A newly observed ransomware group called Majinahanashi has launched a double-extortion campaign against organizations primarily in non-English-speaking countries, claiming about 15 victims and concentrating on the e-commerce and manufacturing sectors. The operators run a Tor-based leak site and archive servers, publish victim previews and countdown timers, and use contact channels including ProtonMail and qTox while reportedly demanding at least $15,000 in ransom. Reporting indicates the operation may involve at least two members and uses the slogan "DECISION REQUIRES CLARITY."
The malware is a Windows ransomware family written in C/C++ that appends the .MAJIN extension and encrypts files with AES-256 using RSA-wrapped per-file keys. Analysis shows it can establish persistence through a Windows service, delete recovery artifacts, disable security tooling, and evade or hinder defenses through features such as lock-screen display, wallpaper hijacking, and network-control functions tied to the Windows Filtering Platform. Researchers also linked the activity to tools including Mimikatz and Advanced IP Scanner, underscoring a capable but still mid-tier ransomware operation with active leak-site maintenance.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The Raven File published an initial threat-intelligence profile of Majinahanashi, describing it as a newly observed ransomware group with a Tor-based leak site, double-extortion tactics, and about 15 listed victims concentrated in non-English-speaking countries. The report also documented technical details of the malware, infrastructure, and operator communications.
Two observed Majinahanashi ransomware samples were described as roughly 90 KB Windows C/C++ binaries with creation dates set to 2 July 2026. The samples used AES-256 with RSA-wrapped per-file keys and appended the .MAJIN extension.
Reporting states the group's leak site was updated regularly between July 6 and August 11, 2026, instead of posting all victims at once. The site used countdown timers and proof-of-hack previews as part of a double-extortion workflow.
The first known victim leak attributed to the Majinahanashi ransomware operation appeared on its leak site, marking the group's earliest explicitly dated public activity. Later reporting said the group ultimately listed about 15 victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.