Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Brain Cipher is a financially motivated ransomware operation that surfaced publicly in June 2024 and rose to prominence through the crippling attack on Indonesia's temporary National Data Center (Pusat Data Nasional Sementara, PDNS). Its encryptor is built from the leaked LockBit 3.0 (LockBit Black) builder with minor modifications, and the group has also deployed a Babuk-derived variant against ESXi/Linux environments. Brain Cipher practices double extortion, operating a Tor-based data-leak site and negotiation portal, and has been assessed as sharing infrastructure with several related ransomware brands.
Brain Cipher emerged in mid-2024 as one of many operations spawned by leaked ransomware builders. Its Windows encryptor is derived from the leaked LockBit 3.0 (LockBit Black) builder, using Salsa20 for file encryption and RSA to protect the Salsa20 key, with the operators making minor customizations such as encrypting filenames in addition to file contents and appending victim-specific extensions with README-style ransom notes. In at least the Indonesian case the group also deployed a variant of the leaked Babuk ransomware to target VMware ESXi hypervisor/Linux environments, making it a dual-family operation reusing two separate leaked builders.
The group became internationally known on June 20, 2024, when it encrypted Indonesia's temporary National Data Center (PDNS), disrupting roughly 200-210 government services including immigration, passport control and event-permit issuance. Brain Cipher initially demanded USD 8 million but, after significant public and government attention, publicly released a decryptor for the Indonesian victim for free and issued an apology — an unusual move for a ransomware crew. Group-IB later analyzed that free Linux decryptor and confirmed it corresponded to a Babuk-based sample.
Beyond Indonesia, Brain Cipher runs a Tor-based data-leak site (DLS) and negotiation portal for double extortion; early reporting (Group-IB, Aug 2024) showed a small number of listed victims, and by 2025 the group had migrated its negotiation portal to a new server behind a vanity .onion address beginning with 'brain'. Ransomware-tracking aggregators (ransomware.live, RansomLook) have since catalogued dozens of claimed victims across multiple regions. Group-IB also tied Brain Cipher to the EstateRansomware, SenSayQ and RebornRansomware operations through shared infrastructure and email artifacts, consistent with a serial-rebranding affiliate cluster. There is no MITRE ATT&CK group ID assigned to Brain Cipher as of this writing. The operation remained active into 2026 per leak-site trackers.
MENA relevance: The current RaqibCTI UAE country tag on this actor reflects UNVERIFIED leak-site/aggregator claims, not corroborated targeting — ransomware.live lists a small number of UAE-based victim domains (e.g. entries such as ahadandco.com, mbmdubai.com, eworldme.com) and Group-IB's early DLS review noted additional Middle Eastern victims (Israel, Lebanon, Kuwait); all are self-reported extortion-site postings that have not been independently confirmed by primary incident reporting, so the MENA/UAE tag should be treated as an unverified leak-site claim (low confidence) rather than confirmed victimology.
+24 more relationships — see the relationships browser.