PEAR, also known as Pure Extraction and Ransom and pear_ransomware_group, is a financially motivated ransomware and cyber-extortion group publicly observed from mid-2025. The group primarily conducts data-theft extortion: it claims to copy victim data and threatens public release unless a ransom is paid. PEAR operates a data leak site and has claimed attacks against organizations in the United States and Jamaica, with a concentration of reported victims in the healthcare sector. Claimed targets also include technology service providers, chemical manufacturing, energy-industry service providers, legal services, retail businesses, and hospitality organizations. PEAR claimed responsibility for the compromise of Medical Computer Business Services, a healthcare revenue-cycle-management provider that disclosed unauthorized network access and exposure of personal and health information; the group alleged it exfiltrated a large volume of confidential data. Other asserted victim and data-volume claims have not always been independently verified. Publicly available reporting does not establish PEAR's geographic origin, initial-access methods, malware implementation, or whether encryption is routinely used in its operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Indroj Medical Group Inc., a U.S.-based healthcare organization operating npiprofile.com.
Conducted a ransomware attack against Martin Lawrence Galleries, a U.S. fine-art gallery.
Conducted a ransomware attack against Westside GI, an ambulatory endoscopy center in the United States.
Reportedly conducted a ransomware attack against Foss Inc., an installation and maintenance services provider to the energy industry.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.