Emperador
Emperador is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Emperador is an active ransomware group targeting education, government and defense sectors.
Emperador is an active ransomware and extortion group primarily targeting the education, government, and defense sectors. The group pressures victims in Albania and the Philippines by listing them on a public leak site. Their main TTPs include file encryption, data theft, and double extortion tactics. Defenders should focus on timely patching of vulnerabilities and robust backup policies, especially within networks in these targeted countries and sectors.
Emperador is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Emperador targets Albania and the Philippines, based on the victims it lists on its public leak site.
Emperador's main TTPs include file encryption, data theft, and double extortion tactics.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.