◇ SIGN IN
← all actors
ransomware

Meow

dormantmedium confidence
Ransomware
Meow LeaksMEOW
Attribution
Financially motivated (unattributed; Conti-lineage tooling)
Origin
Unknown
First seen
2022
Last active
2025
Motivation
Financially motivated (data extortion)
Confidence
medium
MENA targeting
Oman, UAE
Sectors
Oil & gas/energy services, logistics

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Oman, UAE (Oil & gas/energy services, logistics sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Meow is a financially motivated extortion operation first seen in 2022 using a strain derived from leaked Conti code; after a 2023 free decryptor it abandoned encryption for data-theft extortion, running a 'Meow Leaks' marketplace, before activity tapered off through 2025.

History

Meow ransomware was first identified in August 2022 and initially built on Conti's leaked ransomware source code. After a disruptive free decryptor became available in March 2023, the operation abandoned encryption and pivoted to data-only extortion, evolving into a data-marketplace model branded 'Meow Leaks' / 'Market Meow Leaks' where stolen data is listed and sold, reportedly with e-commerce-style interfaces and dynamic pricing.

Activity peaked in 2024, when trackers recorded 80+ claimed attacks and dozens of victims posted to its leak site in a single quarter, spanning healthcare, financial services and manufacturing. Attribution is complicated by name collisions with unrelated 'Meow' database-wiping incidents, a point vendors such as Bitdefender have flagged.

By late 2025 reporting indicated Meow's activity and operational tempo had tapered off, raising questions about its trajectory. Its MENA-relevant claims include Oman and the UAE. All such listings are extortion claims and should be treated as unverified unless corroborated by a reputable source or the victim organization.

Notable campaigns

2024
Meow Leaks marketplace surge
80+ claimed attacks and dozens of leak-site victims across healthcare, finance and manufacturing (claims).
2025
Sonoma County Superior Court listing
Files allegedly tied to a California court offered for sale on Meow's site (claimed/unverified).

Claimed victims · 145 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
KLAUSTechnology
San Francisco BalletUSOther
ZylowareUSRetail & E-Commerce
OMara Ag EquipmentCAAgriculture and Food Production
Karl Malone ToyotaUSProfessional Services
J.S.T. EspanaESManufacturing
Cottles Asphalt Maintenance IncUSProfessional Services
DieTech North AmericaUSManufacturing
Pine Belt CarsUSProfessional Services
Karman IncUSManufacturing
Finger Beton UnternehmensgruppeDEProfessional Services
LexcoCLFinancial Services