AR

arcusmedia

Known ransomware group ACTIVE
Currently active

Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.

1

Total Claims

0

Critical

Records Claimed

1

Industries Hit

Active span: Sep 19, 2026 – Sep 19, 2026 · 1 organizations targeted

Currently active
Activity 1.9 Severity 2.5 Sectors 2.3 Tooling 0.0

Actor Threat Profile

Activity Timeline

Peak: Sep 2026 (1)
Sep 2026
LessMore
Sep 2026

Share this profile

Shareable intel card for arcusmedia

Top Targeted Industries

Technology 1

Tradecraft & Infrastructure

0

Documented tools

0 / 0

MITRE tactics / techniques

1

Known leak sites

Full intelligence profile on ransomware.live →

Targeted Organizations

Claims by arcusmedia

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.