Cyber Threat Actor: Pear
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
5 incidents |
|---|
Profile
Pear is a ransomware group that has been referenced in open‑source threat intelligence under the alias Pear. The group first appeared in public leak‑site listings on 2026‑06‑10, as recorded by the ransomware.live platform. At that time the platform listed several recent victims attributed to Pear. No additional background on the group’s origins, affiliations, or operational history is provided in the source material.
One entry described Bayou Electrical Services as a victim of Pear, noting that the leak‑site listing contained no screenshot, no link to the company website, and no indication of infostealer data having been found. A second entry recorded K & E Distributing as a target, stating that the listing was marked as AI‑generated and offered no further details such as leak size or ransom amount. A third entry showed Alpha IT on the same list, with the entry explicitly noting that no further details were available beyond the victim name. A fourth entry concerned the National Health Fund, which was also marked as AI‑generated and included a note that the name is generic and used by multiple organizations. Across all four entries the platform displayed no icons for screenshots, website links, infostealer data, victim denial, known ransom amounts, disclosed leak sizes, duplicate claims, or press coverage. The ransomware.live service, sponsored by Hudson Rock, uses icons to convey the presence of such information, and their absence indicates a lack of publicly corroborated details for these incidents.
Based solely on the information available from these listings, no specific targeting patterns, sectors, or geographic regions can be attributed to Pear. Likewise, the source material does not describe any particular malware families, initial access vectors, or tooling styles associated with the group. No public attributions to state actors, criminal consortia, or other threat‑actor alliances have been made for Pear. Consequently, any discussion of notable campaigns or representative operations beyond the four victim names listed on 2026‑06‑10 would be speculative and is omitted here. The profile therefore reflects only the confirmed observations that Pear is a ransomware alias appearing in a leak‑site feed on that date with the four named victims.
