White Paper
THREAT PROFILE: Sarcoma Ransomware
Sarcoma is a ransomware-as-a-service (RaaS) group first identified in 2024 that employs a double-extortion strategy, combining file encryption with data theft to pressure victims into paying a ransom. If organizations refuse to pay, the group threatens to publish stolen information through a dedicated leak site. Sarcoma has most frequently targeted manufacturing organizations within the industrial sector, with a significant concentration of victims located in North America. This threat profile examines the group’s operations, targeted industries and regions, known tools, threat actor associations, and attack methodologies across both Windows and Linux environments. It also maps Sarcoma’s tactics, techniques, and procedures to the MITRE ATT&CK framework, providing insight into how the group
