Barracuda is a financially motivated ransomware and data-extortion operation that has claimed attacks against organizations in the United States, South Korea, Brazil, China, and Turkey. Its known victimology includes healthcare providers, manufacturers, industrial-automation and water-sector technology suppliers, and technology organizations. Barracuda has claimed to exfiltrate large volumes of victim data, including patient records, employee and client information, technical documentation, source code, databases, emails, and industrial-system materials. The operation uses public leak and sale listings to pressure victims, offering stolen datasets for sale or threatening publication when victims do not engage. Barracuda describes itself as independent of government sponsorship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed ransomware and data-extortion attack against Turkish technology company i2i-systems. Barracuda claims it moved freely through the network for approximately a week, exfiltrated 693 GB of data—including 44 GB of source code, Linux-system backups, database snapshots, and alleged Turk Telekom customer data—and intends to sell or publish the data.
Claimed responsibility for an opportunistic ransomware/data-theft attack against Micro-Comm, releasing nearly 850,000 purported company files (about 644 GB) on August 6.
Conducting a ransomware/data extortion attack against a healthcare organization and claiming theft and sale of sensitive data including medical records, personal information, and email dumps.
Conducting a ransomware/data extortion operation involving the sale of a fresh full database dump allegedly stolen from Namyang Industrial Co., Ltd. (renamed to Namyang Nexmo).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.