Actor Profile

🏹 cheers — Ransomware

Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks against VMware ESXi servers, running a double-extortion leak site with four documented victims.
🔄 Pivot:🏹 cheers

Classification

Ransomware

Leak-site victims

15
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (15)

VictimCountryPublishedDomain
DYNAM JAPAN HOLDINGS CO., LTD 2022-09-14T11:00:11.961979+00:00
An Japan Game Halls Operator 2022-09-01T18:54:57.537950+00:00
An British Financial Company -Public 2022-08-18T12:58:13.246399+00:00
An Insurance Company -Paid 2022-08-09T03:34:50.557865+00:00
An Turkey Certified Public Accountancy Firms -Unpay 2022-08-09T03:34:47.958234+00:00
An Insurance Company 2022-07-19T18:32:38.955515+00:00
An British Financial Company -Unpay 2022-07-18T13:57:51.602815+00:00
An International Shipping Company - Paid 2022-07-18T12:41:56.092446+00:00
An International Shipping Company - Unpay 2022-07-01T08:32:10.584509+00:00
https:// 2022-06-30T20:30:51.467965+00:00
Sembcorp Marine - Unpay 2022-06-28T20:59:31.324223+00:00
An Technology Company - Paid 2022-05-29T08:39:45.127483+00:00
An Financial Company - Paid 2022-05-29T08:39:43.238597+00:00
An Belgium Hospital - Unpay 2022-05-29T08:39:41.148763+00:00
An International Maritime Company - Unpay 2022-05-29T08:39:38.872245+00:00

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach cheers (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php