Skip to content

tengu

Inactive

25 tracked victims · First seen Oct 23, 2025 · Last seen Mar 7, 2026

About

Aggregated threat-intel description

Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.

Sectors: Technology, Manufacturing, Agriculture and Food Production · Countries: IN, MA, ID

Recent victims

View all →
VictimSectorCountryDataPostedStatus
Sileno Companies IncHospitality22.9TBMar 7, 2026
Communitymosaic.co.ukNot FoundUnited Kingdom—Mar 4, 2026listed
Eos Technology srlTechnologyIT20.78 GBMar 4, 2026
DAINTY CLOUD INCNot FoundUS—Mar 1, 2026
Al Arif Contracting Co. (L.L.C)ConstructionAEsize Data:70GBFeb 25, 2026
martec.itDefenseIT67.04 GBJan 1, 2026listed
www.shora.maAccountingMA23.5GBFeb 20, 2026
femar.itNot FoundIT145GBFeb 18, 2026listed
真言宗智山派 成就院Not FoundJP—Feb 18, 2026
Junta Local de Conciliación y ArbitrajePublic SectorMXsize Data:68GBFeb 10, 2026
PT. Mitra Antar TangguhNot FoundID—Feb 10, 2026
megasilver.com.twInformation TechnologyTW25.6GBFeb 4, 2026
all DataTechnology—Jan 31, 2026
We will be back soonNot Found—Jan 30, 2026
b2motorsport.co.ilNot FoundIL—Jan 29, 2026
Tahkout GroupManufacturingDZ—Jan 28, 2026
KSP TLM INDONESIANot FoundID—Jan 27, 2026
FRUIT-BONTÉ AgroalimentaireAgriculture and Food ProductionFR—Jan 27, 2026
lenotech.com.phNot FoundPH—Jan 27, 2026
COMPAGNIE FONCIÈRE PARISIENNEFinancial ServicesFR—Jan 27, 2026
skyegtours.comHospitality and TourismGB—Jan 27, 2026
Disuelas JC SASNot FoundCO—Jan 26, 2026
premmotors.comNot FoundIN—Jan 26, 2026
namico.go.kePublic SectorKE—Jan 26, 2026
Jakarta Nanyang SchoolEducationID—Jan 26, 2026

All ransomware groups · Dark web intelligence