Orion is a questionable ransomware operation from October 2025 known for recycling victim data from LockBit and BlackCat leaks.
Analyst brief
Orion is a ransomware operation first observed in October 2025, but its claimed victim list was recycled from prior LockBit and BlackCat disclosures, casting doubt on the authenticity of its compromises. While it purports to target India, particularly the manufacturing sector, the reuse of data suggests a possible fake extortion attempt. The main TTP involves operating a dark web leak site with repurposed victim information rather than deploying novel ransomware tools. Defenders should focus on verifying any Orion-related claims internally and maintain existing defenses against known LockBit and BlackCat TTPs.
orion
activecrime
Orion is a ransomware operation first observed in October 2025 that listed 13 alleged victims on a dark web leak site across financial services, manufacturing, and healthcare, though analysts determined its victim list was recycled from prior LockBit and BlackCat disclosures rather than fresh compromises.