The ransomware claim involves Qatargas and Tar Company, Iran, which supplies industrial gases and tar products to the petrochemical sector. The threat actor identified is Tengu, with Iran as the impacted country. #Iran
Incident Details
- Victim: Qatargas and Tar Company, Iran
- Country: IR
- Actor: tengu
- Source: http://longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion/blog/9169dd48cabbf3e397e0a7a8e857dcab66598b3c22984607080f4a13b77b51e9/
- Discovered: 2025-10-23 14:55:01.455541
- Published: 2025-10-23 14:54:39.890229
Information
- Ransomware attack targeted Qatargas and Tar Company in Iran.
- Qatargas and Tar Company supplies industrial gas and tar products to the petrochemical sector in Iran and regional markets.
- The threat actor responsible for the attack is Tengu.

Disclaimer: This post is based on public claims made by the ransomware group "tengu". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.