Frag is a ransomware operation first observed in 2024 and associated with double-extortion activity, including the theft of victim data prior to encryption. Reporting links the group to attacks against organizations in industrial and other enterprise sectors, and to exploitation of Veeam Backup & Replication remote code execution vulnerabilities, notably CVE-2024-40711, to gain access and deploy ransomware. Frag has been cited alongside other ransomware actors that target backup infrastructure in order to facilitate lateral movement, data theft, and the destruction of backups to impede recovery. The group is also referenced as Frag ransomware operators and has been assessed as potentially connected to, or rebranded as, Booba Team. Blockchain-analysis reporting has further noted shared laundering infrastructure between Frag, Akira, and Fog, suggesting operational or ecosystem overlap, although the precise nature of those relationships is not fully established. High-confidence reporting supports characterizing Frag as a financially motivated ransomware threat actor focused on enterprise compromise, extortion, and abuse of exposed or vulnerable backup environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier ransomware group referenced as the predecessor identity for Booba Team.
Associated with exploitation of Veeam Backup & Replication vulnerabilities in ransomware operations.
Named as one of several ransomware operations weaponizing a critical Veeam Backup & Replication RCE flaw in attacks.
Referenced as a ransomware group operationally linked to Akira through shared laundering infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.