MS13-089 is a ransomware and data-extortion threat actor that emerged publicly in 2025–2026. The group has claimed responsibility for intrusions including a breach of Virginia Urology in the United States and a ransomware incident affecting a maritime-sector organization in Chile. In the Virginia Urology case, the actor claimed large-scale theft of protected health information and stated that it did not encrypt systems, indicating the use of encryption-less extortion in at least some operations. The group operates a leak site and has used public disclosure of stolen data to pressure victims. MS13-089 has presented itself as being composed of former members of Conti, Royal, and LockBit, although that claim is self-attributed and not independently confirmed. Available reporting supports characterization of the actor as a financially motivated cybercriminal group engaged in data theft, extortion, and post-compromise exploitation against healthcare and other organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against servmarmg.cl.
MS13-089 is a newly emerged threat actor group targeting healthcare organizations, exfiltrating large volumes of sensitive data without encrypting systems.
MS13-089 is a cybercriminal group claiming to be composed of high-level specialists from Conti, Royal, and LockBit. They exfiltrated 927 GB of sensitive data from Virginia Urology, including protected health information, but stated they did not encrypt the data to avoid harming patients. They operate a dark web leak site and use data exfiltration and extortion tactics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.