Eclipse is a ransomware threat group associated with attacks against organizations in Singapore, India, the United States, Brazil, France, and Japan. Its attributed activity spans at least August through October 2026 and affects manufacturing, transportation and logistics, media, hospitality, software, legal services, food distribution, and public education. Named targets include Simplex Engineering & Foundry Works, Global AirFreight International, The Japan Times, TTG Asia Media, Royal Plaza On Scotts, ETNA Software, The Zhou Law Group, Rosello et Fils, Dublin City Schools GA, DIPECARR, and Moscord. The group's targeting encompasses multiple unrelated industries and geographic regions. Its country of origin, organizational structure, initial-access techniques, malware tooling, and specific encryption or data-extortion practices are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against the Brazil-based organization dipecarr.com.br. The report lists the breach date as October 8, 2026, and discovery at 21:21 UTC that day. It provides no technical evidence, named malware, exploited vulnerabilities, or independently verified victim details. The stated manufacturing sector is insufficient to determine a specific GICS industry group.
Reportedly conducted a ransomware attack against simplexengg.in, an India-based manufacturing organization. The incident was dated October 8, 2026, and discovered at 17:53 UTC that day. The content provides no technical details or attribution evidence.
The report attributes a ransomware attack against sanjoseattorneys.com to Eclipse. It lists the breach date as October 8, 2026, and discovery at 17:52 UTC that day. The victim is categorized as Professional Services, but the content cautions that its identity and operations have not been independently verified. No technical evidence or named ransomware family is provided.
Reportedly conducted a ransomware attack against DIPECARR, a Brazilian truck-parts distributor. The report lists the breach date as October 8, 2026, and discovery at 14:22 UTC that day. No technical attack details are provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.