Team Underground is ransomware reportedly used by the Russia-linked, Russian-speaking threat group Nebulous Mantis, which is also tracked as Cuba, STORM-0978, Tropical Scorpius, and UNC2596. According to the provided reporting, the group deploys Team Underground from July 2023 onward as part of a broader pattern of using ransomware to obscure espionage and data-theft operations after exfiltration. The same reporting states the group previously used Cuba ransomware and later Industrial Spy before shifting to Team Underground, and that Team Underground shares leak sites with those earlier campaigns.
In the described operations, Team Underground is not presented as the initial access malware. Instead, intrusions commonly begin with spear-phishing lures, including fake document or OneDrive-themed download pages, that deliver RomCom RAT. RomCom-enabled compromises involve staged payload delivery, encrypted command-and-control, persistence via registry manipulation or COM hijacking, anti-sandbox and time-zone checks, credential harvesting, host and network reconnaissance, Active Directory/domain enumeration, use of tools such as WinRAR and Plink, and staging of compressed data for exfiltration, including from locations such as C:\Users\Public\Music. After exfiltration, the operators reportedly deploy ransomware, including Team Underground, to provide cover for the theft activity.
High-confidence associations in the provided content tie Team Underground to Nebulous Mantis espionage-and-ransomware operations targeting government entities, critical infrastructure, political figures, and NATO-related defense sectors since 2019. No standalone technical details, encryption behavior, file extensions, ransom note names, or direct indicators of compromise specific to Team Underground itself are provided beyond its use by this actor beginning in July 2023 and its shared leak-site relationship with prior campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Their ransomware arsenal evolved over time: ... Team Underground (since July 2023)..."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used by the group since mid-2023; reported to share leak-site infrastructure with prior campaigns.
Ransomware adopted by Nebulous Mantis starting July 2023, deployed after data theft to encrypt systems and demand ransom.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.