NOTE: This is the initial intelligence gathering and analysis based on the newly found IOCs of Ransomware and also uncovered new File Servers and Communication Channel of the Group.
INDEX
- INTRODUCTION
- DATA LEAK SITE OVERVIEW
- VICTIMOLOGY
- VICTIM LEAK UPLOAD FREQUENCY
- SAMPLE ANALYSIS & DETECTION
- YARA RULE
- RANSOM NOTE
- THREAT INTELLIGENCE
- THREAT ACTOR PROFILING
- IOCs
INTRODUCTION
In August 2026, another Japanese-Themed Ransomware Group appeared after YUREI, SINOBI and TENGU. We will see later in this article, whether they have anything in common.
Regarding the name, the trick here to understand is the name “MAJINAHANASHI” should not be read together, however need to break it into 2 parts namely:- MAJIN (Djinn/Ghost) and AHANASHI (Story) which literally means DJINN/GENIE Stories (Ghost Stories), in Japanese.

DATA LEAK SITE OVERVIEW
The group uses Non-Vanity Domain for their DLS operation, which is reachable at:-
- lthicpjqc7gkn5eq3epxndc2uig3yngvcbdya4u3m3byjod5km4yuwqd.onion
This shows that the group is not much invested/interested to make it synonymous with the brand name, however there are exceptions like Cl0p which follows non-vanity domains.
NOTE: Vanity Domain Names are special TOR Domains which starts with the Ransomware Group’s name such as Lockbit, Rhysida, WorldLeak etc.
The DLS is accessed using solving a simple Math Captcha.

When solving, the DLS is presented to the visitors.
NOTE: After solving captcha for the first time, you don’t have to solve the CAPTCHA again for ~1 month, as the session is set for 30 days.
Here is the DLS of the Website:-

Here is the footnote banner of the group

“DECISION REQUIRES CLARITY” is the tagline for this Group.
Like other ransomware groups, Countdown Timers are available for the upcoming leaks.

The group had adopted one of the oldest pressure tactic from other ransomware group like Victim Introduction which also states the Revenue of the firm.

Analyzing the Annual Revenue of various victims, the top revenue earning victim is from Switzerland clocking at $61M. Other victims are ranging from $2M and the average victim revenue sits at $25M turnover.
Before leaking the dataset, the group lists evidence as Proof of Hack before releasing the entire leak.

While navigating the “News” section, a note was found which is:-

The text such as “Hello world” or “I love bulgaria” could be mis-leading for Researchers/Security Analysts to divert the attention. But could be of personal interest too or an unfinished project. It is also notable that there are 2 Bulgarian companies
Like other groups, Majinahanashi does NOT list any Contact Details left in their DLS. This could be either at developing or the group does not want to grab much attention at this stage.
VICTIMOLOGY
Unlike other groups, Majinahanashi does not target the US but:-
- Switzerland
- Italy
- Germany
- Bulgaria
- India
- Portugal
- France
- Chile
- Lithuania
- Thailand
- Columbia
NOTE: Earlier, I mentioned about targeting US, but the group reached out to me and rectified they don’t have a single victim from the US. Updated the article.
This proves that the group does not target English Speaking Countries like Canada, UK, Ireland etc (as of now), but clearly focusing on non-English Countries. This is a trend which we spotted with Gunra Ransomware, however they announced their first US victim recently.
NOTE: Bulgaria and Lithuania does not comes under CIS Nations, which is often excluded from the Ransomware Infection.
Regarding the sector, the most affected sector is E-Commerce and Manufacturing, which is followed by Agriculture, Services and Technology.
The Initial leak appeared on 27th June 2026 and there are currently 15 victims (as of now in August 2026).
VICTIM LEAK UPLOAD FREQUENCY
While tracking the Victim Leak Frequency of Majinahanashi Group, found a consistent pattern.
Here’s the count of projects per date, from the list of 12 entries spanning July 6 to August 11, 2026. Two dates stand out with the most activity — July 6, July 8, and August 3 and 8 each had 2 projects — while the rest had 1 each.

This shows that the group is regularly updating their DLS with upcoming victims set with a Count Down timer.
NOTE: There are some groups which mass-publish victim leaks at a single go. But here, it’s different.
SAMPLE ANALYSIS & DETECTION
Here are some of the quick-notes of Majinahanashi Samples:-

➸2 samples are spotted with creation date set to 2nd July 2026, coded in C/C++
➸Both samples are sized at 90KB
➸Files are locked and appended the extension .MAJIN
➸Files are encrypted using AES-256
➸Command execution is done through a thin wrapper that builds command lines and calls CreateProcessA
➸Aggressively deletes volume shadow copies, disables recovery/boot options, clears event logs, and disables hibernate/System Restore so the victim cannot easily roll back

Following are the dropped path, file names and other parameters for Detection:-
➸C:\Windows\Temp\majin.exe — Used Drop Path
➸C:\1\service.log — Log File
➸ADMIN$\Temp\majin.exe — Dropped via admin share for remote execution
➸C:\ProgramData\majin.bmp — Generates wallpaper BMP
➸C:\majin.bmp — Generates wallpaper BMP
➸Encryption marker — ENCRYPTEDAES256!SCT2
➸Mutex — Global\majinahanashi_Mutex
➸majinSvc — Windows service name registered for persistence
1. ENCRYPTION
➸Files are encrypted using AES-256
➸Supports AES-NI hardware acceleration when available, with software fallback
➸Uses an RSA public key (embedded in the binary) to wrap the per-file AES keys
➸Files are encrypted in place. A unique key is generated per file
➸The binary contains both hardware AES instructions and classic AES constants
➸AES loop is unrolled for performance and uses hardware AES instructions
2. LOCK SCREEN & WALLPAPER HIJACKING
Majin generates a custom full-screen lock screen using GDI:
➸Font: Segoe UI
➸Key strings drawn on screen:
SEIZEDM A J I N A H A N A S H ITHIS DEVICE HAS BEEN LOCKED.DO NOT MODIFY ENCRYPTED FILES.README.TXT
It creates a BMP wallpaper (typically 1920×1080) and forces it via two registry locations:
➸HKCU\Control Panel\Desktop → Wallpaper + WallpaperStyle
➸HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System → Wallpaper
This dual-path approach increases the chance that the wallpaper survives user-level cleanup
3. SERVICE MODE & COMMAND-LINE OPTIONS
The binary can run as a Windows service and supports several operational flags:
Flag : Purpose
--service --nolan: Run as service, disable LAN scanning--dry-run: Simulation / test mode--test-pre: Pre-flight test--nopf: Skip post-flight--qos-dev / --edr-dev: Development / debug modes--path: Target specific path
--decrypt: Decryption mode (when private key is present)
Logging is relatively verbose and uses prefixes such as SVC:, [pf], [qos], and STRESS:.
4. DEFENSE EVASION & ANTI-ANALYSIS
Notable techniques observed:
➸Direct syscalls (SSN resolution from ntdll.dll)
➸PEB access
➸Stack strings + XOR obfuscation
➸Dynamic API resolution via PE export parsing
➸I/O Priority manipulation (IoPriorityVeryLow / IoPriorityNormal via NtSetInformationProcess) — used to reduce disk activity visibility during encryption
➸Delay execution and language/geo checks (GetKeyboardLayoutList, GetUserGeoID)
5. NETWORK CAPABILITIES
Majin implements Windows Filtering Platform (WFP) based network control under the names:
➸majinahanashi WFP network control
➸majinahanashi Net Filter
➸qos_silence / edr_silence
It also interacts with network QoS policies via WMI:
SELECT * FROM MSFT_NetQosPolicySettingData
This combination is uncommon among ransomware families and appears designed to interfere with EDR/cloud agent communication or to throttle traffic.
6. PRE-FLIGHT & POST-FLIGHT
PRE-FLIGHT
➸Privilege check
➸Process termination of security and backup tools
➸Service stopping
➸System restore disable via WMI
➸Event log clearing
➸USN journal deletion (fsutil usn deletejournal)
➸Shadow copy deletion (vssadmin delete shadows /all /quiet)
➸Boot configuration changes (bcdedit)
POST-FLIGHT
➸Wallpaper application
➸Final cleanup
➸Logging of completed actions
Targeted processes (partial list):
Carbon Black, CrowdStrike Falcon, FortiEDR, SentinelOne, Cylance, Microsoft Defender for Endpoint, Qualys, Tanium, Veeam, Backup Exec, Acronis, and many others.
7. OVERALL ASSESSMENT
Majinahanashi is a mid-tier ransomware family with several interesting technical choices (especially network control and I/O prioritization) but does not exhibit extremely advanced anti-analysis or novel cryptography. Majin’s implementation looks more carefully engineered and performance-aware. Its combination of classic double-extortion with selective modern techniques makes it worth monitoring.
NOTE: This is not a deep-down analysis of the sample, but a shallow analysis which gives a glimpse about Majin capabilities. To check out, you may refer to the IOC section of this article at the end to obtain the samples.
YARA RULE
Combining all the logic and parameters listed above, here is the YARA for detecting Majinahanashi Samples:-
rule Majinahanashi_Ransomware{ meta: description = "Detects Majinahanashi ransomware (based on confirmed disassembly and strings)" author = "THE RAVEN FILE" date = "2026-08-14" threat_name = "Majinahanashi" category = "ransomware" strings: // Strong unique branding $brand1 = "MAJINAHANASHI" ascii wide $brand2 = "M A J I N A H A N A S H I" ascii wide $ext = ".majin" ascii wide nocase // High-value unique identifiers $mutex = "Global\\majinahanashi_Mutex" ascii wide $marker = "ENCRYPTEDAES256!SCT2" ascii $wfp = "majinahanashi WFP" ascii wide $svc = "--service --nolan" ascii // Confirmed lock-screen / note text $note1 = "SEIZED" ascii wide $note2 = "THIS DEVICE HAS BEEN LOCKED." ascii wide $note3 = "DO NOT MODIFY ENCRYPTED FILES." ascii wide $note4 = "FIND README.TXT" ascii wide $readme = "README.TXT" ascii wide nocase // Confirmed recovery destruction commands $cmd1 = "vssadmin.exe" ascii wide $cmd2 = "delete shadows /all /quiet" ascii wide $cmd3 = "reagentc.exe" ascii wide $cmd4 = "bcdedit.exe" ascii wide $cmd5 = "recoveryenabled no" ascii wide $cmd6 = "bootstatuspolicy ignoreallfailures" ascii wide $cmd7 = "powercfg.exe" ascii wide $cmd8 = "/hibernate off" ascii wide $cmd9 = "wevtutil.exe" ascii wide $cmd10 = "fsutil.exe" ascii wide $cmd11 = "usn deletejournal" ascii wide // Confirmed wallpaper / UI strings $font = "Segoe UI" ascii wide $wall1 = "Control Panel\\Desktop" ascii wide $wall2 = "Wallpaper" ascii wide condition: uint16(0) == 0x5A4D and filesize < 8MB and ( // Highest confidence - branding + unique identifiers (1 of ($brand*) and $ext) or (1 of ($brand*) and 2 of ($note*)) or ($mutex or $marker or $wfp) or // Strong secondary ($ext and 3 of ($note*) and 4 of ($cmd*)) or ($svc and 1 of ($brand*)) or // Recovery + wallpaper cluster (6 of ($cmd*) and $font and 1 of ($wall*)) )}
RANSOM NOTE
Here is the Ransom Note obtained:-
We entered. We looked around. We took what was there.This is the report.--------------------------------------------------------------------------WHAT WE DIDFiles were encrypted where they sat. A unique key perfile, wrapped under an offline key that leaves with uswhen this is over. Backups and shadow copies wereremoved because they get in the way.No files were deleted. No data was corrupted. Everybyte can be recovered.--------------------------------------------------------------------------WHAT WE TOOKA copy of your internal data was extracted during theprocess. This is not a threat - it is a statement offact. We have it. You do not.If an agreement is reached, all copies are destroyedand you receive written confirmation. If no agreementis reached, the data finds new owners.--------------------------------------------------------------------------NEXT MOVEContact us via qTOX: 59DE03AE55C400954D0973FFB90C251A7FDCEB3079A42DF6A6DB93E7D1915F5C47B238A2A99EContact us via EMAIL: thedoctorcame@protonmail.comCase: XXXX1111Download qTOX: https://qtox.github.io/
THREAT INTELLIGENCE
➸Upon inspecting the DLS, the public-facing web server is nginx. The Python/Flask application is running behind it.
➸The group hosted their leaks on different servers apart from the DLS. They are named as “文書庫 | MAJINAHANASHI ARCHIVE”.
➸This is interesting as the word “文書庫” translates to “Document Repository” (when you enter in translate, it auto-detects as Chinese but not to get confused, as it is Kanji used in Japanese).
NOTE: Kanji refers to the logographic writing symbols borrowed from China that are used in the modern Japanese writing system
➸The File Servers are located at:-
- cc666mzpsjhn3yi6t7hqkwi5thjeh7prxg3mndpceb7xtchsbsmct3ad.onion: NEW
- rz45lyi2ehl2e2xs3ivwbah65tumebztmypmtqpc6cigc3wadwjicgad.onion: OLD
➸Among this, the OLD File Server is had only hosted 2–3 victims. And rest of the leaks are hosted with NEW File Server, both are running in nginx server.


➸During Email Communication, it is revealed that the threat actor demanded $15.000.

➸Upon further chat, they revealed their BTC Address as:
- bc1qdck7sevqwy3zc5z8h42ekf2txl04af8sattwac
The infection point is quoted by the group as:-
“Yes, we gained access to your company through your internet service provider. The infection occurred via a physical storage device, as is the case with 70% of our initial access”
➸This is a vague statement with exaggerated figure of 70% as USB Infection. It is highly unlikely to compromise each of their targets with a USB Virus infection physically. Hence, we can’t trust the infection method from the group.
➸2–3 Victims are batched together and uploaded intermittently to their DLS
Italy and the US are most targeted with 2 victims each (as of now)
➸The leaks of all victims are not available, though proof of Hack is evident from the Sample Image uploaded on the Victim Page.
➸The group actively re-purposes/uses Mimikatz and Advanced IP Scanner during their operation, which is popularly used by Gentlemen Group or other ransomware groups.
➸While checking the Onion DLS of Yurei and Tengu, both these players does not have a Vanity Domain Name, however; Sinobi does. All these groups are currently offline (ATTOW).
➸ The group quotes “Servers & Hyper-V encrypted” or “20.000+ sensitive H&R files extracted from storage servers” on some of the victim’s page to amplify the scare factor.
THREAT ACTOR PROFILING
➸The group genuinely could be a non-native English Speaker. This is evident from their Email Conversation and DLS, though can’t conclude.
➸The admin of this Ransomware is really available over the email as most of the replies appear within 30 minutes. High Available Time noted.
➸The group adopted the username “THE DOCTOR CAME” over email communication, which had been uncovered during the investigation.
➸While analyzing both DLS and Sample, it is found that the DLS is perfectly created with security. However, the sample of Majinahanashi is bit weak when compared to Yurei. Hence, there could be a chance of 2 group who specially assigned to DLS Maintenance and Build Creation.
➸ The admin/email-handler of Majinahanashi gives vague answer when asked about Infection Method, which makes it less reliable on the group.
➸ The group had added another Proton mail for Communication (which is updated in the IOC section of this article). And additionally added another section to their Ransom Note as:-
TIMELINE Day 7 - the full dataset is released. Regulators, clients, and affected parties are notified directly.
IOCs
DLS: lthicpjqc7gkn5eq3epxndc2uig3yngvcbdya4u3m3byjod5km4yuwqd.onionFILE SERVER===========cc666mzpsjhn3yi6t7hqkwi5thjeh7prxg3mndpceb7xtchsbsmct3ad.onionrz45lyi2ehl2e2xs3ivwbah65tumebztmypmtqpc6cigc3wadwjicgad.onionrtypxnzdjus6slwtzhmnh7dnc35q3sdzbiuhaammefl5u2ce2lxkg5yd.onionHASHES======MD5: 914ff51fb60247cf13897b1bc950a190SHA-1: 6f9e1371427be15a840c2de5eb1719a466af2016SHA-256: bd91d786841f5259430c1c90b454d9f8bf510186fe4d32a0998bd9b5a7916467 MD5: 7ee443b0530bb9fe4c36c0faafdeb6bcSHA-1: d213bccd00f98d8af608186035bc8bf814e13364SHA-256: e6ec7749e3d0f750fa53b5a7619d1e5af57673d236338b3a020d0f534ec5c15d CONTACT=======TOX: 59DE03AE55C400954D0973FFB90C251A7FDCEB3079A42DF6A6DB93E7D1915F5C47B238A2A99EEmail: thedoctorcame@protonmail.comwe_will_treat@proton.me
Follow me on Twitter/X for interesting DarkWeb/InfoSec Short findings!
Leave a Reply