Back to Intelligence

UMBRA Ransomware Gang: 5 New Leak-Site Listings Across Technology, Manufacturing & Education — Campaign Analysis & Detection Rules

SA
Security Arsenal Team
October 7, 2026
12 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-07 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

Executive Summary

Between 2026-10-06 and 2026-10-07, the UMBRA ransomware operation listed five organizations on its dark web leak site. All five postings were independently observed by two separate leak-site crawlers, confirming the gang published these claims — but no listing in this dataset constitutes a confirmed breach. Only the named organizations or their regulators can confirm an intrusion.

The organizations UMBRA claims to have compromised are:

  • SANAtech Global Solutions (Technology, country undisclosed) — listed 2026-10-07
  • Raqib (Technology, country undisclosed) — listed 2026-10-07
  • Tharisa (Manufacturing, ZA) — listed 2026-10-07
  • Beni Suef Technological University – BTU (Education, EG) — listed 2026-10-06
  • Four Hands LLC (Other, US) — listed 2026-10-06

Defenders in the technology, manufacturing, and education verticals — particularly organizations with South African, Egyptian, or US footprints — should treat this as a prompt to review internet-facing exposure, credential hygiene, and pre-encryption detection coverage. The detection content in this briefing is designed to catch UMBRA-consistent tradecraft before detonation.

Sourcing & Verification

  • 5 of 5 listings in this report were independently observed by a second leak-site crawler (multi-source). 0 listings rest on a single source. Multi-source observation confirms the threat actor made the claim; it does not confirm any intrusion occurred.
  • Inclusion in this briefing reflects the threat actor's claim only and is NOT confirmation of a breach, compromise, or active incident at any named organization.
  • A named organization may dispute a listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — UMBRA

Attribution caveat: UMBRA has a comparatively limited body of confirmed public reporting. The profile below reflects observed leak-site behavior and tradecraft consistent with the group's postings, supplemented by sector-pattern analysis. Items marked (assessed) are analytical judgments, not verified fact.

  • Aliases: No widely corroborated aliases at time of writing. Monitor for branding drift — newer operations frequently rebrand or absorb affiliates from disrupted crews.
  • Operating model: (Assessed) Ransomware-as-a-Service (RaaS) or semi-closed affiliate model. The victim mix (mid-market manufacturing, a university, SMB-adjacent technology firms) and batch posting cadence are characteristic of affiliate-driven operations purchasing access from initial access brokers (IABs) rather than a closed, bespoke intrusion team.
  • Extortion approach: Double extortion — data theft followed by encryption, with leak-site publication used as pressure. The current burst of listings (five in ~48 hours) is consistent with a countdown/deadline escalation tactic.
  • Typical ransom demands: (Assessed) Mid-five to low-seven figures USD, scaled to victim revenue — consistent with peer groups targeting this victim profile. Demands against education-sector victims are typically lower, reflecting limited payment capacity.
  • Initial access methods: (Assessed, hypothesis-level) The dominant vectors for groups with this victim profile are: (1) exploitation of internet-facing VPN/firewall appliances and virtualization management planes, (2) phishing with macro-enabled or script-based payloads, (3) exposed or brute-forced RDP, and (4) access purchased from IABs. The CISA KEV entries referenced below represent sector-level exposure consistent with this pattern.
  • Dwell time: (Assessed) Peer operations with this profile typically dwell days to a few weeks between access and detonation; the exfiltration and staging window is the highest-value detection opportunity.

Current Campaign Analysis

Sectors targeted (from listing data): Technology (2 listings: SANAtech Global Solutions, Raqib), Manufacturing (Tharisa), Education (Beni Suef Technological University – BTU), and Other (Four Hands LLC). The spread is opportunistic rather than vertically focused — a hallmark of IAB-fed affiliate operations that take whatever access is available.

Geographic concentration: Confirmed-country listings span ZA (Tharisa), EG (Beni Suef Technological University – BTU), and US (Four Hands LLC); two listings (SANAtech Global Solutions, Raqib) have no disclosed country. The African footprint (South Africa, Egypt) in 2 of 3 country-tagged listings is notable and warrants attention from organizations operating in those regions, where perimeter patching and MFA adoption frequently lag.

Victim profile: The named organizations range from a public university to mid-market manufacturing and technology services firms — a classic mid-market band. Based on sector norms, estimated annual revenues plausibly span from single-digit millions (education, SMB tech) to hundreds of millions USD (established manufacturing). Mid-market victims are favored because they carry cyber insurance, hold monetizable data, and often lack 24/7 SOC coverage.

Posting frequency / escalation: Five listings in approximately 48 hours indicates a batch publication event. This pattern typically means one of two things: (a) a deadline-expiry dump for victims who declined negotiation, or (b) an access-broker inventory clearance feeding multiple near-simultaneous affiliate intrusions. Either way, additional listings in the coming days are plausible.

CVE exposure (hypothesis — NOT attributed to any named victim): We have no evidence linking any specific CVE to any organization listed above. However, the following actively exploited vulnerabilities (CISA KEV, confirmed ransomware use) map directly onto the exposure surface typical of these sectors and this gang's assessed access methods. Treat them as prioritized hypotheses for initial access in your environment:

  • CVE-2026-59310 — Broadcom VMware vCenter path traversal (KEV 2026-08-18): virtualization management planes are high-value ransomware targets; compromise enables mass encryption of VM estates.
  • CVE-2026-63077 — JetBrains TeamCity deserialization (KEV 2026-08-05): CI/CD servers yield source code, secrets, and signing keys — attractive for technology-sector victims and supply-chain pivoting.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password (KEV 2026-07-29): network management plane takeover.
  • CVE-2026-50751 — Check Point Security Gateway improper authentication in IKEv1 (KEV 2026-06-08): VPN edge compromise, the single most common ransomware initial access vector class.
  • CVE-2026-48027 — Nx Console embedded malicious code (KEV 2026-05-27): developer-workstation supply chain exposure relevant to technology firms.

Detection Engineering

The following detections target pre-encryption tradecraft: exploitation follow-on behavior on management servers, lateral movement via remote service execution, and anti-recovery actions (shadow copy deletion) that reliably precede detonation.

YAML
---
title: Volume Shadow Copy Deletion via Vssadmin or WMIC
id: 8f3c2a10-7b21-4e9f-9c41-umbravss01
status: experimental
description: Detects deletion or resizing of Volume Shadow Copies — a near-universal pre-encryption anti-recovery action in ransomware operations including UMBRA-consistent campaigns.
author: Security Arsenal Threat Intelligence
date: 2026/10/07
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
 detection_placeholder: none
detection:
  selection_img:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\wbadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'resize shadowstorage'
      - 'shadowcopy delete'
      - 'recoveryenabled no'
      - 'delete catalog'
  condition: selection_img
falsepositives:
  - Legitimate backup maintenance (rare; validate against change windows)
level: high
tags:
  - attack.impact
  - attack.t1490
---
title: Remote Service Creation Consistent with PsExec-Style Lateral Movement
id: 8f3c2a10-7b21-4e9f-9c41-umbrapsex01
status: experimental
description: Detects creation of remote execution services (PsExec, PAExec, remcom, and renamed clones) used by ransomware affiliates for lateral movement and payload distribution.
author: Security Arsenal Threat Intelligence
date: 2026/10/07
logsource:
  product: windows
  service: system
  definition: Windows Event ID 7045 (Service Installed)
detection:
  selection_service:
    EventID: 7045
    ServiceName|contains:
      - 'PSEXESVC'
      - 'PAExec'
      - 'RemComSvc'
      - 'csexecsvc'
  selection_path:
    EventID: 7045
    ImagePath|contains:
      - '\ADMIN$\'
      - '\IPC$\'
      - '%TEMP%'
      - '\AppData\Local\Temp\'
  condition: 1 of selection_*
falsepositives:
  - Legitimate administration tooling; baseline approved remote-mgmt service names and alert on deviations
level: high
tags:
  - attack.lateral-movement
  - attack.t1569.002
  - attack.t1021.002
---
title: Suspicious Child Process Spawned by Virtualization, CI/CD, or Firewall Management Services
id: 8f3c2a10-7b21-4e9f-9c41-umbraedge01
status: experimental
description: Detects shells or scripting engines spawned by vCenter, TeamCity, Cisco FMC, or Check Point services — post-exploitation behavior consistent with KEV exploitation (CVE-2026-59310, CVE-2026-63077) used as ransomware initial access.
author: Security Arsenal Threat Intelligence
date: 2026/10/07
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\vpxd.exe'
      - '\teamcity-server.exe'
      - '\java.exe'
      - '\tomcat9.exe'
  selection_parent_path:
    ParentImage|contains:
      - '\VMware\'
      - '\TeamCity\'
      - '\Cisco\'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\mshta.exe'
      - '\certutil.exe'
  condition: (selection_parent or selection_parent_path) and selection_child
falsepositives:
  - Rare; management services spawning interactive shells is almost never legitimate outside maintenance windows
level: critical
tags:
  - attack.initial-access
  - attack.t1190
  - attack.t1059

The following Microsoft Sentinel KQL query hunts the pre-detonation staging chain: shadow copy tampering, archive-based data staging, mass share enumeration, and new service installation correlated on the same host within a 24-hour window.

KQL — Microsoft Sentinel / Defender
// UMBRA-consistent pre-ransomware staging hunt — correlate anti-recovery + staging + lateral movement per host
let window = 24h;
let AntiRecovery =
    DeviceProcessEvents
    | where TimeGenerated > ago(window)
    | where ProcessCommandLine has_any ("delete shadows", "resize shadowstorage", "shadowcopy delete", "recoveryenabled no", "delete catalog")
    | project TimeGenerated, DeviceName, AccountName, AntiRecoveryCmd = ProcessCommandLine;
let DataStaging =
    DeviceProcessEvents
    | where TimeGenerated > ago(window)
    | where FileName in~ ("rar.exe", "7z.exe", "7za.exe", "winrar.exe", "tar.exe")
       or ProcessCommandLine has_any (" -a ", " a -p", "invg", ".rar", ".7z")
    | project TimeGenerated, DeviceName, AccountName, StagingCmd = ProcessCommandLine;
let NewRemoteService =
    SecurityEvent
    | where TimeGenerated > ago(window)
    | where EventID == 7045
    | where ServiceName has_any ("PSEXESVC", "PAExec", "RemCom") or ServiceFileName has_any ("ADMIN$", "Temp")
    | project TimeGenerated, DeviceName = Computer, AccountName, ServiceName, ServiceFileName;
let NetEnum =
    DeviceProcessEvents
    | where TimeGenerated > ago(window)
    | where ProcessCommandLine has_any ("net view", "net share", "net group \"domain admins\"", "nltest /dclist")
    | project TimeGenerated, DeviceName, AccountName, EnumCmd = ProcessCommandLine;
AntiRecovery
| join kind=inner (DataStaging) on DeviceName, AccountName
| join kind=leftouter (NewRemoteService) on DeviceName
| join kind=leftouter (NetEnum) on DeviceName
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
            AntiRecoveryCmds = make_set(AntiRecoveryCmd), StagingCmds = make_set(StagingCmd),
            RemoteServices = make_set(ServiceName), EnumCmds = make_set(EnumCmd)
    by DeviceName, AccountName
| extend RiskScore = 100
| sort by FirstSeen desc;
PowerShell
# Rapid-response triage: scheduled tasks added in last 7 days, exposed RDP, shadow copy status
# Run elevated. Output is CSV-friendly for IR timelines.
$cutoff = (Get-Date).AddDays(-7)
$report = @()

Write-Host "=== [1] Scheduled tasks created/modified in last 7 days ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
    $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
    $reg = Get-Item "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\$($_.TaskPath.Trim('\'))$($_.TaskName)" -ErrorAction SilentlyContinue
}
# More reliable: pull from Task Scheduler operational log
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-TaskScheduler/Operational'; Id=106,140,200; StartTime=$cutoff} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, Id, Message |
    Sort-Object TimeCreated -Descending | Format-Table -AutoSize

Write-Host "=== [2] RDP exposure check ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -ErrorAction SilentlyContinue).UserAuthentication
Write-Host "RDP Enabled: $rdpEnabled | NLA: $nla"
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Select-Object LocalAddress, LocalPort, State

Write-Host "=== [3] Failed logons (4625) — brute force indicators, last 7 days ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=$cutoff} -ErrorAction SilentlyContinue |
    Group-Object { $_.Properties[19].Value } | Sort-Object Count -Descending | Select-Object -First 15 Count, Name

Write-Host "=== [4] Volume Shadow Copies ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) { Write-Host "WARNING: No shadow copies present — verify this is expected, not anti-recovery tampering." -ForegroundColor Red }
else { $shadows | Select-Object InstallDate, DeviceObject, VolumeName }

Write-Host "=== [5] Recent 7045 service installs ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=$cutoff} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, Message | Format-List

Incident Response Priorities

T-minus detection checklist (pre-encryption indicators):

  1. Shadow copy deletion or bcdedit recoveryenabled no execution — treat as imminent detonation.
  2. New service installations (Event ID 7045) with binaries in ADMIN$, TEMP, or AppData paths.
  3. Archive utility execution (rar/7z) against file servers, ERP shares, or document repositories — the exfil window.
  4. Anomalous egress to cloud storage or unknown endpoints in the 2–6 GB+/hour range from a single host.
  5. New local/domain admin account creation outside change control; unexpected net group "domain admins" enumeration.
  6. Shells spawned by vCenter, TeamCity, or firewall management services (see Sigma rule 3).
  7. GPO modifications or mass logon script changes — a common payload distribution mechanism.

Critical assets this profile of operation historically prioritizes for exfiltration: file servers and NAS shares; finance/HR documents (for payment pressure); manufacturing IP, CAD, and process documentation; student and research records in education environments; source code, secrets, and CI/CD artifacts in technology firms; backup catalogs and credentials.

Containment actions, ordered by urgency:

  1. Isolate affected hosts from the network (EDR isolate / switch port shutdown) — do NOT power off; preserve memory.
  2. Disable compromised accounts and force credential resets for any account observed in lateral movement paths; reset KRBTGT twice if domain-wide compromise is suspected.
  3. Block egress to identified C2/exfil destinations at the proxy and firewall; sinkhole where possible.
  4. Take backup infrastructure offline from production trust paths and verify immutability/offline copies before any restore decision.
  5. Disable RDP and VPN access from untrusted sources pending scope assessment.
  6. Engage IR retainer and legal counsel before any communication with the threat actor; preserve volatile evidence (memory, EDR telemetry, VPN/auth logs) first.

Hardening Recommendations

Immediate (24 hours):

  • Patch or mitigate the five KEV CVEs listed above — vCenter, TeamCity, Cisco FMC, Check Point IKEv1, and audit Nx Console versions. These are confirmed ransomware-exploited and map directly to this campaign's assessed access surface.
  • Enforce phishing-resistant MFA on all VPN, RDP-gateway, and remote access portals; block legacy IKEv1 aggressive mode where not required.
  • Restrict vssadmin, bcdedit, wbadmin, and wmic execution to a named admin group via AppLocker/WDAC.
  • Disable or tightly control PsExec and equivalent remote service tooling; alert on any 7045 outside approved software deployment.
  • Verify backups are immutable/offline and test one restore.

Short-term (2 weeks):

  • Segment virtualization management (vCenter), CI/CD, and backup infrastructure into isolated management VLANs with jump-host-only access.
  • Deploy the Sigma and KQL detections above; validate them with a controlled purple-team emulation of the staging chain.
  • Implement egress filtering with TLS inspection on server VLANs; alert on bulk transfers to unsanctioned storage providers.
  • Establish attack surface monitoring for exposed RDP/VPN/management interfaces, including third-party and regional subsidiaries (ZA/EG footprints deserve specific review given this campaign's geography).
  • Enroll in a leak-site monitoring program so claims naming your organization trigger immediate internal verification workflows.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.