Majinahanashi is a financially motivated ransomware operation first publicly observed in June 2026. The group uses Japanese-themed branding but has no verified geographic attribution. It operates a Tor-based leak site that publishes victim previews and timed leak announcements, consistent with double-extortion operations involving both file encryption and threatened publication of exfiltrated data. The operator has used the pseudonym THE DOCTOR CAME. Majinahanashi has claimed victims across primarily non-English-speaking countries, including organizations in Europe, South and Southeast Asia, and Latin America. Reported targeting has included e-commerce, manufacturing, technology, agriculture, and hospitality organizations. Public victim claims and leak-site listings should be treated as unverified unless independently confirmed. The Windows ransomware is implemented in C/C++ and encrypts files using AES-256 with unique per-file keys protected by an embedded RSA public key. It can execute as a Windows service, establish service-based persistence, modify the desktop to display a lock screen or ransom-related wallpaper, and conduct pre-encryption checks. Observed recovery-inhibition behavior includes deletion of shadow copies, disabling System Restore and recovery options, clearing event logs, and deletion of the USN journal. The malware also terminates security and backup tooling and stops services. The operation employs multiple defense-evasion measures, including direct system calls, PEB access, dynamic API resolution, string obfuscation, delayed execution, and geographic or language checks. It includes Windows Filtering Platform and QoS-related functionality that can control network traffic. Reported operator tooling includes credential-access and network-scanning utilities. Majinahanashi maintains leak infrastructure and negotiates ransoms through privacy-oriented communications channels.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reported ransomware and data-extortion activity against TERRACOM & MONTCAU, involving a claimed leak of 6,341 files.
Claimed ransomware/data-leak incident against MONTCAU, with a scheduled publication alleging a leak of 6,341 files.
Named as the threat group responsible for a ransomware attack and leak against PCA Group Sdn. Bhd., with the incident summary stating 'PUBLICATION SCHEDULED. [LEAK / 1844 FILES]'.
Mentioned only as prior-week comparison and absent from this week's top 10.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.