Actor Profile

🏹 chort — Ransomware

Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance.

Classification

Ransomware

Leak-site victims

7
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (7)

VictimCountryPublishedDomain
texanscan.org US 2024-11-17T10:30:28.383741+00:00 texanscan.org
Tri-TechElectronics.com US 2024-11-17T10:26:21.191835+00:00 Tri-TechElectronics.com
paaf.gov.kw KW 2024-11-17T10:24:14.411287+00:00 paaf.gov.kw
sheboyganwi.gov US 2024-11-22T14:36:23.984561+00:00 sheboyganwi.gov
hartwick.edu US 2024-11-17T10:22:11.008558+00:00 hartwick.edu
bartow.k12.ga.us US 2024-11-17T10:24:17.402365+00:00 bartow.k12.ga.us
edwardsburgschoolsfoundation.org US 2024-11-17T10:28:24.155376+00:00 edwardsburgschoolsfoundation.org

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php