pear
Intelligence Profile
Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors. We've been monitoring this field for a long-long time. So, we understand all the processes and know well how it all works.
Intelligence Assessment
pear, or Pure Extraction And Ransom (PEAR) Team, is a financially motivated ransomware operation. The group describes itself as a private team with highly responsible and disciplined members, operating independently of other threat actors.
This ransomware operation has tracked 130 victims in total, with 31 new victims in the last 90 days. Its last attack was on 2026-07-08. Top affected sectors include Healthcare, Business Services, and Manufacturing, with the United States, Canada, and Switzerland being the most impacted countries.
With its last attack on 2026-07-08 and 31 new victims in the last 90 days, pear is currently active and demonstrates ongoing victim impact. The group is engaged in an active campaign as of March 2026.
Threat Analysis
pear is a ransomware operation that deploys encryption-based extortion against organizations globally. This group maintains a data leak site (DLS) to pressure victims into paying ransom demands.
Financially motivated threat actors like pear prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.
Ransomware Victims (109)
CTIWATCH tracks 109 organizations claimed as victims by pear on its data leak site, with attack dates, sectors and countries.
View full victims list →Known Campaigns
Pear is conducting an active ransomware campaign targeting organizations across 4 countries. Primary targets: Agriculture and Food Production, Business Services, Healthcare. 11 confirmed victims recorded in the last 45 days. Campaign status: ACTIVE (last activity 30 Jul 2026).