APT73

Dark since November 22, 2024
43 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
May 2024 first victim we recorded
Nov 22, 2024 most recent victim posted
5 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

35.7% of APT73 victims whose domain we can identify (15 of 42) had employee credentials leak in the 12 months before APT73 named them as a victim.

We don't know whether any of these credentials were how APT73 gained initial access.

What industries APT73 targets

Sector identified for 23 of 43 victims.

Financial Services6
Technology5
Manufacturing4
Retail2
Healthcare2
Hospitality1
Automotive1
Telecommunications1

Where the victims are located

Country identified for 17 of 43 victims.

United Kingdom6
Switzerland3
France2
India1
Germany1
Brazil1
Peru1
Croatia1

Most recent APT73 victims

VictimSectorCountryPosted
SFR sfr.frTelecommunicationsFranceNov 22, 2024
RAO doo rao.hrTechnologyCroatiaNov 21, 2024
Protecta Security protectasecurity.peFinancial ServicesPeruNov 19, 2024
Baldinger AG baldinger-ag.chNot identifiedSwitzerlandNov 11, 2024
Emefarma emefarmario.com.brManufacturingBrazilNov 11, 2024
La Maison du Citron lamaisonducitron.comNot identifiedNot identifiedNov 11, 2024
LiftKits4Less liftkits4less.comRetailNot identifiedNov 11, 2024
Assurified assurified.comFinancial ServicesNot identifiedNov 8, 2024
Botiga botiga.com.uyNot identifiedNot identifiedNov 8, 2024
Legilog legilog.frTechnologyFranceOct 30, 2024
Scopesset scopesset.deNot identifiedGermanyOct 30, 2024
Sokak Kreatif sokkakreatif.comNot identifiedNot identifiedOct 30, 2024
Trinite Solutions trinitesolutions.comNot identifiedNot identifiedOct 30, 2024
Appen appen.comNot identifiedNot identifiedOct 25, 2024
Drizly drizly.comNot identifiedNot identifiedOct 25, 2024
Filmai filmai.inNot identifiedIndiaOct 25, 2024
CDS hpecds.comNot identifiedNot identifiedOct 25, 2024
MGF Sourcing mgfsourcing.comNot identifiedNot identifiedOct 25, 2024
Modplan modplan.co.ukManufacturingUnited KingdomOct 25, 2024
Nanolive nanolive.chNot identifiedSwitzerlandOct 25, 2024

Showing the 20 most recent of 43. Browse recent data breaches for more.

APT73 leak sites

Addresses we've seen APT73 publish victims from. Any .onion address needs the Tor Browser.

  • bashex7mokreyoxl6wlswxl4foi7okgs7or7aergnuiockuoq35yt3ad.onion
  • wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
  • bashete63b3gcijfofpw6fmn3rwnmyi5aclp55n6awcfbexivexbhyad.onion
  • basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
  • santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion

APT73 questions

Is APT73 still active?

Not for over a year. The last victim we recorded was November 22, 2024. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has APT73 claimed?

APT73 has named 43 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did APT73 first appear?

The first victim we recorded for APT73 was posted on May 24, 2024. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does APT73 target?

Financial Services accounts for the most victims we can classify, with 6. Technology follows at 5. We could identify a sector for 23 of 43 victims, so treat this as the shape of the targeting rather than a full census.

Has APT73 already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.