Metrea LLC/Commuter Air Technology, Inc.
[defence] Metrea LLC (formerly Meta Special Aerospace, LLC) and its subsidiary Commuter Air Technology, Inc. (CAT) are US defense contractors providing Contractor Owned, Contractor Operated (COCO) ISR aircraft services to US Special Operations Command. They operate modified King Air 350 surveillance aircraft in Niger, East Africa, the Philippines, and other theaters. <redacted> 339 MB of Harris PRC-117G military tactical radio firmware including compiled waveform binaries for SINCGARS, HAVEQUICK II, ROVER, and 10 other ITAR-controlled waveforms (USML Category XI). Named deployment data for 14+ operators at Sable Spear sites in Niger and East Africa, with rotation schedules, SIPRNet access documentation, and divert airfield planning. Complete SOCOM contract pricing portfolios โ labor rates, burn rates, TINA-certified cost data, and subcontractor pricing for SOCPAC C3PO, Sable Spear, and Sable Dagger programs. 232 employee personnel files including resumes, W-9 forms (SSN), SERE training certificates, security clearances, expense reports, and deployment records. NSWDG (SEAL Team Six), MARSOC, and 75th Rangers training exercise documentation โ 37 separately funded SOCOM training deliveries under the Alpha 28 program. <redacted>
Incident Details
- Threat Group
- aurora
- Victim / Organization
- Metrea LLC/Commuter Air Technology, Inc.
- Website / Domain
- Metrea LLC/Commuter Air Technology, Inc.
- Industry Sector
- Transportation
- Country / Region
- ๐บ๐ธ US
- Date Discovered
- Saturday, September 5, 2026
What This Listing Means
Posting on aurora's ransomware leak site typically signals that the threat actor claims to have:
- โธGained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
- โธExfiltrated sensitive data โ potentially including financial records, PII, customer data, or trade secrets
- โธDeployed ransomware to encrypt systems and disrupt operations
- โธIssued a ransom demand with a deadline to publish all stolen data publicly if unpaid
๐บ๐ธ US-based organizations hit by ransomware may have mandatory breach notification obligations under state laws, HIPAA (healthcare), SEC regulations (public companies), or CISA guidelines. The notification window is typically 72 hours from discovery.
Open Source Investigation
Is This Your Organization?
Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.
Get Emergency ResponseIR Services OverviewProtect Your Organization
- AlertMonitor
Dark web & ransomware monitoring for your domains
- Managed SOC & MDR
24/7 threat detection and response
- Penetration Testing
Find ransomware entry points before attackers do