Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor. However, the lack of some of REvil's obfuscation features led researchers to believe that it may have been created by a former core member of the operation...
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation used to target organizations, steal victim data, encrypt systems, and demand payment in exchange for decryption keys or a promise not to publish stolen information.
A ransomware-as-a-service operation run by Maksim Silnikau that provided locking software, used stolen credentials bought from initial access brokers, and operated a hidden affiliate panel for monitoring attacks, negotiating with victims, and splitting proceeds.
A ransomware-as-a-service operation used to encrypt victims' computers, steal corporate data, extort victims for decryption keys or non-leak promises, and manage affiliate attacks through a dedicated portal.
Ransomware-as-a-Service (RaaS) operation involved in extortion and data encryption attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.