auroraRansomware Victim๐Ÿ‡บ๐Ÿ‡ธ US OrganizationTransportation

Metrea LLC/Commuter Air Technology, Inc.

[defence] Metrea LLC (formerly Meta Special Aerospace, LLC) and its subsidiary Commuter Air Technology, Inc. (CAT) are US defense contractors providing Contractor Owned, Contractor Operated (COCO) ISR aircraft services to US Special Operations Command. They operate modified King Air 350 surveillance aircraft in Niger, East Africa, the Philippines, and other theaters. <redacted> 339 MB of Harris PRC-117G military tactical radio firmware including compiled waveform binaries for SINCGARS, HAVEQUICK II, ROVER, and 10 other ITAR-controlled waveforms (USML Category XI). Named deployment data for 14+ operators at Sable Spear sites in Niger and East Africa, with rotation schedules, SIPRNet access documentation, and divert airfield planning. Complete SOCOM contract pricing portfolios โ€” labor rates, burn rates, TINA-certified cost data, and subcontractor pricing for SOCPAC C3PO, Sable Spear, and Sable Dagger programs. 232 employee personnel files including resumes, W-9 forms (SSN), SERE training certificates, security clearances, expense reports, and deployment records. NSWDG (SEAL Team Six), MARSOC, and 75th Rangers training exercise documentation โ€” 37 separately funded SOCOM training deliveries under the Alpha 28 program. <redacted>

Incident Details

Threat Group
aurora
Victim / Organization
Metrea LLC/Commuter Air Technology, Inc.
Website / Domain
Metrea LLC/Commuter Air Technology, Inc.
Industry Sector
Transportation
Country / Region
๐Ÿ‡บ๐Ÿ‡ธ US
Date Discovered
Saturday, September 5, 2026

What This Listing Means

Posting on aurora's ransomware leak site typically signals that the threat actor claims to have:

  • โ–ธGained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
  • โ–ธExfiltrated sensitive data โ€” potentially including financial records, PII, customer data, or trade secrets
  • โ–ธDeployed ransomware to encrypt systems and disrupt operations
  • โ–ธIssued a ransom demand with a deadline to publish all stolen data publicly if unpaid

๐Ÿ‡บ๐Ÿ‡ธ US-based organizations hit by ransomware may have mandatory breach notification obligations under state laws, HIPAA (healthcare), SEC regulations (public companies), or CISA guidelines. The notification window is typically 72 hours from discovery.

Is This Your Organization?

Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.

Get Emergency ResponseIR Services Overview

Protect Your Organization

โ† Back to Ransomware Tracker