AmethystRed Active
Ransomware group first observed in 2022. Uses MegaSync for deployment.1
Total Victims
2022-12-01
First Seen
2026-03-06
Last Seen
0
Known TTPs
1.6d
Avg Delay
0
Negotiations
ONION URLS
emj6evugpd4epcezzl76ha5qbg6w2b5kphrzxybjizaufud36mnrrbrl.onion
TOOLS
MegaSync
SystemBC
FILE EXTENSIONS
.broken
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
| Date | Victim Name | Country | Sector | Status |
|---|---|---|---|---|
| 2026-03-06 | Zenith Consulting | South Africa | Education | Negotiating |
No TTPs data
No YARA rules
No IoCs
No ransom notes