Arvinclub

Compare
Parsing: enabled

View crypto

Description

Arvin Club first appeared around early to mid-2021, debuting on its Tor leak site with posts dating back to May 5, 2021. While frequently characterized as ransomware, there is no verified evidence of file encryption or RaaS operations—its behavior aligns more closely with data-leak and hacktivist activity. The group actively publishes stolen data via its Onion site and maintains a prominent presence on Telegram, operating both official channels and group chats (notably with Persian-language content). A known target includes India's Kendriya Vidyalaya school network among others. Arvin Club has shown ideological leanings (notably support for REvil) and claims to have “hacktivist” motivations, including activities against the Iranian regime. No encryption algorithms, file extensions, or ransom notes have been publicly documented.

External Analysis2
External Analysis
https://cloudsek.com/ar/threatintelligence/ransomware-group-profile-arvin-club
https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/arvin-club
Telegram1
Telegram
http://t.me/arvin_club
Urls2
Url
Status
Screen
Uptime 30d
Health
http://3kp6j22pz3zkv76yutctosa6djpj4yib2icvdqxucdaxxedumhqicpad.onion/ Down
0%
http://arvinc7prj6ln5wpd6yydfqulsyepoc7aowngpznbn3lrap2aib6teid.onion/ Down Screen
0%
Activity (interactive) 39
Activity charts
Posts39
Date Title Description Screen
Islamic Azad University Electronic Campus https://ec.iau.ir
Jahesh Innovation https://jahesh.co
Kimia Tadbir Kiyan https://ktkco.ir
Islamic Azad University of Shiraz https://shiraz.iau.ir
Pasouk biological company https://pasouk.ir
Shirin Travel Agency http://anonissfireenterfdks2u53jqevumbu6hjm35ioorsa7eq5bsjlucad.onion/do.php?filename=bd413d1583d4b7dc9901121.rar
Aban Tether & OK exchange https://abantether.com https://ok-ex.io
sti company https://sticompany.co
Bitimen https://bitimen.com
AFTA Isfahan https://ito.gov.ir/fa/afta
hamyari Shahrdari golestan http://hamyarigolestan.ir
Haraz dairy http://doosheh.com
150k sib360 Database https://sib360.com
Padena Factory https://padenacc.ir
seaside-kish co https://www.sendspace.com/file/0oiz9f
Draje food industrial group https://draje.ir
Parsian Bitumen https://www.parsianbitumen.com
Sabalan Azmayesh https://www.sabalanmedical.ir
Bitimen exchange Bitimen
Al Bijjar
AM International
stormous
bedfordshire.police.uk
elitemate.com
afcx.co
vidisha.kvs.ac.in
Revil
Bureau van Dijk(bvdinfo.com)
Compilation of Many Breaches (COMB)
USA 280M
CardPayPortal
33M Bank Mellat – Iran
Etoudplus.ir
Beh Pardakht Mellat Cards
RockYou2021
UtAir
Leiden University Hacked
For Press
T-Mobile
Note