Attribution
Unattributed financially motivated ransomware operation. Group-IB identified overlapping infrastructure and shared contact email addresses linking Brain Cipher to the EstateRansomware, SenSayQ and RebornRansomware operations, suggesting a shared operator or affiliate cluster that rebrands rather than a distinct nation-state or named APT. No confirmed geographic origin.
First seen
June 2024 (first public samples/notes June 16, 2024; Group-IB assesses activity since at least April 2024)
Last active
2026 (leak-site aggregators recorded new victim postings through mid-2026)
Motivation
Financial (double-extortion ransomware: data theft followed by encryption, with a Tor data-leak site used to pressure victims into paying).
Attribution confidence
medium
Sectors
Retail, professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE (Retail, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.