Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: LinkC

Description

Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI, cloud, aerospace, and manufacturing companies — including H2O.ai — demanding ransoms as high as $15 million using double-extortion tactics. Known victims: 4 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Linkc is a medium-sophistication ransomware group operating since late January 2025. They primarily target US-based AI, cloud computing, aerospace, and manufacturing industries using double-extortion tactics to demand ransoms up to $15 million. Their operations have already affected at least four organizations, including H2O.ai.

Goals & Targeting

Linkc targets US-based AI, cloud computing, aerospace, and manufacturing industries likely due to the high value of their intellectual property and data. These sectors represent attractive opportunities for financial gain through ransom demands and data resale. The group's double-extortion tactics reflect a strategic focus on maximizing both immediate ransom payments and long-term revenue streams from stolen data. Their choice of victims suggests an operational focus on mid-sized organizations with potentially weaker security postures but sufficient assets to meet high ransom demands.

Enhanced Description

Linkc is a recently emerged ransomware group that has garnered attention for its aggressive targeting of high-value US-based technology and industrial sectors. The group operates a Tor-based data leak site as part of their double-extortion strategy, combining the encryption of victim files with the threat to publish stolen data unless a substantial ransom is paid. Their campaigns have specifically targeted mid-sized organizations in the AI, cloud computing, aerospace, and manufacturing industries. The group's operational timeline spans from early 2025 to late February 2026, with known campaigns involving victims such as Sajet Products and StrongLink. Linkc's use of double extortion aligns with broader trends in ransomware evolution, aiming to maximize financial gain by leveraging both data encryption and reputational damage. Their targeting of sectors with significant intellectual property and sensitive data underscores a strategic focus on maximizing payout potential.

Key Capabilities

  • Ransomware deployment
  • Double extortion operations
  • Tor-based data leak site management
  • Spear-phishing attacks
  • Data exfiltration
  • High-value target identification

Software / Tooling

Ransomware (Encrypts files)
Phishing tools (Spear-phishing campaigns)
C2 infrastructure (Tor-based)
Data exfiltration utilities
Network traversal tools

Campaigns & Victims

Linkc has conducted several notable campaigns, including targeting H2O.ai and other mid-sized tech companies. Their operations typically involve initial access via phishing emails or network exploitation, followed by data encryption and exfiltration. The group's operational tempo appears to be opportunistic, with a focus on striking high-impact targets in sectors with deep intellectual property and customer trust dependencies. Their campaigns often feature prolonged lateral movement within networks to gather sensitive information before deploying ransomware.

IOC Patterns

  • Spear-phishing emails with attachments
  • C2 communication over Tor
  • Ransomware encryption patterns
  • Phishing URLs linked to known campaigns
  • Encrypts files with specific extensions

Recommended Actions

  • Implement strict email filtering and endpoint detection for spear-phishing attempts.
  • Conduct regular network segmentation and privileged access management.
  • Monitor for unusual network traffic indicative of data exfiltration.
  • Backup critical systems regularly and test recovery processes.
  • Consider deploying Zero Trust Architecture to mitigate internal lateral movement.

Suggested Tags

Ransomware
Financial-gain
Criminal
Double-Extortion
US-targeted

Confidence Assessment

Moderate confidence in Linkc's identity and operations based on known victims and TTPs. Limited IOC samples and campaign details remain gaps, hindering comprehensive understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 20
URL 20
https://www.roblox.com.bn/games/102156635116501/Murder-Drones-Absolute-Battle?privateServerLinkCode=28405194768188635998407230900998&game_id=102156635116501&game_name=Murder-Drones-Absolute-Battle
80% TLP:CLEAR
https://www.roblox.com.et/games/80155953911794/-Huge-Playground-Playplace?privateServerLinkCode=40356220944328363609251126240211
80% TLP:CLEAR
https://www.roblox.et/games/104715542330896/BlockSpin?privateServerLinkCode=12967758233438862154292342439465
80% TLP:CLEAR
https://www.roblox.com.bi/games/17625359962/RIVALS?privateServerLinkCode=26794274690145427755087934733914
80% TLP:CLEAR
https://www.roblox.com.bi/games/94117165224282/Escape-Tsunami-for-Dandy-QQL?privateServerLinkCode=35976373059471016383959043181064&game_id=94117165224282&game_name=Escape-Tsunami-for-Dandy-QQL
80% TLP:CLEAR
https://www.roblox.com.bi/games/130733429041738/NEW-Squabble-Game-RP?privateServerLinkCode=35976373059471016383959043181064&game_id=130733429041738&game_name=NEW-Squabble-Game-RP
80% TLP:CLEAR
https://www.roblox.com.bi/games/85369912495910/PRE-ALPHA-The-Remains-of-Robloxia?privateServerLinkCode=35976373059471016383959043181064&game_id=85369912495910&game_name=PRE-ALPHA-The-Remains-of-Robloxia
80% TLP:CLEAR
https://www.roblox.com.bi/games/18687417158/FIXES-Forsaken?privateServerLinkCode=35976373059471016383959043181064&game_id=18687417158&game_name=FIXES-Forsaken
80% TLP:CLEAR
https://www.roblox.com.bi/games/2768379856/3008-2-74?privateServerLinkCode=35976373059471016383959043181064&game_id=2768379856&game_name=3008-2-74
80% TLP:CLEAR
https://www.roblox.com.bi/games/11765402359/Clip-It?privateServerLinkCode=35976373059471016383959043181064&game_id=11765402359&game_name=Clip-It
80% TLP:CLEAR
https://www.roblox.com.bi/games/13600218266/My-Movie?privateServerLinkCode=35976373059471016383959043181064&game_id=13600218266&game_name=My-Movie
80% TLP:CLEAR
https://www.roblox.com.ml/games/142823291/Murder-Mystery-2?privateServerLinkCode=556237238747184974201575374363
80% TLP:CLEAR
https://www.robiox.com.py/games/116342226627962/Duemer-with-makima?privateServerLinkCode=034074815360930863747828703952
80% TLP:CLEAR
https://www.roblox.com.et/games/78896868574590/Untitled-Cons-Experience-New?privateServerLinkCode=23658489500385543297162075220903
80% TLP:CLEAR
https://www.robiox.com.ps/games/2753915549/Blox-Fruits?privateServerLinkCode=12415183278034696495672693097530
80% TLP:CLEAR
https://www.roblox.et/games/2753915549/Blox-Fruits?privateServerLinkCode=81286767085957624934779909819308
80% TLP:CLEAR
http://www.roblox.com.ml/games/16732694052/Fisch-HUMPBACK?privateServerLinkCode=879419823283425228157216249356
80% TLP:CLEAR
https://www.roblox.com.ml/games/78896868574590/Untitled-Cons-Experience-New?privateServerLinkCode=425861301861783283899380535682
80% TLP:CLEAR
https://www.roblox.com.ml/games/77747658251236/Sea-2-Update-Sailor-Piece?privateServerLinkCode=123173420535715543277593962283
80% TLP:CLEAR
https://www.roblox.com.ml/games/102208116895989/Untitled-Experience?privateServerLinkCode=247772518604175568104568742480
80% TLP:CLEAR

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

3

Campaigns

21

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Financial-gain
Criminal
Double-Extortion
US-targeted

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 29, 2025
Last Seen
Feb 27, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.