Abyss-Data ransomware group
Abyss-Data is one of the extortion operations we watch continuously. This page covers what is known about the group and the current state of its leak site, which we last saw change 18h ago.
Who they are
Abyss‑Data, also known as Abyss Locker, is a ransomware operation first identified around March 2023. It conducts double extortion by exfiltrating data and encrypting systems—particularly targeting VMware ESXi virtual environments—then threatening to leak stolen data via a TOR-based leak site if ransom demands aren't met. The group’s Linux variant derives from the Babuk ransomware source code with encryption resembling HelloKitty, using ChaCha–based ciphers. On Windows, Abyss Locker encrypts files (typically appending “.abyss” or randomized extensions), deletes Volume Shadow Copies, manipulates boot policy to disable recovery, and delivers ransom notes (e.g., WhatHappened.txt), often replacing the desktop wallpaper as part of its extortion tactics. Its campaigns have targeted diverse industries—finance, healthcare, manufacturing, technology—across multiple regions, with victim lists prominently featuring organizations in North America.
Current status
Abyss-Data's leak site is not answering. Sites go dark for infrastructure trouble, a deliberate quiet period, or a takedown, and a good number return weeks later under the same name, so the entry stays on the list either way.
The last change we recorded on it was 18h ago (4 Sep 2026 18:10 UTC).
Which organisations this group has named, and when, is part of the SINON platform rather than this page. Create an account to search it, or to be told automatically if a name you care about turns up.
Sectors targeted
- Memsic.Com
Watching for your name
If Abyss-Data posts your company, a supplier or a subsidiary, you want to hear it from us rather than from a journalist. SINON checks these sites continuously and alerts on the names you give it.
Start monitoring