Frag is a financially motivated ransomware operation first observed in March 2024. It has used data-theft-and-encryption double extortion and operated through a dedicated leak site, including public claims involving healthcare entities. Frag has also targeted industrial-sector organizations. In late 2024, operators exploited the Veeam Backup & Replication remote-code-execution vulnerability CVE-2024-40711 to deploy Frag ransomware. Compromising backup infrastructure can support ransomware deployment and obstruct recovery. Frag has been linked with Akira and Fog through shared cryptocurrency-laundering infrastructure, but this does not establish common operational control or origin. Booba Team has been reported as a possible rebrand of Frag, though that relationship is not sufficiently confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier ransomware group referenced as the predecessor identity for Booba Team.
Associated with exploitation of Veeam Backup & Replication vulnerabilities in ransomware operations.
Named as one of several ransomware operations weaponizing a critical Veeam Backup & Replication RCE flaw in attacks.
Referenced as a ransomware group operationally linked to Akira through shared laundering infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.