Lamashtu

First seen
2026-04-15 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:26:55

Targeted industries: energy-and-utilities healthcare-and-pharmaceutical retail-and-hospitality media-and-entertainment

Targeted regions: country_code:fr country_code:ro country_code:th country_code:my country_code:eg country_code:ae

Context

Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails to pressure victims. The group has claimed 17+ victims across France, Romania, Thailand, Malaysia, Egypt, and the UAE within its first weeks of activity, targeting energy, pharmaceutical, retail, hospitality, and film sectors, with confirmed exfiltration totaling 760+ GB.

Reports & references

  • redpiranha.net — Threat Intelligence Report April 21 April 27 2026 (report)

External references