Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors emperador

Also known as: DeputyDog, Emperador Oscuro Marble, Emperador Dark, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, UAS-TeNT

Description

Known victims: 1

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Government
Telecommunications
Healthcare
Defense
Education
Critical infrastructure
Manufacturing
Retail
Media
Entertainment
Non profit
Information technology
Hospitality
Utilities
Aerospace
Maritime
Nuclear
Gaming
Food agriculture
Construction
Transportation
Pharmaceutical

Targeted Countries / Regions

UA
IN
CN
RU
GB
US
DE
KP
IR
PK
BY
PL
TW
CA
AU

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 12 Email Address 1 Domain 4 IPv4 Address 1 SHA-256 Hash 2

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  2. pmc.ncbi.nlm.nih.gov — Cited by web research for: UAS-TeNT
  3. www.trendmicro.com — Cited by web research for: T1059.005
  4. www.trendmicro.com — Cited by web research for: Payload

Intel Summary

22

Techniques

40

Tools

1

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
Iran (IR)
Confidence
80%
First Seen
Aug 10, 2026
Last Seen
Aug 10, 2026
Added
Aug 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.