CMD Organization is a ransomware and extortion threat group active by mid-2026. It has been observed claiming intrusions against organizations in multiple countries, with victims spanning education, government, financial services, health-related nonprofits, manufacturing, professional services, retail, and energy-related organizations. The group has publicly claimed attacks against universities and municipalities and has posted samples of allegedly stolen data on a Tor-based leak site, indicating a public shaming and coercion model centered on data exposure. The group has been described as operating an auction-based extortion model. Reported incidents show it stealing data and threatening publication, including cases where it advertised large volumes of exfiltrated information and published sample documents to pressure victims. Available reporting supports extortion and data-theft-driven ransomware activity, but does not provide high-confidence detail on its malware family, encryption workflow, or deeper tradecraft such as initial access vectors, persistence mechanisms, or lateral movement techniques. Known aliases include cmdorganization and cmd_organization. Victimology indicates broad opportunistic targeting rather than a narrowly specialized sector focus, with repeated activity against organizations in the United States and Canada and additional victims in the United Kingdom, Australia, Norway, Ghana, and Pakistan. The actor appears financially motivated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a new entrant using an auction-based extortion model.
Conducting a ransomware attack against Stewart Belland & Associates Inc.
Conducting a ransomware attack against Contact Group.
Conducting a ransomware attack against Collge Mont Notre-Dame de Sherbrooke.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.