Ethical Side Group (ESG) is the name used by a threat actor involved in follow-on extortion operations against organizations previously victimized by ransomware. Beginning in October 2023, the actor contacted victims of Royal and Akira incidents and impersonated a security researcher or helpful intermediary, claiming to have gained access to infrastructure used by the original ransomware operators and offering, for a comparatively small payment, to delete or otherwise provide access to exfiltrated victim data. Reported communications under the names Ethical Side Group (ESG) and xanonymoux showed strong stylistic and behavioral overlap, supporting an assessment that they were likely the same actor or closely related operators. The actor’s tradecraft centered on post-incident extortion rather than initial compromise. In observed cases, the operator claimed access to stolen data, offered proof of that access, communicated via Tox, and used external file-sharing services to demonstrate possession of victim information. The actor also attempted to increase pressure by warning of future attacks if security issues were not addressed. Payment demands were relatively low compared with primary ransomware extortion demands, indicating an opportunistic monetization model focused on exploiting uncertainty after an earlier intrusion. Available reporting does not establish whether Ethical Side Group was formally sanctioned by, affiliated with, or acting independently from the original ransomware operators behind Royal or Akira incidents. The activity is best characterized as financially motivated follow-on extortion leveraging prior ransomware intrusions and the residual fear associated with data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.