Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Para detección/bloqueo en tu EDR/SIEM. Fuente: ransomware.live.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
benzona ransomware
*/
rule benzona_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.benzona"
description = "Detects benzona ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "benzona" ascii nocase
$name2 = "BENZONA" ascii
$onion = "benzona.onion" ascii nocase
condition:
any of them
}
[AI generated] "Casamedica.com.gt" is a Guatemala-based company that provides a range of medical equipment and supplies. Their product range includes everything from surgical instruments to hospital furniture and diagnostic equipment. Not just limited to sales, Casamedica also provides maintenance services for the equipment. They aim to improve the healthcare sector by catering to the specific needs of professionals in the field.
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| casamedica.com.gt | GT | Healthcare | — | 30 ene 2026 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética