ms13089
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
MS13089 is a new double-extortion ransomware group targeting entities in Chile.
MS13089 is a newly emerged ransomware group first observed in December 2025, named after a 2013 Microsoft Security Bulletin. It primarily targets entities in Chile, including a law firm, and operates as a double-extortion actor. The group exfiltrates victim data before encryption and threatens to leak it if the ransom is not paid. Defenders should strengthen email security, verify offline backup integrity, and monitor threat intelligence feeds for new ransomware variants associated with this group.
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
MS13089 operates as a double-extortion actor. This means the group exfiltrates victim data before encryption and threatens to leak it if the ransom is not paid.
MS13089 is named after a 2013 Microsoft Security Bulletin.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.