Diskstation is a Romanian-based ransomware group disrupted in a Europol-led law enforcement action known as Operation Elicius. The group is known for targeting Synology network-attached storage devices, encrypting victim data, and demanding cryptocurrency ransoms. Reported victims included businesses, non-governmental organizations, and media firms, with activity notably affecting Italy’s Lombardy region. Italian authorities stated that multiple Romanian nationals participated in the operation and identified a suspected primary operator in Bucharest. Diskstation’s operations centered on ransomware-driven extortion rather than broader espionage or influence activity. Its observed tradecraft includes initial access sufficient to compromise exposed or reachable NAS infrastructure, encryption of stored data, and post-compromise extortion through ransom demands. The group’s victimology indicates opportunistic targeting of organizations reliant on NAS appliances for business data storage and continuity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Romanian-based ransomware group targeting Synology NAS devices, encrypting data and demanding ransoms from businesses, NGOs, and media firms.
Ransomware operations targeting Synology NAS devices (data encryption and ransom demands).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.