◇ SIGN IN
← all actors
ransomware

Sarcoma

activemedium confidence
Ransomware
Sarcoma Group
Attribution
RaaS
Origin
Unknown
First seen
2024
Last active
2025
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Saudi Arabia, Oman, Kuwait, Qatar, UAE
Sectors
Manufacturing/holding, energy, hospitality, retail, business services

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, Oman, Kuwait (Manufacturing/holding, energy, hospitality sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Sarcoma is a ransomware-as-a-service operation that emerged in October 2024 and rapidly became one of the most active groups of 2025, running a Tor leak site with countdown timers and weaponizing legitimate RMM tools for stealthy 'living off the land' intrusions.

History

Sarcoma appeared in October 2024 and, within its first month, climbed to among the most active ransomware brands globally. It operates a RaaS model that fueled rapid expansion across sectors, targeting critical infrastructure, financial institutions and manufacturing. Analysts highlight its abuse of legitimate remote monitoring and management (RMM) tooling to blend malicious activity into normal IT operations, a 'living off the land remotely' approach.

The group runs a minimalist Tor data-leak site listing breached organizations alongside sample data and countdown clocks, and openly solicits cooperation from initial-access brokers, third parties and insiders. Documented 2025 incidents include the June 2025 publication of data from Swiss nonprofit Radix and an October 2025 posting related to Unimed RS in Brazil, illustrating a global victim spread.

Sarcoma remained fully operational through late 2025 with 100+ documented victim claims and, per reporting, no public law-enforcement action against it. Its MENA-relevant leak-site claims include Saudi Arabia, Oman, Kuwait, Qatar and the UAE. All such listings are extortion claims and should be treated as unverified unless corroborated by a reputable source or the victim.

Notable campaigns

2025
Radix (Switzerland) data leak
Published stolen data from Swiss nonprofit Radix on its leak site in June 2025 (claim; Swiss authorities acknowledged the incident).
2025
Unimed RS leak
Posted data tied to an attack on Brazilian health cooperative Unimed RS in October 2025 (claimed).

Claimed victims · 141 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
GYFTechnology
Propane Levac Inc.CAEnergy & Utilities
MecMaticaITTechnology
SöllnerDEManufacturing
B&J Rocket SalesCHManufacturing
Paul HildebrandtDEManufacturing
Unimed do BrasilBRHealthcare
Charter Industrial SupplyUSManufacturing
MSBOther
MACMA Werbeartikel oHGDEProfessional Services
ThermofinCAManufacturing
Miami ManagementUSProfessional Services