cmd organization
Ransomware group profile
Description
CMD Organization is a new ransomware group that surfaced in May 2026, claiming to be an IT security firm while engaging in ransomware activities. Their unique auction-based extortion model incentivizes financial gain through public listings of stolen data, setting them apart from traditional groups.
Key insights
- •Utilizes an auction-based extortion model to maximize ransom payments.
- •Exploits vulnerabilities in public-facing applications for initial access.
- •Focuses on data extraction from information repositories.
- •Employs tactics like double extortion and public data leaks on dark web platforms.
- •Operates using a combination of onion sites and clearnet domains.
Threat Level & Status Breakdown
For cmd organization · Based on incidents in selected period
Recent activity
Monthly attack count for cmd organization in the selected period
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for cmd organization
T1213
Data from Information Repositories
T1071
Application Layer Protocol
T1562
Impair Defenses
T1059
Command and Scripting Interpreter
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
T1021
Remote Services
T1190
T1190
T1041
T1041
T1037
T1037
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
Victims(21)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| Pinnacle Re-Tec | — | — | Professional Services | Unknown | about 20 hours ago | |
| Southern design RV | — | — | Retail & E-Commerce | Unknown | about 22 hours ago | |
| New FACOM Co., Ltd. | — | — | Manufacturing | Unknown | 10 days ago | |
| SeeWriteHear | — | — | Technology | Unknown | 17 days ago | |
| Lake Washington School District | — | US United States | Education | Unknown | 21 days ago | |
| Lee Law Offices | — | US United States | Professional Services | Unknown | 22 days ago | |
| Capital Family Physicians | — | US United States | Healthcare | Unknown | 23 days ago | |
| Hospice Savannah | — | US United States | Healthcare | Unknown | 24 days ago | |
| North Dallas Shared Ministries | — | US United States | Government & Defense | Unknown | 27 days ago | |
| Stonehenge Therapeutic Community | — | US United States | Healthcare | Unknown | about 1 month ago | |
| Holy Name of Jesus | — | US United States | Other | Unknown | about 1 month ago | |
| Raise the Bottom | — | US United States | Healthcare | Unknown | about 1 month ago | |
| WholeHealth Chicago | — | US United States | Healthcare | Unknown | about 1 month ago | |
| Houston Eye Associates | — | US United States | Healthcare | Unknown | about 1 month ago | |
| Goodstone Group | — | — | Hospitality | Unknown | about 1 month ago | |
| Ira & Larry Goldberg Coins & Collectibles | — | — | Retail & E-Commerce | Unknown | about 1 month ago | |
| Advanced Software Products Group | — | — | Technology | Unknown | about 1 month ago | |
| PennEastern Architects | — | US United States | Professional Services | Unknown | about 1 month ago | |
| Cytek Biosciences | — | US United States | Healthcare | Unknown | about 2 months ago | |
| JG Stewart Construction | — | — | Other | Unknown | about 2 months ago |
Page 1 of 2
Affected countries(6)
Countries where this group has been reported to target or leak victims.