Eclipse is a ransomware threat group associated with reported attacks against organizations in the United States, France, India, and Singapore. Reported victims span education, food distribution, hospitality and travel media, legal services, technology, industrial manufacturing, and maritime commerce. Named targets include a U.S. charter-school system, a French produce wholesaler, Singaporean hospitality and maritime-marketplace organizations, an Indian engineering manufacturer, and technology-sector firms. Publicly available reporting does not establish Eclipse’s geographic origin, malware tooling, initial-access methods, encryption activity, data theft, extortion practices, victim-impact details, or operational structure. Eclipse is the only known alias in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Dublin City Schools GA, a U.S. education-sector charter school system.
Conducted a ransomware attack against Rosello et Fils, a French fruit and vegetable wholesaler.
Conducted a ransomware attack against TTG Asia Media, a Singapore-based travel-trade media organization in the hospitality sector.
Conducted a ransomware attack against The Zhou Law Group, a California-based family-law firm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.