Sarcoma

Sarcoma — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

SarcomaConfidence: High

Ransomware
Also known as: Sarcoma Group

Motivation: Financial

1Attributed Breaches Circulating
HighAttribution Confidence
RansomwareActor Type

Overview

Emerged October 2024 and rapidly reached high global volume against industrial, manufacturing, and tech firms with double extortion. Willing to exploit zero-days; its multithreaded encryption and leak-site design mirror Maze/Egregor, suggesting possible operator lineage.

Tactics, Targeting & TTPs

Willing to exploit zero-day vulnerabilities; multithreaded encryption and leak-site design that researchers note mirror Maze/Egregor, suggesting possible operator lineage.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation