Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Timc

TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.

Victims
3
 
First Victim
2026-04-09
(est. attack date)
Discovery Date
2026-04-09
 
Last Seen
2026-04-09
 
Inactive Since
129
days
Avg Delay
N/A
attack→claim
Infostealer
33.3%
victims with domain
Countries
3
hit
Uptime
87.5% avg (30d)
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months (based on attack estimated date if available)

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Pixel Dashboard Yes 2026-08-16T20:20:35 NGINX nginx 1.18.0 rzzfiwoop67jrxadngcy7nvjm7suwtrjznview63ooowqfsm5sq7gmqd.onion

Target
Top 5 Activity Sectors
  • Healthcare 1
  • Professional Services 1
  • Manufacturing 1
Top 5 Countries
  • GB flag United Kingdom 1
  • ES flag Spain 1
  • AR flag Argentina 1

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (1)
tox 1
Type IOC
tox F4227BEF9125773745F2065645AEA50C37153EF801C83FAD6C72CE2B7484051CFACCC16F1533

Victims (3)
Logo
Discovered: 2026-04-09 (4mo ago)
We breached into their intranet and have total control of it , with 1TB+ data exfiltrated including …
Logo
Discovered: 2026-04-09 (4mo ago)
On behalf of A IT solution company , the first response to the data breach was trying to cover the t…
Logo
Discovered: 2026-04-09 (4mo ago)
We've taken down their DC and FS, 100GB+ of the data including PII, Trade record and Full 20GB+ MySQ…