Barracuda is a financially motivated ransomware and data-extortion operation with an international victim base. Its targets include healthcare providers, manufacturers, technology companies, professional-services firms, transportation organizations, and government institutions. The operation publicly identifies victims, offers stolen information for sale, publishes compromised data, and threatens disclosure to pressure organizations into responding to its demands. Exposed material includes personal and medical information, internal business documents, email archives, databases, source code, and manufacturing information. Its targeting includes industrial automation suppliers serving water and wastewater utilities, although this does not establish direct compromise or disruption of their utility customers. Barracuda claimed responsibility for the independently confirmed cyberattack against U.S. industrial automation company Micro-Comm; investigators characterized that intrusion as opportunistic. The operation describes itself as financially motivated and independent of government sponsorship. Its geographic origin is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against Croatia’s Ministry of Agriculture, Forestry and Fisheries, discovered on October 9, 2026. The group claims to possess complete database dumps and documents from the ministry’s main file server, including residents’ personal information, agricultural registration records, contracts, and confidential documents. It advertises the stolen data for sale for $50,000. The content does not independently verify these claims or identify a ransomware family.
Alleged ransomware/data-extortion operation targeting Automovil Club del Ecuador ANETA in Ecuador, claiming exfiltration of customer records, financial documents, and a large email archive, then advertising the data for sale for $30,000.
Barracuda claims to possess customer databases and applications, customer photos, financial documents, and an entire year's email-server dump from Automovil Club del Ecuador ANETA in Ecuador. The listing includes numerous mailbox archive filenames and advertises the data for sale for $30,000; no ransom payment deadline or data size is stated.
Ransomware and data-extortion activity targeting International Chemical Co.; the group claims theft of sales data, proprietary formulas, patents, manufacturing instructions, contracts, and partner information, and is selling the data for $50,000.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.