Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Tengu is a ransomware-as-a-service operation first observed on 9 October 2025, when it published its initial victims to a Tor-based data leak site. It runs a double-extortion model, exfiltrating data before deploying intermittent/partial file-encryption for speed. Over fewer than six months it claimed roughly 49-50 victims across multiple continents and sectors. In March 2026 the leak site rebranded to 'Shisa,' pruning older listings while retaining a subset of active victims, so 'Tengu' and 'Shisa' refer to the same operation.
Tengu emerged on 9 October 2025 with an initial batch of victims on its DLS (fuvodyoktsjdwu3mrbbrmdsmtblkxau6l7r5dygfwgzhf36mabjtcjad.onion). In January 2026 it migrated to new leak-site infrastructure (longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion) and retired the old site. Reported tradecraft includes RDP brute-forcing via residential proxies for initial access, network/service discovery with tools such as NetExec (nxc smb) to enumerate SMB and identify Fortinet appliances, exploitation of ZeroLogon (CVE-2020-1472) against domain controllers, abuse of ConnectWise ScreenConnect for remote deployment (with revoked/abused code-signing observed), heavy use of LOLBins to blend with admin traffic, and rapid intermittent encryption (one victim reportedly ~22.9 TB encrypted in ~14 hours). Sectors hit include manufacturing, technology/IT, consumer goods, real estate, automotive, healthcare, food production, and education. On 10 March 2026 the operation rebranded to 'Shisa,' keeping ~12 active listings on a revamped site; the underlying operation appears to remain active under the new name, so the Tengu brand itself is effectively superseded rather than shut down. MENA relevance: REAL, not thin. ransomware.live's victim list for Tengu includes confirmed Gulf and North-African leak-site victims: UAE (Al Arif Contracting Co., Al Rimal Group), Saudi Arabia (Health Services Association, seha.org.sa), plus Morocco (multiple), Algeria, Iran, Israel, and Turkey. The existing RaqibCTI 'Saudi Arabia' and 'UAE' country tags are therefore substantiated by named DLS victims, not merely inferred or opportunistic keyword hits.
+9 more relationships — see the relationships browser.