Actor Profile

🏹 AuditTeam — Ransomware

AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and Southeast Asia across technology and manufacturing sectors, operating a data leak site consistent with double-extortion methodology.

Classification

Ransomware

Leak-site victims

15
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (15)

VictimCountryPublishedDomain
I-SYS RU 2026-06-25T04:20:19.047045+00:00
I-***YS RU 2026-06-14T23:50:14.563740+00:00
Paid Victim 111CEAA5AD9DA2F1 RU 2026-06-04T14:50:17.101569+00:00
ca***lm RU 2026-06-02T08:50:16.475085+00:00
Paid Victim B35411691DDC2265 RU 2026-05-28T16:20:17.341156+00:00
On***de RU 2026-05-28T00:50:16.607999+00:00
Mopas Online Supermarket TR 2026-05-23T09:20:19.076203+00:00 mopas.com.tr
Mo***et 2026-05-15T12:50:14.760378+00:00
Trésor Public SN 2026-05-18T04:20:17.223305+00:00
Tr***ic SN 2026-05-10T09:20:14.302065+00:00
Paid Victim CCD233FEE92FFA2D HK 2026-04-08T15:57:08.315965+00:00
Paid Victim A98A624456DA525F TH 2026-04-08T15:56:51.028914+00:00
Paid Victim D3C1388C1B73BCA2 CN 2026-04-08T15:56:35.236851+00:00
joycity KR 2026-04-08T15:57:26.323415+00:00 joycity.com
Kawasaki Motors Philippines Corporation PH 2026-04-08T15:57:43.209462+00:00 kawasaki.ph

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php