Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States. Known victims: 141
Objectives
Executive Summary
Sarcoma is a ransomware group that emerged in July 2024, rapidly establishing itself as one of the most active global threats by mid-2025, with at least 141 documented victims. Targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services globally, Sarcoma primarily seeks financial gain through extortion. Unlike other ransomware groups, Sarcoma focuses heavily on organizational-gain motivations, suggesting a structured approach to victim selection and campaign management.
Goals & Targeting
Sarcoma’s strategic objectives center on generating maximum financial return through ransomware deployment. They target sectors with high organizational resilience gaps and the potential for significant operational disruption, such as manufacturing and healthcare. Their geographic concentration in the United States suggests a focus on regions with higher corporate ransom payment capabilities. The group likely aims to maximize both the volume of victims and the average ransom amount by targeting industries where the impact of downtime is severe but organizational security measures may be inadequate for full protection.
Enhanced Description
Sarcoma is a financially motivated ransomware group that first appeared in mid-2024 and quickly gained notoriety for its aggressive campaigns. By the middle of 2025, Sarcoma had targeted over 141 victims across multiple industries, including manufacturing, retail, healthcare, legal services, and business operations. Their activities span both international and regional markets, with a significant concentration of attacks in the United States (approximately 50% of their victims). The group's operational approach is characterized by its ability to quickly scale its campaigns, leveraging sophisticated techniques to compromise organizations and deploy ransomware effectively. Sarcoma’s primary motivation is financial gain, aligning their tactics with the broader goals of extortion and profit maximization. Their targeting strategy focuses on mid-market companies, which are often less secure but have sufficient resources to pay ransoms without full organizational shutdown.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Sarcoma has demonstrated a rapid escalation in campaign intensity, from its debut in July 2024 to mid-2025. Their victims include both small and medium-sized enterprises (SMEs) and larger corporations within targeted industries. Notable campaigns involve coordinated phishing attempts followed by rapid ransomware deployment, often leading to significant business disruption. The group’s operational tempo suggests a professional approach with well-coordinated campaign planning and execution.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data available on Sarcoma is moderately reliable, with confirmed victims and observable patterns in their TTPs. However, specific technical details about their attack vectors and toolset remain limited. The group appears to maintain a professional operational approach but lacks direct attribution to state-sponsored actors. Further IOC correlation and campaign analysis would enhance the understanding of their full capabilities.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics