Unattributed financially motivated ransomware operation. Group-IB identified overlapping infrastructure and shared contact email addresses linking Brain Cipher to the EstateRansomware, SenSayQ and RebornRansomware operations, suggesting a shared operator or affiliate cluster that rebrands rather than a distinct nation-state or named APT. No confirmed geographic origin.
First seen
June 2024 (first public samples/notes June 16, 2024; Group-IB assesses activity since at least April 2024)
Last active
2026 (leak-site aggregators recorded new victim postings through mid-2026)
Motivation
Financial (double-extortion ransomware: data theft followed by encryption, with a Tor data-leak site used to pressure victims into paying).
Attribution confidence
medium
MENA targeting
UAE
Sectors
Retail, professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE (Retail, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Payload tampers with/disables Windows Defender and Security Health services (windefend, wdfilter, wdnisdrv, sense, wscsvc); Indonesia PDNS timeline shows Defender deactivation attempts on 17 June 2024 before 20 June deployment.
Encryptor built from the leaked LockBit 3.0 builder enumerates local files and directories to select encryption targets (functionality reported as identical to LockBit 3.0).
Double-extortion model: data stolen before encryption and published on a Tor DLS with countdown timers; exact exfil channel not detailed in public reporting (Group-IB notes data was not actually published for most victims).
LockBit 3.0-builder encryptor: Salsa20 file encryption with RSA-1024-wrapped key, encrypt_filename=true, 7-char name + 9-char extension, ransom note [ext].README.txt / 'How To Restore Your Files.txt'; Linux variant is Babuk-derived.
Extortion demands from ~$20K up to $8M (Indonesia PDNS), Monero payment, Tor negotiation portal keyed by encryption ID and cyberfear.com contact email.
SentinelOne links Brain Cipher intrusions to CVE-2023-28252 (Windows CLFS driver) for local privilege escalation, inherited from LockBit 3.0 tradecraft.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside BrainCipher's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 8 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1562significantAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialConditional AccessT1078minimalIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1566partialPrivileged Identity ManagementT1078minimalPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1078minimalRole Based Access ControlT1562minimalAntimalwareT1027significantAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantAudit SolutionsT1078partialAudit SolutionsT1562partialInformation ProtectionT1070significantInformation ProtectionT1070.001significantInformation ProtectionT1567significant
detect · 13 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1078significantApp GovernanceT1562significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialMicrosoft Defender for IdentityT1021minimalMicrosoft Defender for Identity
respond · 5 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1562minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1566significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1566partialZero Hour Auto PurgeT1027significantZero Hour Auto PurgeT1566significantConditional Access
Countermeasures · D3FEND
Defensive techniques that counter BrainCipher's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.