Unattributed to any nation-state or named individual. Multiple vendors (Bitdefender, Hudson Rock, SOCRadar) assess the operation is run by affiliates drawn from the English-speaking 'Com' cybercriminal ecosystem, citing overlaps with ShinyHunters, Scattered Spider and Lapsus$ tradecraft (credential/infostealer-driven access, social engineering, pure data extortion). These links are analytic overlaps, not confirmed identity. Despite the name, no reporting establishes any affiliation with Coinbase the cryptocurrency exchange or with the 2025 Coinbase insider data-breach extortion incident; the 'Coinbase' branding appears to be psychological/theatrical rather than a real connection.
First seen
2025-09
Last active
2026-04
Motivation
Financial (data-theft extortion). Some researchers note an anomalous single-month cluster of UAE victims that may hint at motives beyond pure financial gain, but this is speculative.
Attribution confidence
medium
MENA targeting
UAE
Sectors
Real estate, financial services, professional services, technology
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE (Real estate, financial services, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
→Propertyfinder / PropSpace CRM - In aucitioin place your bids now !!!target
Observed techniques
7 distinct
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Data is siphoned directly from compromised cloud environments and file-sharing/FTP infrastructure using valid logins, with no encryptor deployed (infostealers.com, Bitdefender).
Bitdefender reports the group uses admin accounts to tamper with log files to reduce detection; Halcyon reports log tampering, syslog-forwarding disablement and mass log truncation.
Pure data-extortion model: victims listed on Tor DLS with active/leaking/leaked statuses, 48h chat window then 10-day Bitcoin deadline, plus a data AUCTIONS page; all sources state no encryption is used (Crocodyli's T1486 listing contradicts every narrative source and is excluded).
Bitdefender, Halcyon and ProvenData report recruitment/bribery of insiders and third-party contractors for access; the leak site advertises a PARTNERSHIPS page soliciting access. Reported, not forensically confirmed.
Primary entry is reuse of employee/contractor credentials harvested by infostealers (RedLine, Lumma, Vidar) against cloud, FTP and file-transfer services; Hudson Rock/infostealers.com and ransomware.live (78.5% of victims with prior stealer exposure) corroborate; Bitdefender adds IAB-sourced and exp
Reported to log in to corporate cloud/SaaS tenants with stolen credentials rather than deploying malware (infostealers.com, Halcyon, ransomware.live/Crocodyli TTP matrix).
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Coinbase Cartel's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 7 techniques
Defender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1078minimalConditional AccessT1078.004significantConditional AccessT1530minimalIdentity Secure ScoreT1078minimalIdentity Secure ScoreT1078.004partialMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1078.004significantMultifactor AuthenticationT1530significantPrivileged Identity ManagementT1078minimalPrivileged Identity ManagementT1078.004partialPasswordless AuthenticationT1078.004significantPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1078minimalRole Based Access ControlT1078.004partialRole Based Access ControlT1199partialRole Based Access ControlT1530partialAudit SolutionsT1078partialAudit SolutionsT1078.004partialAudit SolutionsT1530partialInformation ProtectionT1070significantInformation ProtectionT1567significant
detect · 8 techniques
App GovernanceT1078significantApp GovernanceT1078.004significantApp GovernanceT1199significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1078.004significantAdvanced Threat HuntingT1199significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1078.004partialDefender for Cloud AppsT1530partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialLateral MovementsT1078partialLateral Movements
respond · 4 techniques
Automated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1078.004significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1530minimalQuarantine PoliciesT1530significantConditional AccessT1078minimalConditional AccessT1078.004partialID ProtectionT1078.004significant
Countermeasures · D3FEND
Defensive techniques that counter Coinbase Cartel's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.