The Rainmaker is a Brazilian hacker group associated with the initial sale and distribution of the Philadelphia ransomware family as a ransomware-as-a-service offering in 2016. The group is identified as the author and early distributor of Philadelphia, a Windows ransomware strain written in AutoIt and designed for cryptoviral extortion through file encryption and ransom demands. Philadelphia was marketed through spam-driven promotion and online criminal forums, lowering the barrier to entry for less-skilled operators by packaging ransomware capabilities as a service. Operations linked to The Rainmaker are tied to financially motivated ransomware activity rather than espionage. The group’s tooling supported initial access through malicious email attachments, compromised websites, macros, and trojanized downloads, followed by encryption of victim files and extortion. Philadelphia also incorporated pressure tactics such as gradual file deletion and included an unusual attacker-controlled “mercy” feature that allowed free decryption at the operator’s discretion. Reporting on Philadelphia has also linked its use to spear-phishing campaigns against hospitals and other healthcare targets. The Rainmaker is also referenced as The Rainmaker (Brazilian hacker group).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazilian ransomware vendor/group that sold the Philadelphia ransomware as-a-service and promoted it via spam campaigns and online forums; associated with the Stampado ransomware family/ecosystem.
Brazilian ransomware vendor/group that sold the Philadelphia encrypting ransomware as-a-service starting in September 2016, promoting it via spam campaigns and online forums; associated with the Stampado ransomware family/ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.