Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Lamashtu is a data-extortion brand that surfaced publicly in mid-April 2026 and was catalogued by ransomware trackers (ransomware.live, DarkFeed, WatchGuard) after listing victims on a dark-web (.onion) leak site. It operates a double-extortion model (data theft plus threat of leak), though public sources note it has not been confirmed to deploy actual file-encrypting ransomware as opposed to pure exfiltration extortion. Targeting is opportunistic and cross-sector/cross-region rather than focused on any single vertical or geography.
Lamashtu first appeared publicly around 11-13 April 2026, when trackers observed an initial wave of victim postings on its leak site. Over roughly two months it accumulated on the order of 30+ claimed victims across ~17 countries before going quiet after mid-June 2026 (last observed leak-site activity ~17 June 2026; dormant since). Top-hit countries in aggregator data include Malaysia, France, Thailand, Germany and Mexico, spanning manufacturing, professional services, agriculture/food production, retail and hospitality. Public reporting on Lamashtu is THIN and largely aggregator-level: ransomware.live victim entries, DarkFeed/WatchGuard tracker rows, and derived blog posts. There is no in-depth vendor malware analysis, no confirmed encryptor sample, no attributed operators, and no MITRE ATT&CK group ID. Reported TTP detail is minimal; aggregator notes that a notable share of listed victims also show infostealer-log presence, consistent with initial access via stolen credentials, but this is inferential, not confirmed. MENA relevance: REAL but low-volume and unverified as to compromise. RaqibCTI's UAE and Egypt country tags are each backed by actual named leak-site listings on ransomware.live — Egypt: Great Foods and Luna Group; UAE: Royal M Hotel by Gewan (Fujairah). These are genuine leak-site victim entries (not phantom tags), so the country tags are justified; however, like all Lamashtu claims they are unverified extortion assertions with no independent confirmation of breach, scope or data authenticity. Net: MENA footprint is real on the leak site but small (a handful of claimed victims) and evidentially thin.