Actor Profile

🏹 RunSomeWares — Ransomware

RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain services, financial services, accounting, and manufacturing, with unclear deployment of an encryptor vs. pure data-theft extortion.

Classification

Ransomware

Leak-site victims

6
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (6)

VictimCountryPublishedDomain
Coös County Family Health US 2025-08-13T12:46:45.198406+00:00 coosfamilyhealth.org
Harvest FR 2025-04-10T13:07:03.996666+00:00 Harvest.fr
Donna G. Rogers, CPA, P.A. US 2025-02-27T14:37:04.752890+00:00 dgrogerscpa.com
Thai Metal Aluminium Co., Ltd TH 2025-02-27T14:35:55.680018+00:00 thaimetal.co
F&V Capital Management, LLC (FVCM) US 2025-02-27T14:34:45.268790+00:00 fvcapital.us
Gilbert US 2025-02-27T14:33:32.077430+00:00 gilbertusa.com

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach RunSomeWares (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php