Actor Profile

🏹 IMNCrew — Ransomware

IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.

Classification

Ransomware

Leak-site victims

12
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (12)

VictimCountryPublishedDomain
Jansenfurniture.com CA 2025-09-16T06:37:52.012722+00:00 Jansenfurniture.com
Onegolditalia.it IT 2025-08-02T14:37:51.190258+00:00 Onegolditalia.it
Apntelecom.com US 2025-07-04T09:05:49.481747+00:00 Apntelecom.com
Repremundo.com.co CO 2025-06-14T10:07:43.772099+00:00 Repremundo.com.co
Stiga.com SE 2025-05-20T01:33:56.171847+00:00 Stiga.com
Synthesia.com CZ 2025-05-05T20:10:15.594157+00:00 Synthesia.com
Grupo Herradura Occidente MX 2025-05-05T20:09:48.010718+00:00 grupoherradura.com.mx
Croatianmint.hr HR 2025-05-05T20:09:39.958070+00:00 Croatianmint.hr
Derp.org US 2025-05-05T20:09:11.589359+00:00 Derp.org
Abdainsurance.co.id ID 2025-05-05T20:08:42.554233+00:00 Abdainsurance.co.id
Vnakc.org US 2025-05-05T20:08:14.553130+00:00 Vnakc.org
Goodson.com US 2025-05-05T20:07:46.205871+00:00 Goodson.com

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach IMNCrew (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php