Groove was presented in 2021 as a ransomware affiliate program and extortion group active in the Russian-language cybercrime ecosystem. It was announced on the RAMP forum by the persona Orange and publicly positioned as a financially motivated criminal operation involved in industrial espionage. Groove became notable for publishing a large cache of Fortinet VPN credentials and for issuing rhetoric encouraging other extortion actors to target U.S. government interests. Reporting and later actor statements indicate Groove was at minimum heavily intertwined with Babuk-linked operators and the RAMP forum, and may have functioned partly as a deceptive or failed operation rather than a mature ransomware enterprise. High-confidence reporting links the personas Orange and Boriselcin, associated with Groove and RAMP, to Russian national Mikhail Pavlovich Matveev, also known as Wazawaka, with additional aliases including TetyaSluha and Uhodiransomwar. These identities have been tied to the Babuk ransomware ecosystem, and some assessments linked Groove to former Babuk affiliates and possible BlackMatter connections. Intel reporting further assessed that the same actor likely operated both the Groove blog and the RAMP forum. Groove demonstrated capabilities associated with credential theft, data publication, extortion-oriented messaging, and recruitment or affiliate-building activity. Its public behavior included leaking stolen access data, attempting to attract affiliates, and using media manipulation and provocative messaging as part of its operational persona. However, Groove listed only a small number of victims publicly, its infrastructure disappeared within months, and Boriselcin later claimed the group was largely created to mislead journalists and security firms. As a result, Groove is best understood as a Babuk-adjacent, Russia-linked ransomware and extortion brand whose real operational depth remains disputed, but whose dominant posture was financially motivated cybercrime with strong elements of trolling, deception, and information manipulation inside the ransomware scene.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware affiliate program announced by Orange; later described by Boriselcin as largely a pet project intended to mislead media and the security industry.
Presented as a new ransomware/extortion group, called for attacks on U.S. government interests, posted 500,000 Fortinet VPN credentials, and may have been a hoax or failed attempt to launch a ransomware operation intended to troll media and security researchers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.