Also known as: ms13-089
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor. Known victims: 3
Objectives
Executive Summary
MS13089, also known as ms13-089, is a newly emerged ransomware group first observed in December 2025. The group operates primarily as a double extortion actor, targeting victims with both data encryption and exfiltration. Their activities have been limited to a few incidents, including the compromise of a law firm, suggesting an emerging threat that organizations should monitor closely.
Goals & Targeting
The strategic objectives of MS13089 appear to be driven by the pursuit of financial gain through ransom payments. Their targeting profile suggests a focus on sectors or organizations where data value is high, such as law firms, which may possess sensitive client information. The group's geographic targeting remains unclear, but their limited activity indicates they may still be developing their operational playbook.
Enhanced Description
MS13089 is a relatively new ransomware group that surfaced in December 2025. The group's name appears to be a nod to Microsoft Security Bulletin MS13-089, possibly reflecting an interest in leveraging or targeting Microsoft-related vulnerabilities or services. Operating as a double extortion actor, the group encrypts victims' data and demands ransoms for decryption keys while also threatening to release stolen information unless paid. Their primary focus has been on financial gain through ransom payments, with known victims including a law firm. The group's operational timeline is short, with activity observed between December 2025 and May 2026.
Key Capabilities
MITRE ATT&CK Tactics
Campaigns & Victims
MS13089 has been linked to a limited number of campaigns, with one notable example involving the compromise of Brittany Residential. The group's short lifespan and limited victim count suggest they are either in an active development phase or undergoing operational maturation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in MS13089's profile is low due to the limited data available on their campaigns, targets, and specific tactics. While their alias and operational focus provide some context, gaps remain in understanding their full capabilities, infrastructure, and long-term goals.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
1
IOCs
0
Observed Data
0
Tactics