Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
What tactics does the Orca ransomware group use in its attacks?+
The Orca ransomware group uses key TTPs including file encryption and likely double extortion tactics, along with a highly configurable ransomware payload characteristic of the Zeppelin lineage.