IMN Crew is a ransomware threat group identified as an emerging operation in 2025. It is described as a rising ransomware actor that began its campaign relatively recently and operates a leak site used to name victims, indicating public shaming and extortion activity. Reporting places IMN Crew among newer entrants in a volatile post-LockBit and post-ALPHV/BlackCat ransomware ecosystem in which affiliates and operators frequently shift between platforms and reuse common tooling and tradecraft. High-confidence public reporting supports IMN Crew’s role as a ransomware actor, but does not provide corroborated detail on its malware family, intrusion chain, victimology, geographic origin, or specific tooling beyond its classification as a rising ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly launched ransomware/extortion operation with an active leak site and initial victim set.
Rising ransomware threat group newly active in campaigns (no specific tooling/CVEs detailed in this content).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.