Japan

tengu

Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.

First seen 2025-10-23 · Last seen 2026-03-07 · 1 Japan claims

Tactics: Initial Access, Execution, Persistence, Defense Evasion, Lateral Movement, Exfiltration, Impact

CVEs named by the source: CVE-2025-43995, CVE-2025-55754, CVE-2024-38178

Cached from ransomware.live. 2026-10-01 PT. Leak sites are not linked.

真言宗智山派 成就院

JP

Discovered: 2026-02-18 <span class="ransom-ago">(7mo ago)</span>

Jōju-in is a traditional Japanese Buddhist temple belonging to the Shingon-shū Chisan-ha (真言宗智山派) sect, one of the main branches of…

jyojyuin.o.oo7.jp