DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries. Known victims: 16 1 ransom note(s) on file
Objectives
Executive Summary
DataCarry is a medium-sophistication criminal threat actor specializing in ransomware and data extortion operations. They operate a double-extortion model, leveraging Tor-based infrastructure to host leak portals and demand ransoms from victims. Targeting primarily insurance, healthcare, aerospace, legal, and retail sectors across multiple countries, DataCarry poses a significant financial risk to organizations through their disruptive activities.
Goals & Targeting
DataCarry's strategic objectives are primarily financial in nature, driven by the desire for organizational gain through ransom payments and data sales. Their targeting profile focuses on sectors with high data value and vulnerability, such as healthcare and insurance, where disruptions can have severe consequences. The group's geographic focus spans multiple countries, indicating a global reach but showing particular interest in regions where their double-extortion approach may be more effective. Typical victims include enterprises with significant data assets, inadequate security postures, or limited incident response capabilities.
Enhanced Description
DataCarry is a relatively new ransomware operation that emerged in June 2024. The group employs a double-extortion tactic where victims are threatened with both data encryption and public exposure of sensitive information if demands are not met. This approach increases the pressure on organizations to comply, making it one of their key strategies for maximizing financial gain. DataCarry's infrastructure heavily relies on Tor networks to anonymize communication channels and maintain operational security. Their target sectors include industries with significant data sensitivity and potential economic impact, such as insurance and healthcare. The group has demonstrated a certain level of targeting precision, focusing on regions where the political and economic environment may make organizations more susceptible to extortion. DataCarry's modus operandi involves initial access through phishing campaigns, followed by ransomware deployment, and subsequent data exfiltration for double-extortion purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DataCarry has conducted several high-profile campaigns across multiple sectors, targeting organizations in at least six countries. Their operational rhythm appears to be steady, with a focus on maintaining persistence and lateral movement within networks to maximize data exfiltration. Notable past operations include incidents in the insurance and healthcare industries where victims were forced to pay ransoms to avoid public exposure of sensitive records. The group's use of double extortion suggests a strategic shift towards more elaborate attack planning compared to basic ransomware groups.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is moderate confidence in the details regarding DataCarry's operational techniques and targets, as they are relatively new to the threat landscape. While their TTPs are well-documented through incident reports and IOC data, there is limited visibility into their internal structures or long-term strategic goals. Gaps exist in understanding their exact toolset beyond phishing campaigns and ransomware deployment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
6
IOCs
0
Observed Data
0
Tactics