Eclipse is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
observed victims (by country)
ItalyIndiaUnited StatesSingapore
observed sectors
TechnologyManufacturingHealthcareNot Found
4 victims · last active 27 Aug 2026
recent activity · our intel
source: ransomware.live1 refs → FAQ2
Which country's organizations does the Eclipse group primarily target?+
The Eclipse group primarily targets organizations in Singapore.
What is the primary attack method used by the Eclipse group?+
The Eclipse group uses double extortion TTPs, exfiltrating data and threatening to publish it on a public leak site.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.