Grupo Promasa
Attack Intelligence
Grupo Promasa was compromised in a ransomware attack attributed to qilin in October 2025. The organization, operating in the Manufacturing sector in Mexico, was added to the group's data leak site as part of an extortion campaign.
qilin operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Grupo Promasa is a company that operates in the Building Materials industry. It employs 250to499 people and has 10Mto25M of revenue. The company is headquartered in San Pedro Sula, Cortes, Honduras. The amount of downloaded data is unknown at ...
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-0257, which may have been leveraged as initial access vectors or for lateral movement.