benzona Unknown
First seen:
12/01/2026 11:38
Last Attack:
30/01/2026
6
Total Victims
0
Victims (30d)
Details
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Leak Site
Onion URL:
http://rwsu75mtgj5oiz3alkfpnxnopcbiqed6wllyoffpuruuu6my6imjzuqd.onion
Victims by Country
2
🇽🇽
Unknown
1
🇹🇿
TZ
1
🇫🇷
France
1
🇬🇹
GT
1
Ransomware Victims 6
| Victim | Country | Sector | Discovered |
|---|---|---|---|
| casamedica.com.gt | 🇬🇹 GT | Healthcare |
30/01/2026 17:29 30/01/2026 |
| empreinte-hotel.com | 🇫🇷 FR | Hospitality and Tourism |
22/01/2026 12:00 22/01/2026 |
| *a*ame*i*a.com.g* | - | Not Found |
22/01/2026 12:00 22/01/2026 |
| ccbrt.org | 🇹🇿 TZ | Healthcare |
17/01/2026 09:25 17/01/2026 |
| em***int*-ho***.com | - | Not Found |
17/01/2026 09:24 17/01/2026 |
| cc***.or.*z | 🇽🇽 XX | Not Found |
12/01/2026 11:38 12/01/2026 |
Metadata
Slug:
benzona
Created: 14/01/2026 08:19
Updated: 28/06/2026 16:02