MO

moneymessage

Known ransomware group ACTIVE
Currently active

Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US.

1

Total Claims

0

Critical

Records Claimed

1

Industries Hit

Active span: Sep 21, 2026 – Sep 21, 2026 · 1 organizations targeted

Currently active
Activity 1.9 Severity 2.5 Sectors 2.3 Tooling 0.0

Actor Threat Profile

Activity Timeline

Peak: Sep 2026 (1)
Sep 2026
LessMore
Sep 2026

Share this profile

Shareable intel card for moneymessage

Top Targeted Industries

Energy & Utilities 1

Tradecraft & Infrastructure

0

Documented tools

0 / 0

MITRE tactics / techniques

1

Known leak sites

Full intelligence profile on ransomware.live →

Claims by moneymessage

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.