Sarcoma is a ransomware and extortion threat actor first observed in October 2024. It is commonly referred to as Sarcoma, Sarcoma Group, or Sarcoma Ransomware, and has been described as operating a ransomware-as-a-service model with affiliates. The group rapidly became active across multiple regions and has been associated with aggressive double-extortion operations, combining data theft with encryption and public leak-site pressure. Some reporting also describes Sarcoma activity that emphasizes data-theft extortion without encryption in certain cases, indicating operational flexibility. Sarcoma has targeted organizations worldwide, including high-value and supply-chain-relevant victims. Publicly reported victims include organizations in Switzerland and Taiwan, and reporting identifies the United States, Italy, Canada, Australia, the United Kingdom, Brazil, and Spain among prominent target countries. Targeting has affected multiple sectors, with especially strong evidence of attacks against manufacturing and healthcare-related organizations, as well as government-linked entities through third-party service providers. Operationally, Sarcoma has been linked to phishing, exploitation of older vulnerabilities, and supply-chain intrusion paths for initial access. Post-compromise behavior includes reconnaissance, lateral movement, remote execution, data exfiltration, and encryption. Technical reporting on Sarcoma malware shows Windows and Linux variants with cross-platform encryption capability. The Windows variant has been observed performing passive network discovery, host reachability testing, remote payload copying over SMB and native Windows mechanisms, authentication to remote systems, and scheduled-task-based remote execution. It also disables database-related services and processes before encryption. The Linux variant has been observed removing VMware snapshots to hinder recovery in virtualized environments. Sarcoma uses hybrid cryptography, with ChaCha20 for file encryption and RSA to protect symmetric keys. Anti-analysis and regional evasion behavior has also been reported, including self-termination under specific locale conditions. Additional reporting links Sarcoma to the abuse of legitimate remote management and monitoring tools for stealthy reconnaissance and lateral movement. The group is associated with leak-site operations and public extortion pressure, and has been characterized as specializing in double extortion and supply-chain attacks. Its victimology, tooling, and tradecraft indicate a financially motivated cybercriminal operation rather than a state-directed espionage actor. Claims about a specific national origin are not sufficiently supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sarcoma is a financially motivated ransomware group known for double-extortion attacks, combining data theft with system encryption. They target mid-market and larger organizations, especially in manufacturing, technology, and construction, primarily in Western countries. Sarcoma operates a Ransomware-as-a-Service (RaaS) model with a small set of trusted partners, uses advanced evasion and anti-forensics techniques, and frequently updates its malware to target Windows, Linux, and ESXi environments. They leverage phishing, credential theft, exploitation of unpatched services, and third-party access for initial entry, followed by lateral movement, data exfiltration, and rapid encryption. Their extortion model relies on public data leaks and negotiation portals.
Named ransomware group referenced in victim-claim rankings based on data-leak site postings.
Named ransomware group referenced in victim-claim rankings based on data-leak site postings.
Ransomware group targeting government and manufacturing victims, with Windows and Linux variants supporting network spread and ESXi snapshot deletion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.