GoodWill is a ransomware actor publicly noted in 2022 for an unusual extortion model that replaced conventional payment demands with coercive charitable and social tasks. The group demanded that victims perform charitable acts and publish video evidence, positioning its operation with quasi-hacktivist or moralistic rhetoric rather than standard profit-driven messaging. GoodWill is associated with ransomware-based coercion, but there are no high-confidence publicly confirmed victims directly attributed to this strain in the supplied facts. Its known tradecraft in the available reporting is limited primarily to extortion behavior and the use of reputational pressure through compelled public acts, rather than a well-documented broader intrusion lifecycle or established sub-groups and aliases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.