Dark Web Shocker: Ransomware Group “Pear” Strikes Two US Firms in One Night!

Listen to this Post

Featured Image

A Cyber Nightmare Unfolds

In a chilling development that underscores the rising threat of cybercrime in 2025, the notorious ransomware gang known as “Pear” has launched two successful attacks within minutes of each other. According to reports from the ThreatMon Threat Intelligence Team, Garrison Law Firm and Preferred Homes Realty have both been added to the victim list of the Pear ransomware group. The group reportedly posted the attacks on the dark web, highlighting its ongoing campaign against U.S.-based organizations.

⚠️ Two Attacks in Minutes: A Disturbing Timeline

Garrison Law Firm, a U.S. legal service provider, was targeted first at 21:30:58 UTC +3 on August 5, 2025. Just seven minutes later, Preferred Homes Realty also fell victim to the same cybercriminal gang.

The attacks were detected and reported by ThreatMon’s intelligence monitoring team, who track dark web chatter and underground ransomware activity. According to their posts on X (formerly Twitter), both incidents have been verified as part of Pear’s expanding list of victims.

🎯 Pear Ransomware Group: Who Are They Targeting?

Pear has been increasingly active on the dark web, operating with the usual tactics of double extortion—stealing data before encrypting it and threatening to leak the information if ransom demands aren’t met. Their victim selection is not random; instead, they appear to be focusing on small to mid-sized U.S. businesses, particularly those in law and real estate—sectors that often lack advanced cybersecurity infrastructures.

What Undercode Say: 🔍 Deeper Analysis on the Pear Ransomware Attacks

🧠 Understanding Pear’s Modus Operandi

Pear is believed to be a relatively new but rapidly evolving ransomware-as-a-service (RaaS) group. The group uses sophisticated encryption methods and operates via dark web portals where stolen data is advertised or auctioned if victims don’t comply. The speed and timing of these two attacks suggest an automated deployment mechanism—possibly exploiting similar vulnerabilities across industries.

🔓 Why Law and Realty Firms?

These sectors typically handle confidential data—legal documents, personal identification, financial records—but often have weaker digital defenses than larger corporations. The selection of Garrison Law Firm and Preferred Homes Realty signals a focused campaign on high-value, low-security targets.

💥 Economic and Legal Fallout

The cost of ransomware attacks has soared in 2025. Victims like Garrison and Preferred Homes may face not only data loss but also legal consequences, regulatory fines, and loss of client trust. On average, ransomware recovery in the U.S. now exceeds \$1.8 million USD per incident, factoring in downtime, recovery, and potential ransoms.

📉 Reputational Damage & Client Loss

For law firms, trust is their currency. A ransomware breach can ruin a firm’s reputation overnight. Similarly, realty firms dealing with mortgage info and private client files can lose market credibility and face lawsuits from clients whose data has been exposed.

🔁 The RaaS Model & Future Proliferation

Pear appears to be operating under the Ransomware-as-a-Service (RaaS) model. This allows cybercriminals with little technical know-how to rent Pear’s software and launch attacks. This model is accelerating the frequency of ransomware events, especially against SMBs.

🔐 Lessons for the Industry

Both industries must urgently invest in:

Endpoint detection and response (EDR) solutions

Employee phishing awareness

24/7 dark web monitoring

Zero-trust security architectures

🌐 Global Implications

Although this attack was U.S.-based, Pear’s reach is expected to grow. Experts believe that global real estate and legal networks could be next, particularly in Europe and the Middle East.

✅ Fact Checker Results

✅ Verified: Garrison Law Firm and Preferred Homes Realty were listed as victims by ThreatMon.
✅ Confirmed: The attack times and sequence were published directly on the ThreatMon X account.
❌ Not Confirmed: No ransom amount or negotiation details have been released at this time.

🔮 Prediction: What Comes Next?

Pear is not slowing down. With two attacks in seven minutes, we expect their next wave to target healthcare clinics and financial consultants—sectors with sensitive data but minimal cybersecurity maturity. Expect an increase in multi-victim hits and more activity surfacing on the dark web in the coming weeks.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: x.com
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon