LostTrust is an emerging ransomware and leak-site extortion group that became notably active in 2023. It was observed among the more active ransomware-branded groups in September 2023 and had already published more than 50 victim organizations by that period, indicating a rapid early expansion of its leak-site operations. Reporting also linked a surge in LostTrust victim activity in August 2023 with increased use of the .NET remote access trojan CSHARP-STREAMER, suggesting overlap with broader ransomware intrusion ecosystems. LostTrust has been associated with post-compromise tooling used in ransomware operations, particularly CSHARP-STREAMER, a modular RAT that supports capabilities including keylogging, file transfer, relay functionality for movement into segmented networks, execution of assemblies, and use of administrative and SMB-related modules. Across incidents tied to that tooling, operators relied heavily on PowerShell-based execution and in-memory loading techniques, including AMSI bypass and decrypted payload staging, and used relay functionality to bridge protected network segments. Public reporting has also linked the same malware family to other ransomware ecosystems including Metaencryptor, REvil, and ALPHV, which supports the assessment that LostTrust operated within a shared criminal tooling environment rather than as an isolated actor. LostTrust is best characterized as a financially motivated cybercriminal ransomware actor. High-confidence public information supports its role as a leak-site-based extortion group active during the 2023 ransomware surge, but available corroborated detail on its specific victimology, geographic origin, and whether it consistently deployed file-encrypting ransomware in addition to extortion is limited.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware actor temporally associated with increased CSHARP-STREAMER usage.
Ransomware group reported as an observed incident driver against industrial organizations in Q4 2023; also listed as first observed by Dragos in Q4 2023.
Listed among the top active ransomware groups in September 2023.
Named as a newly observed ransomware group; the article notes it had already posted more than 50 victim organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.