OldGremlin is a Russian-speaking cybercriminal ransomware and extortion group known for targeting organizations in Russia, an unusual victimology for a Russian-language financially motivated actor. The group emerged in 2020 and has conducted repeated phishing-led intrusions against Russian companies, including health care, financial, and industrial organizations, with renewed activity against large domestic industrial enterprises in 2025. OldGremlin has also been referred to in plural form as OldGremlins. OldGremlin commonly gains initial access through spearphishing campaigns that impersonate trusted organizations and exploit topical themes to increase credibility. Reported lures have included media outreach, COVID-19-related messaging, and regional political events. In documented operations, the group used custom malware including TinyNode, TinyPosh, and the TinyCryptor ransomware, and also leveraged Cobalt Strike during post-exploitation. Observed behavior includes establishing persistence, downloading additional payloads, reconnaissance, credential theft, lateral movement via remote administration and file-sharing mechanisms, creation of fallback privileged accounts, backup destruction, and broad ransomware deployment across enterprise networks. The group’s operations indicate a mature intrusion lifecycle oriented toward monetization through encryption and extortion. In one well-documented case, OldGremlin compromised a large Russian medical company, maintained access for weeks, obtained domain-level privileges, wiped backups, and then encrypted hundreds of systems across the corporate network. OldGremlin has been associated with high ransom demands and, by 2025, renewed extortion campaigns against Russian industrial enterprises reportedly incorporated techniques such as bring-your-own-vulnerable-driver to disable security controls and Node.js-based script execution. The actor’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware attacks, including a high-value attack against Russian logistics company Sotrans.
Conducting multistage targeted ransomware and spearphishing attacks against Russian organizations, including banks, industrial enterprises, medical organizations, and software developers, using custom malware and post-exploitation tooling before deploying ransomware.
OldGremlin is conducting extortion attacks against Russian industrial enterprises using phishing emails, BYOVD techniques to disable security solutions, and legitimate Node.js interpreter for malicious script execution.
OldGremlins is a ransomware group that has resurfaced and is conducting new attacks targeting Russian companies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.