APT73 is a ransomware and data-extortion threat actor tracked through public leak-site victim listings beginning in 2024 and continuing into 2026. The group is associated with naming and shaming victims on a leak site and publicly claiming compromises across multiple countries and sectors. Reported victims span technology, transportation and logistics, manufacturing, consumer-facing businesses, real estate-related platforms, and public-sector entities. Observed activity indicates a financially motivated cybercriminal operation rather than a nation-state espionage actor. APT73 has been linked to ransomware incidents in which victim organizations were listed on a leak site, often accompanied by screenshots of purported internal documents and, in some cases, references to downloadable stolen data. This supports the assessment that the group uses data theft for extortion and operates a leak-site-based pressure model. Some victim entries explicitly describe ransomware attacks, while others emphasize breach and exposure claims without technical detail on encryption or intrusion tradecraft. Known aliases include apt73 and group_apt73. Available reporting does not provide high-confidence attribution to a specific country of origin, nor does it establish distinct sub-groups. Publicly observed behavior supports capabilities in initial access, exfiltration, and extortion-oriented post-exploitation, but detailed evidence for specific malware families, persistence mechanisms, privilege escalation methods, or lateral movement techniques is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against metrabyte.cloud, a cloud service provider.
Conducting a ransomware attack resulting in a data breach against dgcement.com / D.G. Khan Cement Company Limited.
Conducting a ransomware attack against azarestan.com (Azarestan Business Development Group) in Iran.
Conducting a ransomware attack against vicentetrapani.com / Vicente Trapani S.A.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.