WW
Ransomware Victim Business Services

www.shora.ma

Ransomware attack by Tengu ยท Disclosed February 20, 2026 ยท ๐Ÿ‡ฒ๐Ÿ‡ฆ Morocco

www.shora.ma

Date Disclosed
Feb 20, 2026
2026
Threat Group
Tengu
49 total victims
Industry
Business Services

ThreatAI Analysis

Compiled from this incident record and the threat intelligence profile for Tengu. Figures and technique mappings are quoted from the source data, not inferred.

About the Tengu group

Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors. Tengu has listed 49 victims since October 2025.

How Tengu is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference โ†’
Indicator Removal T1070 Stealth

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior. Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.

Mitigations: Remote Data Storage, Restrict File and Directory Permissions, Encrypt Sensitive Information

MITRE ATT&CK reference โ†’
System Binary Proxy Execution T1218 Stealth

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Mitigations: Filter Network Traffic, Restrict Web-Based Content, Execution Prevention, Privileged Account Management, Exploit Protection, Disable or Remove Feature or Program

MITRE ATT&CK reference โ†’

MITRE ATT&CK techniques attributed to Tengu across its recorded activity, not a finding about how www.shora.ma was reached.

Vulnerabilities Tengu is recorded exploiting

1 of these 3 are in the CISA Known Exploited Vulnerabilities catalog. CVEs attributed to Tengu across its reported activity. There is no indication that any of these was involved in the www.shora.ma incident โ€” the source data does not record an entry point.

Incident Analysis

www.shora.ma was targeted by Tengu ransomware, one of the most active ransomware groups in our database with 49 confirmed victims globally. The attack was disclosed on February 20, 2026, when www.shora.ma appeared on the group's dark web leak site.

www.shora.ma is based in Morocco , operating in the Business Services sector. Morocco ranks #56 globally for ransomware attacks, with 22 victims in our database.

Sector context: Business services firms often have access to multiple client environments, making them high-value pivot points for ransomware operators seeking to maximise impact across multiple victim organisations.

Tengu typically employs a double extortion model: first exfiltrating sensitive data from the victim's systems, then deploying ransomware to encrypt files. Victims face two simultaneous threats โ€” paying to restore access and paying to prevent publication of stolen data. The group's leak site publishes victim names and exfiltrated data as leverage.

Data source: This incident record is sourced from public ransomware group leak site disclosures aggregated via the ransomware.live API. Disclosure date reflects when the victim was published on the leak site, which may differ from the initial date of compromise. This platform does not publish or link to stolen data. Last data update: Aug 11, 2026 12:00 UTC.

Frequently Asked Questions

Was www.shora.ma attacked by ransomware?

Yes. www.shora.ma was listed as a victim of the Tengu ransomware group on February 20, 2026. The organisation is based in Morocco and operates in the Business Services sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked www.shora.ma?

www.shora.ma was attacked by Tengu ransomware. Tengu is one of the most active ransomware groups, having claimed 49 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the www.shora.ma ransomware attack occur?

The ransomware attack on www.shora.ma was disclosed on February 20, 2026. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the www.shora.ma ransomware attack?

The specific data stolen from www.shora.ma has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Business Services organisation, www.shora.ma likely held sensitive business data, client information, and operational records.

How can organisations protect against Tengu attacks?

To defend against Tengu and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.