CMD Organization is a ransomware and data-extortion threat group that publicly claims intrusions against organizations and uses leak-site shaming to pressure victims. The group has been observed listing victims on extortion infrastructure and publishing sample stolen documents to support its claims. Reporting also associates it with an auction-style monetization model in which allegedly stolen datasets are offered to the highest bidder, indicating a financially motivated operation centered on double-extortion and possible data resale. Observed victimology includes educational institutions, and the group has appeared in weekly ransomware claim tracking as an active but not top-tier actor, with multiple claimed victims across separate reporting periods in mid-2026. In one publicly reported university intrusion, the group claimed theft of a large volume of sensitive data, issued a cryptocurrency ransom demand, and threatened timed publication of additional material. That incident was also characterized by disruptive actions beyond exfiltration, including deletion of files from affected storage systems, consistent with coercive pressure designed to hinder recovery and increase leverage. Tactics attributed to CMD Organization include unauthorized network access, data exfiltration, extortion via leak-site publication, deadline-based ransom demands, and destructive or disruptive post-compromise activity such as file deletion. The group’s operating model suggests overlap between ransomware and pure extortion tradecraft: public victim naming, proof-of-compromise releases, and sale or threatened release of stolen information. Available information supports classifying CMD Organization as a cybercriminal extortion actor. No high-confidence public attribution to a nation-state sponsor is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-style extortion activity against Mount Royal University involving network breach, data theft, data deletion, ransom demand, and leaking samples of stolen data.
Ransomware group claiming responsibility for the Mount Royal University attack, alleging theft of over 10 TB of data, publishing screenshots as proof, demanding a $1.9 million cryptocurrency ransom, and known to auction allegedly stolen victim data.
Extortion group claiming the attack on Mount Royal University, exfiltrating sensitive data, deleting data, demanding ransom, and using auction-based sale of stolen data on both the clear web and dark web.
Ransomware/extortion actor claiming responsibility for the Mount Royal University intrusion, alleging theft of data, deleting original files to hinder recovery, demanding 30 bitcoin, and using an auction-style extortion model via leak sites on both the clear web and dark web.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.