Motivation: Financial
By early 2026 its leak site listed 200+ victims across 50+ countries, having moved from a closed group to RaaS in September 2025. Uses a Go-based encryptor with worm-like self-propagation, led by a Russian-speaking operator tracked as LARVA-368 (aliases hastalamuerte, ArmCorp, zeta88, nobody0, santamuerte).
Go-based encryptor with aggressive worm-like self-propagation. Led by a Russian-speaking operator tracked as LARVA-368 (aliases hastalamuerte, ArmCorp, zeta88, nobody0, santamuerte).
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.