Attribution
Unattributed. No public reporting links Lamashtu to a known ransomware operation, RaaS affiliate program, or named lineage. Named after the Mesopotamian demon Lamashtu; the branding is the only distinctive marker and no vendor has published code or infrastructure analysis tying it to a predecessor. Any lineage claim would be speculative.
Motivation
Financial (data-theft extortion)
Attribution confidence
medium
Sectors
Hospitality, manufacturing, agriculture/food
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE, Egypt (Hospitality, manufacturing, agriculture/food sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.