Actor Profile

🏹 ValenciaLeaks — Ransomware

ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of data and publishing it on a dedicated leak site, with documented victims including the City of Pleasanton, CA (283 GB exfiltrated) and pharmaceutical firm Duo Pharma Biotech.

Classification

Ransomware

Leak-site victims

5
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (5)

VictimCountryPublishedDomain
globe.com.bd BD 2024-09-18T09:47:16.136675+00:00 globe.com.bd
satiagroup.com LU 2024-09-18T09:44:14.436808+00:00 satiagroup.com
duopharmabiotech.com MY 2024-09-18T09:39:45.615900+00:00 duopharmabiotech.com
cityofpleasantonca.gov US 2024-09-10T03:45:00.123456+00:00 cityofpleasantonca.gov
tendam.es ES 2024-09-18T09:36:27.724416+00:00 tendam.es

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach ValenciaLeaks (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php