Arcus Media is a ransomware group that emerged in May 2024 and is described as a technically advanced ransomware-as-a-service operation. It has been associated with victim claims across multiple countries and sectors, including technology, professional services, transportation and logistics, tourism, public-sector organizations, and industrial or critical infrastructure environments. Reported activity indicates a broad, opportunistic targeting pattern rather than a narrow vertical focus, although the group has also been noted as focusing on industrial and critical infrastructure targets. Arcus Media operates as an extortion-oriented ransomware actor and has publicly claimed multiple victims. Reported incidents include both ransomware deployment and associated data-breach claims, with victim postings accompanied by deadlines consistent with double-extortion workflows. The group has been linked to credential harvesting, including collection of browser-stored credentials, and is assessed as part of the broader trend of modern ransomware crews consolidating tooling for intrusion, theft, and monetization. Aliases include arcusmedia and arcus_media. Available information supports classification as a financially motivated cybercriminal actor. No high-confidence attribution to a nation state or a specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against ManagementPro.
Conducting a ransomware attack against Mark’Techno.
Conducting a ransomware attack resulting in a data breach against Perpustam in Malaysia.
Conducting a ransomware attack resulting in a data breach against gemese.pt.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.