MoneyMessage, also known as Money Message, is a financially motivated ransomware and extortion operation first identified in March 2023. The group conducts double-extortion attacks, stealing data and threatening public disclosure through a dedicated leak site while deploying ransomware to encrypt victim environments. Its ransomware is written in C++ and uses Elliptic Curve Diffie-Hellman key exchange and the ChaCha stream cipher. MoneyMessage has targeted organizations in healthcare, energy, transportation and logistics, nonprofit human services, and professional services. Its March 2023 compromise of U.S. pharmacy-services provider PharMerica was associated with the exposure of sensitive patient information and subsequently affected approximately 5.8 million individuals according to breach-related litigation and settlement proceedings. MoneyMessage claimed responsibility for that incident, asserted that it exfiltrated a large volume of data, and published data on its leak site. Observed MoneyMessage activity includes deploying its encryptor to multiple hosts through a network-accessible Windows directory and using PowerShell to uninstall endpoint security and EDR products. These behaviors demonstrate ransomware deployment at scale, data exfiltration and extortion, and defense evasion. No high-confidence public attribution establishes the operation's country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against U.S. Electrical Services and Wiedenbach Brown in the Energy & Utilities sector.
Conducted a ransomware attack against ProCare, a U.S. healthcare-sector organization.
Conducting a ransomware attack against Yourway Transportation.
Conducting a ransomware attack against Indigo Energy.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.