Skip to content

DataCarry

DataCarry is a ransomware-associated extortion operation that emerged in 2025 and has been observed targeting organizations across multiple countries and sectors.

Profile source: Mallory opens in a new tab

DataCarry

Family profile

DataCarry is a ransomware-associated extortion operation that emerged in 2025 and has been observed targeting organizations across multiple countries and sectors. Reported victimology includes aviation, education, finance, insurance, and healthcare, with additional reporting placing it among ransomware variants frequently observed against European financial institutions. The operation has also been described as part of a broader wave of short-lived, rapidly branded ransomware groups that emphasize operational speed, shared criminal infrastructure, and leak-site driven coercion.

Available reporting indicates that DataCarry has, in some cases, relied on data theft and leak-based extortion without deploying a traditional file-encrypting locker. This places it within the broader 2025 trend of exfiltration-first or extortion-only ransomware activity, where public exposure of stolen data is used as the primary pressure mechanism. High-confidence attribution of a distinct custom malware payload, encryption routine, or unique technical tradecraft beyond extortion activity is currently not available.

DataCarry has been linked to abuse-resistant hosting infrastructure, including a bulletproof hosting provider identified in reporting as PFCloud. Such infrastructure is commonly used to support ransomware and extortion operations by providing resilient hosting for leak sites, command-and-control functions, and data staging. The group has been mentioned alongside other contemporary ransomware and extortion brands such as Akira, BlackLock, Dire Wolf, Silent Team, and J Group, reflecting its place in the fragmented 2025 ransomware ecosystem.

The operation appears financially motivated and focused on organizations whose data exposure can create regulatory, reputational, or operational pressure. Reporting also notes disclosure of victim organizations in eight countries and public leakage of personal records associated with one of its campaigns. While DataCarry is consistently referred to as a ransomware group, the strongest supported characterization is an extortion-focused ransomware operation centered on data exfiltration and public leak pressure.

Capabilities

  • Exfiltration
  • Extortion

Operational record

7
Indicators
1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Published indicators

Md5

1 total
  • d86163423afa32bb0b793ad909d6b357

Sha256

2 total
  • b1cf41363401fe5671e24fd55ee89b0c177140c482a8dab1b9891db509df52f6
  • bb62196338dab7b26993f27e3a8ad917d848508ad8cd4646c9fe836b1140c3e4

Ip

2 total
  • 176.65.141.201
  • 154.216.19.224

Session

1 total
  • 050d1feda2751e807b2a731f1f5fe764910ba9ea8bc46e2643d3180876a5bc953c

Email

1 total
  • datacarry@riseup.net

MITRE ATT&CK

DataCarry in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.