Back to Intelligence

LAMASHTU Ransomware Gang: 4 New Leak-Site Listings Across ES, DE, MX — Sector Targeting Analysis & Detection Rules

SA
Security Arsenal Team
October 6, 2026
11 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-06 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

LAMASHTU Ransomware Gang: 4 New Leak-Site Listings Across ES, DE, MX — Sector Targeting Analysis & Detection Rules

Executive Summary

Security Arsenal's dark web monitoring pipeline has observed four new listings on the LAMASHTU ransomware group's leak site, all published 2026-10-05. The group claims to have compromised organizations in the manufacturing, transportation, and audiovisual/services sectors, with listings concentrated in Spain (2), Germany (1), and Mexico (1). Every listing was independently corroborated by a second leak-site crawler, confirming the gang published these claims — but none of the alleged breaches are confirmed.

Organizations named in this wave are: Fluge Audiovisuales (ES), Bender Tribunenbau (DE), TRANS LOGROÑO SOCIEDAD ANONIMA (ES), and Grupo Industrial Tauro (MX). These are criminal accusations, not verified incidents. Defenders in mid-market manufacturing and logistics across Europe and Latin America should treat this bulletin as a sector-level exposure warning and apply the detection content below immediately.

Sourcing & Verification

  • Corroboration status: 4 of 4 listings were independently observed by a second leak-site crawler (multi-source). 0 listings appear on a single source only.
  • What corroboration means: Independent crawler observation confirms the threat actor published the claim. Inclusion in this briefing reflects the threat actor's claim and is NOT confirmation of a breach.
  • Disputed listings: A named organization may dispute the listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and not every incident is reportable, so neither silence nor denial settles the question.
  • Corrections: Security Arsenal will publish corrections and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — LAMASHTU

LAMASHTU (named for the Mesopotamian demoness, a naming convention consistent with theatrical criminal branding) operates in the mid-tier ransomware ecosystem. Key assessed characteristics:

  • Model: Assessed Ransomware-as-a-Service (RaaS) operation recruiting affiliates through closed underground forums; affiliate-driven intrusions with centralized leak-site publication and negotiation infrastructure.
  • Aliases: No widely documented aliases at time of publication; tracking as LAMASHTU pending overlap analysis with predecessor families.
  • Ransom demands: Typical of mid-tier RaaS targeting mid-market firms — demands observed in comparable campaigns range from low six figures to ~$2M USD, scaled to victim revenue.
  • Initial access: Phishing with macro/ISO-lure attachments, exploitation of exposed remote access (VPN appliances, RDP), and opportunistic exploitation of internet-facing management planes. Supply-chain/developer-tooling compromise is an emerging vector across the ecosystem (see CVE discussion below).
  • Extortion model: Double extortion — data theft staged prior to encryption, with leak-site publication as pressure. The 2026-10-05 wave follows this pattern: names posted first, data release implied as escalation.
  • Dwell time: Comparable campaigns show 5–14 days from initial access to detonation, with exfiltration typically occurring 24–72 hours before encryption.

Current Campaign Analysis

Sector Targeting

  • Manufacturing (2): Bender Tribunenbau (DE), Grupo Industrial Tauro (MX) — consistent with the ecosystem-wide preference for operational-technology-adjacent manufacturers with low tolerance for downtime.
  • Transportation (1): TRANS LOGROÑO SOCIEDAD ANONIMA (ES) — logistics firms present time-pressure leverage.
  • Other/Services (1): Fluge Audiovisuales (ES) — event-production sector; likely opportunistic rather than strategic.

Geographic Concentration

Spain accounts for half of this wave (2/4), with Germany and Mexico rounding out a European–Latin American footprint. Spanish-language targeting capability within the affiliate base is plausible.

Victim Profile

All four organizations fit the classic mid-market ransomware target band: estimated revenues in the tens to low hundreds of millions USD, large enough to pay, small enough to lack 24/7 SOC coverage. Mid-market manufacturers and logistics operators remain the highest-yield demographic for mid-tier RaaS crews.

Posting Frequency & Escalation

Four listings in a single day (2026-10-05) suggests either a batch publication of accumulated intrusions or an affiliate pushing multiple victims through negotiation simultaneously. Watch for data-sample releases within 7–14 days as the escalation trigger.

CVE Exposure — Hypothesis Only

We have no evidence linking any specific CVE to any specific named organization above. However, the following CISA KEV entries with confirmed ransomware use represent plausible sector-level exposure consistent with this gang's known access patterns:

  • CVE-2026-50751 (Check Point Security Gateway, improper authentication) — VPN-edge compromise is a hallmark initial access vector for mid-tier RaaS affiliates.
  • CVE-2026-20316 (Cisco Secure FMC, hard-coded password) — network management plane takeover enables stealthy pre-positioning.
  • CVE-2026-59310 (VMware vCenter path traversal) — virtualization-layer access is the single highest-impact pre-encryption objective; hypervisor compromise enables mass VM encryption.
  • CVE-2026-63077 (JetBrains TeamCity deserialization) — build-server compromise supports supply-chain lateral movement.
  • CVE-2026-48027 (Nx Console embedded malicious code) — developer-tooling poisoning vector.

Priority action: If you run Check Point gateways or vCenter, verify patch status against CVE-2026-50751 and CVE-2026-59310 today.

Detection Engineering

The following Sigma rules target TTPs consistent with LAMASHTU's assessed playbook: VPN/edge exploitation follow-on activity, phishing macro execution, RDP brute force, lateral movement via PsExec/WMI, and pre-encryption data staging with shadow copy deletion.

YAML
---
title: Suspicious Office Macro Spawning Script Interpreter
description: Detects Office applications spawning script interpreters or shells, consistent with phishing macro execution used in ransomware initial access
id: 7a1f3c20-4b2d-4e91-a5c6-lamashtu0001
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/06
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\outlook.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare legitimate Office add-ins
level: high
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.t1059
---
title: RDP Brute Force Followed By Successful Logon
description: Detects multiple failed RDP authentications followed by a success from the same source, indicating possible brute-force initial access
id: 7a1f3c20-4b2d-4e91-a5c6-lamashtu0002
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/06
logsource:
  product: windows
  service: security
detection:
  selection_failed:
    EventID: 4625
    LogonType: 10
  selection_success:
    EventID: 4624
    LogonType: 10
  condition: selection_failed or selection_success
  timeframe: 10m
  aggregation:
    failed_count:
      condition: selection_failed
      group-by: SourceAddress
      threshold: 8
    success_after:
      condition: selection_success
      group-by: SourceAddress
falsepositives:
  - Legitimate users with repeated password typos
level: high
tags:
  - attack.credential_access
  - attack.t1110
  - attack.t1021.001
---
title: Pre-Ransomware Staging - Shadow Copy Deletion and Mass Archive Creation
description: Detects Volume Shadow Copy deletion via vssadmin/wmic and mass 7z/rar archive creation indicative of pre-encryption data staging and anti-recovery behavior
id: 7a1f3c20-4b2d-4e91-a5c6-lamashtu0003
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/06
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'recoveryenabled no'
      - 'bootstatuspolicy ignoreallfailures'
  selection_archive:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\rar.exe'
      - '\winrar.exe'
    CommandLine|contains:
      - ' a '
      - ' -p'
  condition: 1 of selection_*
falsepositives:
  - Backup administrators running legitimate shadow copy maintenance
  - IT compression of project archives
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.t1560.001

The following Microsoft Sentinel KQL query hunts lateral movement and pre-ransomware staging: remote service creation (PsExec-style), WMI remote execution, and suspicious admin-share writes clustered on a single host within a short window — the classic pre-detonation pattern.

KQL — Microsoft Sentinel / Defender
// LAMASHTU hunt: lateral movement + pre-ransomware staging indicators
// Lookback: 14 days. Tune thresholds to environment baseline.
let lookback = 14d;
let ServiceInstall = SecurityEvent
    | where TimeGenerated >= ago(lookback)
    | where EventID == 7045
    | where ServiceName has_any ("PSEXESVC", "RemCom", "paexec", "csexec")
       or ServiceFileName has_any ("ADMIN$", "\\PSEXESVC")
    | project TimeGenerated, Computer, Account, ServiceName, ServiceFileName, IpAddress;
let WmiRemote = SecurityEvent
    | where TimeGenerated >= ago(lookback)
    | where EventID == 4688
    | where Process has "wmic.exe" and CommandLine has_any ("/node:", "process call create")
    | project TimeGenerated, Computer, Account, CommandLine;
let AdminShareWrites = SecurityEvent
    | where TimeGenerated >= ago(lookback)
    | where EventID == 5145
    | where ShareName has_any ("\\ADMIN$", "\\C$")
    | where RelativeTargetName endswith ".exe" or RelativeTargetName endswith ".bat" or RelativeTargetName endswith ".ps1"
    | project TimeGenerated, Computer, Account, ShareName, RelativeTargetName, IpAddress;
union ServiceInstall, WmiRemote, AdminShareWrites
| summarize IndicatorCount = count(), Techniques = make_set(Type), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
    by Computer, Account
| where IndicatorCount >= 3
| order by IndicatorCount desc

The following PowerShell script provides rapid-response checks: exposed RDP listeners, scheduled tasks created in the last 7 days, recently deleted shadow copies, and suspicious new local admin accounts.

PowerShell
# Security Arsenal - LAMASHTU Rapid Triage Script
# Run as Administrator on suspect hosts. Outputs to C:\Triage\LAMASHTU_Triage_<hostname>.txt
$out = "C:\Triage"; New-Item -ItemType Directory -Path $out -Force | Out-Null
$log = "$out\LAMASHTU_Triage_$env:COMPUTERNAME.txt"
"=== LAMASHTU RAPID TRIAGE - $(Get-Date) - $env:COMPUTERNAME ===" | Out-File $log

"`n[1] RDP Exposure Check" | Out-File $log -Append
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
"RDP Enabled: $(if ($rdp.fDenyTSConnections -eq 0) {'YES - EXPOSED'} else {'No'})" | Out-File $log -Append
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Format-Table | Out-String | Out-File $log -Append

"`n[2] Scheduled Tasks Created in Last 7 Days" | Out-File $log -Append
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) } |
  Select-Object TaskName, TaskPath, Date, @{n='Action';e={$_.Actions.Execute}} | Format-List | Out-String | Out-File $log -Append

"`n[3] Shadow Copy Status (recent deletion = pre-encryption indicator)" | Out-File $log -Append
"Current shadow copies:" | Out-File $log -Append
vssadmin list shadows 2>&1 | Out-String | Out-File $log -Append
"VSS deletion events in last 7 days (Event ID 7036/vssadmin usage):" | Out-File $log -Append
Get-WinEvent -FilterHashtable @{LogName='System'; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
  Where-Object { $_.Message -match 'shadow' } | Select-Object TimeCreated, Id, Message -First 20 | Format-List | Out-String | Out-File $log -Append

"`n[4] New Local Admin Accounts (last 14 days)" | Out-File $log -Append
Get-LocalGroupMember -Group 'Administrators' -ErrorAction SilentlyContinue | Format-Table | Out-String | Out-File $log -Append
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4720; StartTime=(Get-Date).AddDays(-14)} -ErrorAction SilentlyContinue |
  Select-Object TimeCreated, Message -First 15 | Format-List | Out-String | Out-File $log -Append

"`n[5] Suspicious Processes (staging/archiving tools)" | Out-File $log -Append
Get-Process | Where-Object { $_.Name -match '^(7z|rar|winrar|psexec|wmic|anydesk|teamviewer|ngrok|chisel)' } |
  Select-Object Name, Id, Path | Format-Table | Out-String | Out-File $log -Append

"`n=== TRIAGE COMPLETE ===" | Out-File $log -Append
Write-Host "Triage output written to $log"

Incident Response Priorities

T-Minus Detection Checklist (Before Encryption Fires)

  • Mass archive creation (7z/rar with password flags) on file servers or exec endpoints
  • vssadmin delete shadows, bcdedit recoveryenabled no, or wbadmin delete catalog execution anywhere in the estate
  • New unauthorized remote access tools (AnyDesk, TeamViewer, ngrok) — common persistence channels for RaaS affiliates
  • Unusual outbound transfer volume to cloud storage (MEGA, Rclone endpoints, unfamiliar S3 buckets) in the 72h window
  • Service creation events (7045) referencing PSEXESVC across multiple hosts in short succession
  • VPN/firewall management-plane logins from unusual geographies or ASNs

Critical Assets Historically Prioritized for Exfiltration

  • ERP/accounting exports and financial statements (leverage for payment pressure)
  • CAD/engineering drawings and production IP (manufacturing-specific targeting)
  • HR/payroll PII (regulatory pressure multiplier, especially under GDPR for ES/DE entities and LFPDPPP for MX)
  • Customer contracts and shipping manifests (transportation-specific leverage)

Containment Actions — Ordered by Urgency

  1. Isolate, don't power off affected segments — preserve memory for forensics; kill east-west pathways first.
  2. Disable compromised identities and force enterprise-wide credential resets, prioritizing domain admins and VPN accounts.
  3. Block known exfil destinations at the egress proxy; throttle or suspend bulk cloud-storage uploads.
  4. Snapshot hypervisor state if vCenter exposure is suspected — ransomware crews increasingly detonate at the ESXi layer.
  5. Engage IR retainer and legal counsel before any negotiation contact; do not communicate with the actor from corporate infrastructure.

Hardening Recommendations

Immediate (24 Hours)

  • Patch or mitigate CVE-2026-50751 (Check Point) and CVE-2026-59310 (vCenter) — both carry confirmed ransomware exploitation and map directly to this gang's access and detonation patterns.
  • Disable Office macros from the internet via Group Policy (Block macros from running in Office files from the Internet).
  • Restrict RDP to VPN-gated access only; enforce account lockout thresholds and audit LogonType 10 failures.
  • Alert on any execution of vssadmin delete shadows outside backup maintenance windows.
  • Verify offline/immutable backups are actually immutable — test a restore of one critical system.

Short-Term (2 Weeks)

  • Segment OT/production networks from corporate IT; manufacturing victims consistently suffer worst when flat networks let encryption reach the plant floor.
  • Deploy EDR in block mode on servers (not just endpoints) and enable tamper protection.
  • Implement egress filtering with deny-by-default for unsanctioned cloud storage and file-sharing services.
  • Enforce phishing-resistant MFA (FIDO2) on all remote access and privileged accounts.
  • Stand up deception: canary files on file shares and honey admin credentials to catch staging activity early.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.