Skip to content

arcusmedia

Arcus Media is a ransomware threat actor and ransomware-as-a-service operation that emerged in May 2024.

Profile source: Mallory opens in a new tab

arcusmedia

Family profile

Arcus Media is a ransomware threat actor and ransomware-as-a-service operation that emerged in May 2024. It has been described as technically advanced and has shown sustained activity against organizations across multiple regions, including Europe, Africa, North America, and Asia. Known aliases include arcusmedia and arcus_media.

Arcus Media has been associated with double-extortion ransomware activity in which victim data is stolen and victims are pressured with publication deadlines in addition to encryption-related disruption. Reported victimology indicates broad sector coverage, including technology, transportation and logistics, consumer services, tourism, public-sector entities, and organizations tied to industrial and critical infrastructure environments. The group has been noted as focusing on industrial and critical infrastructure targets, aligning it with the broader trend of ransomware actors pursuing organizations where operational disruption increases leverage.

Observed tradecraft attributed to Arcus Media includes consolidation of tooling and harvesting of browser-stored credentials. In broader ransomware reporting, the group has been listed alongside other active operators using increasingly mature intrusion workflows and extortion mechanisms. Arcus Media has also appeared in weekly ransomware claim tracking as an active actor with multiple publicly claimed victims in a single reporting period, indicating an operational tempo consistent with an established extortion program.

There is currently no high-confidence public attribution linking Arcus Media to a specific nation-state. It is best characterized as a financially motivated cybercriminal ransomware actor.

Operational record

1
YARA rules
1
Leak sites
0 available

Recent claims

MITRE ATT&CK

arcusmedia in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.