Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors sarcoma

Description

Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States. Known victims: 141

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Sarcoma is a ransomware group that emerged in July 2024, rapidly establishing itself as one of the most active global threats by mid-2025, with at least 141 documented victims. Targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services globally, Sarcoma primarily seeks financial gain through extortion. Unlike other ransomware groups, Sarcoma focuses heavily on organizational-gain motivations, suggesting a structured approach to victim selection and campaign management.

Goals & Targeting

Sarcoma’s strategic objectives center on generating maximum financial return through ransomware deployment. They target sectors with high organizational resilience gaps and the potential for significant operational disruption, such as manufacturing and healthcare. Their geographic concentration in the United States suggests a focus on regions with higher corporate ransom payment capabilities. The group likely aims to maximize both the volume of victims and the average ransom amount by targeting industries where the impact of downtime is severe but organizational security measures may be inadequate for full protection.

Enhanced Description

Sarcoma is a financially motivated ransomware group that first appeared in mid-2024 and quickly gained notoriety for its aggressive campaigns. By the middle of 2025, Sarcoma had targeted over 141 victims across multiple industries, including manufacturing, retail, healthcare, legal services, and business operations. Their activities span both international and regional markets, with a significant concentration of attacks in the United States (approximately 50% of their victims). The group's operational approach is characterized by its ability to quickly scale its campaigns, leveraging sophisticated techniques to compromise organizations and deploy ransomware effectively. Sarcoma’s primary motivation is financial gain, aligning their tactics with the broader goals of extortion and profit maximization. Their targeting strategy focuses on mid-market companies, which are often less secure but have sufficient resources to pay ransoms without full organizational shutdown.

Key Capabilities

  • Ransomware deployment
  • Spear-phishing campaigns
  • Leverage of internal vulnerabilities
  • Sophisticated encryption techniques
  • Exfiltration of sensitive data

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
credential Dumping
Lateral Movement

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078.001
T1204.001

Software / Tooling

Custom ransomware (Sarcoma)
Phishing emails with malicious links
Cobalt Strike-like tools for internal movement

Campaigns & Victims

Sarcoma has demonstrated a rapid escalation in campaign intensity, from its debut in July 2024 to mid-2025. Their victims include both small and medium-sized enterprises (SMEs) and larger corporations within targeted industries. Notable campaigns involve coordinated phishing attempts followed by rapid ransomware deployment, often leading to significant business disruption. The group’s operational tempo suggests a professional approach with well-coordinated campaign planning and execution.

IOC Patterns

  • Phishing emails containing malicious links or attachments
  • Ransomware payloads delivered via PowerShell scripts
  • Exfiltration of sensitive data prior to ransomware deployment
  • Command and Control (C2) communication over HTTP/HTTPS protocols

Recommended Actions

  • Implement robust phishing detection mechanisms, including email filtering and endpoint protection
  • Enhance internal network monitoring for unusual activity patterns
  • Conduct regular employee training on identifying social engineering tactics
  • Encrypt sensitive data at rest and in transit
  • Establish a strong incident response plan with regular演练

Suggested Tags

Ransomware
Criminal
Mid-market targeting
Financial gain
Organizational disruption

Confidence Assessment

The data available on Sarcoma is moderately reliable, with confirmed victims and observable patterns in their TTPs. However, specific technical details about their attack vectors and toolset remain limited. The group appears to maintain a professional operational approach but lacks direct attribution to state-sponsored actors. Further IOC correlation and campaign analysis would enhance the understanding of their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Criminal
Mid-market targeting
Financial gain
Organizational disruption

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 9, 2024
Last Seen
Mar 30, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.