Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

PEAR Ransomware Decryption & Data Recovery

  • Active
  • High
  • No public decryptor

PEAR (Pure Extraction And Ransom) is a data-theft-only extortion crew that surfaced in mid-2025. It openly states that it does not encrypt systems, relying entirely on stolen data and a Tor leak site for leverage; roughly 90% of its victims are US-based, concentrated in business services, healthcare, legal and education.

First seen
2025-06
File extensions
No public information
Ransom notes
No public information
Affected platforms
Windows

Family profile

File extensions
No public information
Ransom notes
No public information
Contact patterns
  • Anonymous mailbox on the onionmail.org domain
  • Tox ID (long hexadecimal string) used for negotiation
  • Tor (.onion) leak sites whose addresses begin with pear, plus separate data-hosting onion servers that do not carry that prefix
  • Temporary file-hosting links used to deliver proof-of-data samples
  • Direct SMS and WhatsApp messages to employees' personal phones
Aliases / versions
PEAR Team、Pure Extraction And Ransom
First seen
2025-06
Status
Active
Operational status
Actively operating
Threat level
High
Affected platforms
  • Windows
Tags
  • Extortion-only
  • Active
  • Phishing
  • RDP brute force
Decryptor
No public decryptor

There is no public decryptor, and nothing that needs decrypting: in every publicly documented case PEAR deploys no encryptor, files are not renamed and no extension is appended. No More Ransom and vendor toolkits therefore carry no PEAR decryptor, and none is required.

If encrypted files do appear alongside an extortion message signed PEAR, treat them as two separate problems: identify the real encrypting family from actual samples first (it may be a second intruder in the same window, or someone borrowing the PEAR name for leverage), then assess that family's decryptability on its own terms. Downloads advertised as a "PEAR decryption tool" should be assumed to be scams or second-stage malware and never run against production volumes.

Latest activity

  1. PEAR published roughly 3.3 TB stolen from US medical billing provider MCBS for free download, covering 1,261,464 individuals. The intrusion dated to late September 2025; free release is its penalty for non-payment.

    Sources
  2. PEAR listed Club One Casino and Austin Plastic Surgery Institute on the same day; 14 further victims were claimed in the preceding 60 days, concentrated in healthcare, business services and manufacturing.

    Sources
  3. PEAR listed Monmouth University (New Jersey), claiming roughly 16 TB of stolen data - about 28 times the average exfiltration volume for comparable attacks. The university disclosed the incident on 13 March.

    Sources

Overview

PEAR (Pure Extraction And Ransom, self-styled PEAR Team) surfaced in mid-2025 - most trackers place it in June, some in July - and began naming victims on its Tor leak site that August; by September 2026 more than 120 organisations had been listed, at a steady 8 to 13 per month.

Its defining trait is that it does not encrypt: leverage comes entirely from stolen data and the threat of publication. Victims see no renamed files and no outage - the first signal is an extortion email or their own name on the leak site. The crew describes itself as a closed private team rather than a RaaS and prices demands from exfiltrated financial statements; cyber-insurance claims research puts the average demand near USD 550,000. Roughly 90% of victims are US-based, concentrated in business services, healthcare, legal, finance and education.

Public technical reporting remains thin - no tier-one vendor has published a deep analysis - so this page rests on long-run leak-site observation and vendor intelligence.

How to identify it

PEAR does not encrypt, so there is no extension to match and no ransom-note file on disk. Identification rests on intrusion artefacts and the extortion message itself.

The contact. An anonymous mailbox on the onionmail.org domain or Tox, signed PEAR Team, with proof-of-data samples on temporary file-hosting links. Operators also text or WhatsApp executives and staff on personal numbers taken from stolen directories.

Host artefacts. Unapproved remote management software as a service and autorun entry (AteraAgent, Splashtop and similar); PsExec and bulk PowerShell activity; endpoint protection or EDR disabled or uninstalled; security and audit logs cleared.

Exfiltration artefacts. WinSCP and RClone binaries, frequently renamed; hundreds of gigabytes outbound in a short window; wide-scale enumeration and archiving across file servers and shares.

Infection vectors

PEAR's access playbook is unremarkable but reliable against common weaknesses.

  • Stolen VPN and remote-access credentials. Ranked first across public reporting: third-party breach corpora, credential stuffing and password reuse, especially VPN without MFA and internet-facing RDP, with phishing as a supplement.
  • Persistence. Legitimate remote management software (AteraAgent, Splashtop and similar) installed for a durable channel - frequently allow-listed and hard to separate from normal IT operations.
  • Lateral movement. PsExec, PowerShell and in-memory credential dumping, spreading over SMB to file servers and database hosts.

Dwell time is the trait that matters most: publicly documented cases run to months between initial compromise and the extortion contact - in one disclosed incident the intruders held access for roughly half a year before bulk exfiltration began. By then exfiltration is normally complete, so the priority is scoping rather than interdiction.

Encryption behavior

No encryption. In every publicly documented case PEAR deploys no encryptor: contents, names and extensions are untouched, shadow copies, backups and virtual machines are left alone, and production keeps running.

The core activity is bulk exfiltration: internal enumeration and staging, then batched transfer via WinSCP and RClone (often renamed). One documented incident recorded roughly 732 GB leaving through WinSCP over 24 hours; per-victim volumes run from hundreds of gigabytes to multiple terabytes, the largest public claim being 16 TB.

Pressure is staged: sample proof, a payment deadline, then phased publication, with complete archives posted for free download where nobody pays. No outage, but data exposure is irreversible.

Assess before you act

Recoverability assessment

A PEAR incident has no decryption problem - nothing was encrypted. What must be assessed is the scope of the data loss, the resulting notification duties and ongoing risk. We do not pay ransoms and do not negotiate; our work is forensics, scoping and hardening.

1) Establish what actually left (first priority). Reconstruct the accessed and exfiltrated directories, tables and mailboxes from firewall, proxy and VPN flow logs, remote-management session records, file-server and database audit logs, and WinSCP or RClone artefacts, with a volume estimate and timeline - not from the attacker's own claims.

2) Classify the data and determine reporting duties. Grade personal information, health and financial records, contracts and intellectual property, then assess obligations under China's PIPL and Data Security Law plus GDPR or HIPAA exposure for overseas operations.

3) Rotate credentials and keys. Assume every credential inside the exfiltration scope is burned: reset passwords and sessions, enforce MFA on VPN, mail and administrative consoles, and rotate API keys, certificates and service accounts.

4) Remove persistence. Uninstall unapproved remote management agents and clear rogue accounts, scheduled tasks and services; access obtained by theft-only crews is regularly resold to groups that do deploy encryptors.

5) Monitor downstream risk. Watch for redistribution of the archive, targeted phishing and impersonation fraud.

We commit to a verifiable scoping conclusion and a concrete remediation checklist. We do not promise data can be "withdrawn" or "deleted" - once it has left your network no party can ensure it will not circulate again, and payment does not change that.

Our response plan

Hit by PEAR ransomware? What to do

  1. Containment and evidence preservation

    Disable the implicated VPN and remote-access accounts and block suspicious egress, but do not rush to reimage or clean hosts. Image or snapshot file servers, database hosts, domain controllers and any endpoint carrying a remote management agent first, and export firewall, proxy and VPN flow logs, Active Directory and endpoint logs, and session records from the RMM tooling. Preserve the extortion email in full with headers, the Tox conversation, and the file listing the actor supplied as proof.

  2. Intrusion confirmation and actor identification

    Verify the actor is really PEAR by matching the contact pattern (onionmail.org mailbox, Tox, pear-prefixed onion sites), the content of the proof archive and the leak-site listing, ruling out someone borrowing the name. In parallel, check whether an encryptor is also present - theft-only access is routinely resold, and two crews in one environment is a real scenario. Reconstruct when the RMM agent was installed, the PsExec and PowerShell execution chain and the lateral path, and establish whether entry came from stolen credentials or phishing.

  3. Exfiltration scoping and compliance impact

    Using flow logs, file access auditing and staging artefacts, scope the read and exfiltrated data system by system with volumes and a timeline, delivered as a written inventory. Grade the findings by category - personal information, health and financial records, trade secrets - determine reporting and notification duties under PIPL and the Data Security Law along with any overseas obligations, and produce material usable directly for internal escalation, regulator contact and customer notification.

  4. Persistence removal and credential reset

    Uninstall every unapproved remote management agent along with its services and autorun entries, and clear rogue accounts, scheduled tasks and backdoor configuration. Rotate all credentials confirmed or suspected to fall inside the exfiltration scope: domain and local administrator passwords, VPN and mail accounts, API keys, certificates, database and service accounts. Enforce MFA on the critical entry points, close internet-facing RDP and management ports, reinstall endpoint protection, and restore audit log retention and forwarding.

  5. Attribution, hardening and monitoring handover

    Deliver a full incident report covering the entry point, dwell time, exfiltration timeline and volume, and the compliance determination. Set hardening priorities from the gaps this case actually exposed - MFA on VPN, an allow-list and approval process for remote management software, alerting on large outbound transfers, access auditing on file servers and databases, and centralised log retention. Stand up ongoing monitoring of the leak site and criminal forums for redistribution, plus early warning for impersonation phishing and payment fraud, and close out against a formal handover checklist.

Risk warning

What not to do

  • Do not treat the incident as minor because files are intact and systems are running - PEAR's entire impact is data exposure, and the cost surfaces in notification and legal exposure rather than downtime.
  • Do not rush to reimage hosts, clean systems or let logs roll over. Flow and audit logs are the only basis for scoping the exfiltration; once overwritten the scope cannot be bounded and the compliance assessment loses its foundation.
  • Do not reply to the extortion email, add the actor on Tox or pay on your own. The operators already hold a copy; payment buys neither verifiable deletion nor protection against resale and repeat extortion.
  • Do not open the supplied proof-of-data files on a normal workstation - inspect them in an isolated environment to avoid second-stage malware and contaminated evidence.
  • Do not declare the case closed after removing a single remote management agent; PEAR usually keeps multiple channels, and such access is routinely resold to crews that do deploy encryptors.
  • Do not restore external access before credential rotation is complete, especially VPN without MFA and internet-facing RDP - that is how the intrusion started.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

PEAR Frequently asked questions

  • Does PEAR encrypt files? Our extensions are unchanged - were we still hit?

    It does not. In all publicly documented cases PEAR deploys no encryptor: filenames, extensions and contents are untouched and shadow copies and backups are left alone - which is exactly why the incident gets underestimated. Intact files plus an extortion message signed PEAR means the intrusion already happened and exfiltration is most likely complete. The evidence lives in flow and audit logs, not in file state: a burst of outbound transfer, a remote management agent that appeared without approval, disabled endpoint protection, cleared logs. Preserve the logs and scope the loss before cleaning any host.

  • Is there a free PEAR decryptor?

    No, and none is needed - without encryption there is nothing to decrypt, so No More Ransom and vendor toolkits carry no PEAR decryptor. Anything advertised online as a "PEAR decryption tool" should be assumed to be a scam or second-stage malware and never run in production. If encrypted files genuinely exist in your environment, a second ransomware family is probably also present (access from theft-only crews is frequently resold); sample and identify that family separately, then assess its decryptability on its own merits.

  • What does PEAR do with our data if we do not pay?

    The observed pattern: the company name and sample data go up on the leak site with a deadline, publication proceeds in stages once it passes, and for victims who refuse outright the full archive is posted for free download. One US medical billing provider had an archive the group put at roughly 3.3 TB released this way, and subsequently notified about 1.26 million individuals. Paying does not resolve it either - the operators keep a copy that can be resold or recycled by other crews for repeat extortion. We do not pay or negotiate; the higher-value work is scoping the loss quickly, meeting notification obligations and rotating credentials.

  • How does PEAR get in, and where should we look first?

    The primary vector is stolen VPN or remote-access credentials sourced from third-party breach corpora, credential stuffing and password reuse - VPN without MFA and internet-facing RDP in particular - with phishing as a supplement. Once inside, the crew installs legitimate remote management software such as AteraAgent or Splashtop for persistence, moves laterally with PsExec and PowerShell, and exfiltrates in batches using WinSCP and RClone, frequently renamed. Investigate in this order: anomalous VPN and RDP logins (unusual geography, odd hours, dormant accounts reactivated), then unapproved remote management agents across endpoints and servers, then large outbound transfers, then the timestamps where endpoint protection was disabled and logs were cleared.

  • Does PEAR target Chinese organisations? Should we be concerned?

    Around 90% of the victims on the public leak site are US-based, and no public report documents a PEAR campaign against mainland China organisations. Two points still matter. First, overseas subsidiaries, cross-border entities and US, Canadian, Australian and New Zealand partners of Chinese groups already sit inside its target space. Second, the entry points it depends on (VPN without MFA, exposed RDP, password reuse) and the tradecraft it uses (abusing legitimate remote management tools, WinSCP and RClone for exfiltration) are just as common locally, and other theft-only crews reuse the same playbook. Treating this actor as a test case for your own remote-access and egress controls is more useful than tracking the brand name.