info@ranshelp is a ransomware-associated actor observed in financial tracing tied to laundering of victim payments. It has been linked to a cluster of cryptocurrency addresses used to process proceeds from ransomware incidents alongside activity associated with INC, Lynx, and Sinobi Group. Available reporting places non-VPN access to that laundering cluster in Iran, indicating an operational nexus there, but public detail on the actor’s broader structure, malware lineage, victimology, and internal organization remains limited. Based on the confirmed activity, info@ranshelp is involved in ransomware-related post-compromise monetization and fund movement, with demonstrated use of laundering infrastructure to handle extortion proceeds. High-confidence public evidence is insufficient to attribute additional capabilities, specific targeting patterns, or a more precise organizational profile.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.