desolator
Active since 2025-08-27
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from desolator's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
According to ransomware.live, the group claims:
Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.
Source: Ransomware.live