UmBra is a ransomware-associated threat group linked to reported attacks against educational institutions, technology companies, mining businesses, and furniture suppliers. Its reported victims include IIT Roorkee and Manipal Academy of Higher Education in India; FSE, Cairo University and Beni Suef Technological University in Egypt; and Four Hands LLC in the United States. Other reported targets include cybersecurity provider Raqib, IT services company SANAtech Global Solutions, and Tharisa, a Cyprus-based mining group with major operations in South Africa. In October 2026, UmBra claimed responsibility for an attack against Tharisa and threatened to publish allegedly compromised sensitive information unless a company representative entered negotiations. This establishes the group's use of data-release threats for extortion, but does not establish whether it encrypted systems or operated an encryption-less extortion campaign. Its geographic origin, organizational structure, initial-access methods, malware tooling, and technical capabilities beyond extortion are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed to a ransomware attack against SOCOCO, reportedly discovered on October 8, 2026, at 21:36 UTC. The report inconsistently identifies the victim as France-based and Brazilian, and labels its sector Technology while describing a food company. No malware family, exploited vulnerability, or detailed attack methods are provided.
Reportedly conducted a ransomware attack against FSE, Cairo University in Egypt. The report identifies a data breach discovered on October 8, 2026, at 20:27 UTC, but provides no technical details or named ransomware family.
Reportedly conducted a ransomware attack against IIT Roorkee, an educational institution in India. The report dates the breach to October 8, 2026, at 20:27 UTC and its discovery to 20:28 UTC.
Reportedly conducted a ransomware attack against Manipal Academy of Higher Edu, an Indian university. The report lists the breach time as October 8, 2026, at 20:28 UTC and discovery one minute later. No specific ransomware family, exploitation method, or attribution evidence is provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.