C0015 is a ransomware intrusion campaign characterized by post-compromise file discovery, cloud-based data exfiltration, and living-off-the-land execution. Operators conducted file listing discovery across multiple hosts to verify that locker encryption had succeeded, indicating hands-on post-encryption validation activity. The campaign also involved exfiltration of files and sensitive data to MEGA using Rclone, demonstrating pre- or parallel-impact data theft consistent with extortion-oriented ransomware tradecraft. For execution, the actors used code that leveraged regsvr32, aligning with common abuse of signed Windows utilities to launch malicious components while blending with legitimate system activity. High-confidence observed behaviors for this campaign include file and directory discovery, data exfiltration to cloud storage, and regsvr32-based execution. Attribution to a specific named threat actor or country is not supported by the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used regsvr32 for execution during the activity cluster operation.
Exfiltrated files and sensitive data to MEGA using Rclone.
Activity cluster conducted file listing discovery across multiple hosts to verify locker encryption success.
Exfiltration of files and sensitive data to MEGA using Rclone.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.