Wallstreet is a ransomware threat group that emerged in 2026 and has been publicly associated with multiple victim claims. Reported victims indicate a focus on opportunistic targeting across several sectors, including manufacturing, health care, and government entities. Known victim organizations include U.S.-based manufacturers, a police department, a hospital, and a medical assistance and health insurance provider in Ecuador. Reported incidents are characterized as ransomware attacks accompanied by data breaches, indicating that the group conducts extortion operations involving stolen data. Available reporting supports Wallstreet’s activity against organizations in the United States and Ecuador, with observed victimology spanning industrial firms, automotive-related businesses, public-sector organizations, and health-related services. Publicly available information in this dataset does not establish a confirmed national affiliation, malware lineage, or sub-group structure for Wallstreet.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against T.RAD North America.
Conducting a ransomware attack against Black Hills Bentonite, a US manufacturing organization.
Newly emerged ransomware/extortion group noted in June 2026.
Conducting a ransomware attack against Gold Standard Automotive.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.