Skip to content

EndZone

EndZone is a purported ransomware and data-extortion group associated with public claims of compromises affecting U.S.

Profile source: Mallory opens in a new tab

EndZone

Family profile

EndZone is a purported ransomware and data-extortion group associated with public claims of compromises affecting U.S. organizations, including AT&T and Accela. The group has claimed to possess sensitive data and threatened public disclosure in an apparent effort to compel victim engagement. Claims of the underlying intrusions, data theft, and attribution have not been independently corroborated.

Operational record

4
Indicators
1
Leak sites
1 available

Published indicators

Session

1 total
  • 05d048114cbc3b66844702d9d2be346433b2761be19fb9ade49fdbc0bb487f4b3c

Tox

1 total
  • 07907451C6709A86CFB6933822BF1830387948DF3369F90496ECAACB8B92C14C1C0BF7D86ED7

Email

1 total
  • endzone4@atomicmail.io

Pgp

1 total
  • -----BEGIN PGP PUBLIC KEY BLOCK----- mDMEaqs7uRYJKwYBBAHaRw8BAQdA0S/Mla4/TCfK4ZOKz3sKE0wZOekEWJ/gVJZx Q8QCdne0B2VuZHpvbmWItQQTFgoAXRYhBALNjg4t9SytT8qy06XSEHHqfsLnBQJq qzu5GxSAAAAAAAQADm1hbnUyLDIuNSsxLjEyLDIsMQIbAwUJBaSXdwULCQgHAgIi AgYVCgkICwIEFgIDAQIeBwIXgAAKCRCl0hBx6n7C5zzPAP45OoD2IC56dI5pAYB8 0+XDSRgxxrUuinKE2ZUtZr7vCAD8DDc1xbzlEwo4EJhUGOwkR9e09cgVBqZsgXQL TH5Xege4OARqqzu5EgorBgEEAZdVAQUBAQdALsj4PubJG9YDdzp4XXZG/yvCp9nU ja85gmZF+eNzNQUDAQgHiJoEGBYKAEIWIQQCzY4OLfUsrU/KstOl0hBx6n7C5wUC aqs7uRsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiwyLDECGwwFCQWkl3cACgkQpdIQ cep+wueBTAEAs8iP3oxn11A/fvTNb4/MbZsaQ8L4OUaOE0BpKqIhi6EA/31Ilg7+ MI7n6BcGGTI5dFuKHELjMtc0OnKKONYtbocN =c9iP -----END PGP PUBLIC KEY BLOCK-----

Recent claims

MITRE ATT&CK

EndZone in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.