Skip to content

CMD Organization

CMD Organization is a ransomware and data-extortion threat group that publicly claims intrusions against organizations and uses leak-site shaming to pressure victims.

Profile source: Mallory opens in a new tab

CMD Organization

Family profile

CMD Organization is a ransomware and data-extortion threat group that publicly claims intrusions against organizations and uses leak-site shaming to pressure victims. The group has been observed listing victims on extortion infrastructure and publishing sample stolen documents to support its claims. Reporting also associates it with an auction-style monetization model in which allegedly stolen datasets are offered to the highest bidder, indicating a financially motivated operation centered on double-extortion and possible data resale.

Observed victimology includes educational institutions, and the group has appeared in weekly ransomware claim tracking as an active but not top-tier actor, with multiple claimed victims across separate reporting periods in mid-2026. In one publicly reported university intrusion, the group claimed theft of a large volume of sensitive data, issued a cryptocurrency ransom demand, and threatened timed publication of additional material. That incident was also characterized by disruptive actions beyond exfiltration, including deletion of files from affected storage systems, consistent with coercive pressure designed to hinder recovery and increase leverage.

Tactics attributed to CMD Organization include unauthorized network access, data exfiltration, extortion via leak-site publication, deadline-based ransom demands, and destructive or disruptive post-compromise activity such as file deletion. The group’s operating model suggests overlap between ransomware and pure extortion tradecraft: public victim naming, proof-of-compromise releases, and sale or threatened release of stolen information. Available information supports classifying CMD Organization as a cybercriminal extortion actor. No high-confidence public attribution to a nation-state sponsor is currently available.

Operational record

1
YARA rules
2
Leak sites
1 available

Recent claims

MITRE ATT&CK

CMD Organization in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.