CARDS
CARDS
PEAR (Pure Extraction and Ransom) is a data-extortion threat group that emerged in June 2025, operating with an exfiltration-first model rather than deploying encryption-based ransomware. The group rapidly scaled its operations, focusing on stealing and publicly exposing sensitive data to monetize its efforts through direct extortion, double extortion, and staged data leaks. PEAR distinguishes itself by claiming to be a private, disciplined team with no affiliations to other threat actors, often positioning itself as a security-focused organization that aims to expose vulnerabilities in victims' systems. The group is also known to manipulate victims during negotiations by posing as legitimate penetration testers.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
17 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables1,2
17 IOCs are reported by SOCRadar, but the underlying observable values are not yet retained in IntelliOS. The profile therefore cites the source count without republishing unstored IOC values.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 17 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Pear | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Pear | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/pear | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Pear.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |