Extortion crew hits Russian firms and flags who paid

Published

The newest name on Audit Team's leak site is TEK SPB, a St Petersburg engineering firm that builds and services the heating substations keeping Russian apartment blocks warm. It went up on 20 September. For eight days before that, the same row read only "TE***PB".

Russian companies almost never turn up on ransomware leak sites. This crew lists them more than it lists any other country.

One crew out of eighty-three

IntelFusions holds 7,576 attributed leak-site claims from the past twelve months. Russia accounts for 0.3 percent of them and ranks 43rd among target countries. Of the 83 crews that posted ten or more claims in that window, exactly one has Russia as its most-listed country, and it is this one.

The group is small. Our records carry 24 named listings across 13 countries since it surfaced on 8 April 2026, and ten of those are Russian organizations: an agricultural enterprise in Kursk Oblast, a steel products manufacturer, a software house, an online pallet shop, now the St Petersburg heating company. It is not a one-sided political operation either. On 16 September it listed Wise IT, a Kyiv-based system integrator. Senegal's public treasury and Kawasaki Motors Philippines sit on the same site.

September is when it woke up

Thirteen of the 24 listings arrived in September alone, more than the previous five months put together. The public tracker ransomware.live puts the group's attack velocity up 317 percent against the previous month and records two live Tor locations, a ransom note template and a YARA rule. It fits a market where more crews keep arriving with fewer victims each.

A countdown that runs about a week

Every victim reaches the site twice. It appears first as a stub, the first two and last two characters of its name with asterisks in between, and is named in full roughly a week later. TE***PB became TEK SPB in eight days. Wi***IT became Wise IT in eight. The stubs pa***op, bu***en and dg***kr took seven or eight. Across the whole site the gap runs from seven to eleven days, and the tracker's own average of 9.6 days sits inside that range.

Six stubs from the last twelve days are still masked, one of them ending in .ru. If the pattern holds, those names are due this week.

Eight rows that never get a name

Eight of the 24 listings never resolve to a company at all. They read "Paid Victim" followed by a 16 character hexadecimal string, and four of the eight are tagged to Russia. Audit Team is the only group in our entire incident corpus that does this. The row is not deleted when a case closes, it is relabeled, and the effect, designed or not, is a standing advertisement that paying makes the name go away.

If a stub looks like you, you have about a week

There is nothing to patch here, and none of this is confirmed. A leak-site entry is an accusation written by the party that profits from it, and no organization named above has acknowledged a breach. The stub stage is still worth something: an organization that can recognize itself in a four character fragment has roughly seven to eleven days before its full name is published. Spend them pulling remote access and authentication logs for the attack window the tracker prints against each entry, and agreeing what you will say before somebody else says it for you.

Russia's near absence from leak sites is usually read as evidence about where the crews live rather than about how well Russian companies are defended. A group that lists Russian firms week after week, and a Ukrainian one in the same fortnight, fits neither side of that assumption. IntelFusions tracks it as Audit Team, and the wider picture sits on our Russia country profile.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions