwg.com awwg.com πŸ‡ͺπŸ‡Έ Spain Business Services May 1, 2024
17 bulldogbag.com bulldogbag.com πŸ‡¨πŸ‡¦ Canada Manufacturing May 1, 2024
18 cochraneglobal.com cochraneglobal.com πŸ‡¦πŸ‡ͺ UAE Technology May 1, 2024
19 Creative Business Interiors creativebusinessinteriors.com πŸ‡ΊπŸ‡Έ United States Business Services May 1, 2024
20 frenckengroup.com frenckengroup.com πŸ‡ΈπŸ‡¬ Singapore Manufacturing May 1, 2024
21 KyungChang β€” Manufacturing May 1, 2024
22 Skender Construction skender.com πŸ‡ΊπŸ‡Έ United States Business Services May 1, 2024
23 synology.com synology.com πŸ‡©πŸ‡ͺ Germany Technology May 1, 2024
24 tpa-group.sk tpa-group.sk πŸ‡ΈπŸ‡° Slovakia Business Services May 1, 2024
25 Triathlon.group triathlon.group πŸ‡©πŸ‡ͺ Germany Transportation/Logistics May 1, 2024
26 Y. Hata & Co., Ltd. yhata.com πŸ‡ΊπŸ‡Έ United States Agriculture and Food Production May 1, 2024

Frequently Asked Questions

What is Underground ransomware?

Underground is a ransomware threat group that has claimed 26 victims since its first known activity in May 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Underground attacked?

Underground has claimed 26 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Canada, South Korea, Germany.

Which countries does Underground target?

Underground has attacked organizations in 11 countries. The top targeted countries are: United States, Canada, South Korea, Germany.

Which industries does Underground target?

Underground most frequently targets the Technology, Manufacturing, Healthcare sectors based on victim disclosures in our database.

Is Underground still active?

Underground's most recent victim disclosure in our database was on August 15, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.