Also known as: LinkC
Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI, cloud, aerospace, and manufacturing companies — including H2O.ai — demanding ransoms as high as $15 million using double-extortion tactics. Known victims: 4 1 ransom note(s) on file
Objectives
Executive Summary
Linkc is a medium-sophistication ransomware group operating since late January 2025. They primarily target US-based AI, cloud computing, aerospace, and manufacturing industries using double-extortion tactics to demand ransoms up to $15 million. Their operations have already affected at least four organizations, including H2O.ai.
Goals & Targeting
Linkc targets US-based AI, cloud computing, aerospace, and manufacturing industries likely due to the high value of their intellectual property and data. These sectors represent attractive opportunities for financial gain through ransom demands and data resale. The group's double-extortion tactics reflect a strategic focus on maximizing both immediate ransom payments and long-term revenue streams from stolen data. Their choice of victims suggests an operational focus on mid-sized organizations with potentially weaker security postures but sufficient assets to meet high ransom demands.
Enhanced Description
Linkc is a recently emerged ransomware group that has garnered attention for its aggressive targeting of high-value US-based technology and industrial sectors. The group operates a Tor-based data leak site as part of their double-extortion strategy, combining the encryption of victim files with the threat to publish stolen data unless a substantial ransom is paid. Their campaigns have specifically targeted mid-sized organizations in the AI, cloud computing, aerospace, and manufacturing industries. The group's operational timeline spans from early 2025 to late February 2026, with known campaigns involving victims such as Sajet Products and StrongLink. Linkc's use of double extortion aligns with broader trends in ransomware evolution, aiming to maximize financial gain by leveraging both data encryption and reputational damage. Their targeting of sectors with significant intellectual property and sensitive data underscores a strategic focus on maximizing payout potential.
Key Capabilities
Software / Tooling
Campaigns & Victims
Linkc has conducted several notable campaigns, including targeting H2O.ai and other mid-sized tech companies. Their operations typically involve initial access via phishing emails or network exploitation, followed by data encryption and exfiltration. The group's operational tempo appears to be opportunistic, with a focus on striking high-impact targets in sectors with deep intellectual property and customer trust dependencies. Their campaigns often feature prolonged lateral movement within networks to gather sensitive information before deploying ransomware.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in Linkc's identity and operations based on known victims and TTPs. Limited IOC samples and campaign details remain gaps, hindering comprehensive understanding.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
3
Campaigns
21
IOCs
0
Observed Data
0
Tactics