Ransomware
White RabbitMario ESXi
Attribution
Unattributed financially motivated cybercrime group; no confirmed nation-state or named-crew attribution in public reporting. Cyberint used a Doc2Vec ransom-note comparison to identify a ~99% linguistic match between RansomHouse and the later 8Base group, suggesting affiliation, shared operators, or a copycat relationship, but the exact overlap remains unconfirmed. English is the primary operating language of the group's communications and leak site.
Motivation
Financial (data-theft extortion / double extortion)
Attribution confidence
medium
MENA targeting
Saudi Arabia, Egypt
Sectors
Manufacturing, hospitality
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, Egypt (Manufacturing, hospitality sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.