PARINACOTA is a financially motivated cybercriminal threat actor tracked for human-operated ransomware intrusions, most notably associated with deployment of the Wadhrama ransomware. The group has been observed conducting rapid, hands-on-keyboard compromises that often move from initial access to ransom deployment in less than an hour, while also maintaining some compromised systems for extended periods and repurposing them for additional criminal activity. PARINACOTA commonly gains initial access by brute-forcing internet-exposed Remote Desktop Protocol services. After compromise, the actor performs reconnaissance, disables or stops security-related services, clears event logs, and downloads additional tooling. Observed post-compromise activity includes credential dumping from LSASS, privilege escalation to SYSTEM, persistence through enabling remote access and creating new local administrator accounts, and lateral movement using common administrative and scanning tools. The actor has also used malicious autostart mechanisms to launch ransomware and has deleted backups and stopped services to facilitate encryption. Beyond ransomware, PARINACOTA has demonstrated opportunistic monetization by using compromised hosts for cryptocurrency mining, spam operations, and proxying or scanning activity. The group is notable for adaptive tradecraft and repeated reuse of compromised infrastructure to support further intrusions. Reported ransom demands have been made on a per-machine basis. PARINACOTA is best characterized as an opportunistic, high-tempo ransomware actor focused on rapid monetization through exposed remote access services and follow-on post-exploitation activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.