Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors. Known victims: 49 3 ransom note(s) on file
Objectives
Executive Summary
Tengu is a recently emerged Ransomware-as-a-Service (RaaS) operation utilizing a double-extortion model and Living Off The Land Binaries (LOLBins). Targeting multiple sectors including consumer goods and healthcare, Tengu poses a significant risk to organizations due to its sophisticated tactics and rapid campaign activity.
Goals & Targeting
Tengu's primary goals are financial gain via ransoms and reputational damage through data leaks. The targeting of sectors with high data sensitivity indicates an intent to maximize both ransom demands and the impact of leaked information, affecting a diverse range of industries and potentially global operations.
Enhanced Description
Tengu emerged in October 2025 as a RaaS operator employing a double-extortion ransomware model. This approach combines data encryption with threats of leakages, enhancing the pressure on victims to comply. The use of LOLBins allows Tengu's activities to mimic legitimate administrative tasks, making detection challenging. Targeting sectors such as healthcare and real estate suggests an emphasis on industries holding sensitive or valuable data. Despite being a medium-sophistication threat actor, Tengu demonstrates effective operational methods through its campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Tengu has executed campaigns against diverse targets, including Sileno Companies Inc and Eos Technology srl. With 49 recorded victims, Tengu demonstrates an aggressive approach likely facilitated by affiliates or partners. The group's operational tempo is brisk, with activity tracked from October 2025 to March 2026, indicating both persistence and adaptability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence based on campaign data and known TTPs. Gaps include detailed TTP specifics, targeted countries beyond linked campaigns, and exact toolset used by the actor.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
4
Campaigns
0
IOCs
0
Observed Data
0
Tactics