Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Nasirsecurity

Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle East (UAE, Oman, Saudi Arabia, Iraq) and Israeli IT supply chain firms, using spear-phishing, BEC, and exploitation of public-facing applications.

Victims
1
 
First Victim
2025-10-05
(est. attack date)
Discovery Date
2025-10-12
 
Last Seen
2025-10-12
 
Inactive Since
310
days
Avg Delay
7
days
Infostealer
N/A
victims with domain
Countries
1
hit
Uptime
— avg (30d)
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months (based on attack estimated date if available)

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Nasir Security No 2026-04-28T07:25:15 yzcpwxuhbkyjnyn4qsf4o5dkvu6m2fyo7dwizmnlutanlmzlos7pa6qd.onion
favicon Error Response Page No 2026-04-28T07:27:47 Microsoft-IIS 10.0 nasir.cc

Target
Top 5 Activity Sectors
  • Technology 1
Top 5 Countries
  • IL flag Israel 1

Heatmap

YARA Rules (1)

Victims (1)
Logo
Discovered: 2025-10-12 (10mo ago)  ·  Attack est.: 2025-10-05
This is a warning... you remain in danger.…