Financially motivated cybercriminal collective; no confirmed nation-state or named-individual attribution. Analysts assess operators likely based in the Eastern Europe / Russia region based on language and communications, but this is a low-confidence inference, not confirmed.
First seen
2023-10
Last active
2026-08
Motivation
Financial gain via ransomware extortion and data-leak extortion; residual hacktivist/notoriety motivation carried over from its Anonymous-aligned origins.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Resecurity traced the Sept 2025 MedicSolution (Brazil healthcare) breach to publicly exposed AWS S3 buckets located with an automated crawler; 34GB+/94k files taken - cloud misconfiguration rather than zero-days is a KillSec hallmark.
SOCRadar dark-web profile and Halcyon document RDP brute-forcing / credential stuffing against weak or reused passwords and VPN credential brute-forcing.
Halcyon reports 5-34GB per-incident data transfer to cloud file-sharing services including GoFile, harvested quietly over weeks before extortion; leak-site 'For Sale' listings confirm bulk theft.
Double extortion via Tor leak site with countdown timers, sample leaks and a 'For Sale' data section ($5k-$350k), Monero-only ransom payments, 88/12 affiliate split (SOCRadar, Halcyon, Cyber Express).
RaaS launched June 2024 with a C++ Windows locker (KillSecurity 2.0/3.0, hybrid AES-256 per-victim keys) and an ESXi locker added Nov 2024; affiliates use a Tor panel builder to configure encryptors (Cyber Express, Rapid7, Halcyon).
Halcyon reports shadow-copy deletion via vssadmin.exe and wmic.exe prior to encryption (single-source; consistent with the locker's ransomware behavior).
DDoS was a core pre-ransomware activity; the RaaS roadmap advertised a stresser (DoS) service and DDoS is listed among extortion pressure tactics (Cyber Express, Rapid7, Halcyon).
Kill Security claimed coordinated early exploitation of CrushFTP auth bypass CVE-2025-31161 (Mar-Apr 2025; Huntress confirmed ITW exploitation); SOCRadar/Halcyon cite exploitation of unpatched web servers and internet-facing systems as a primary vector.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside KillSec's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 9 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1219significantDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1078minimalConditional AccessT1110significantConditional AccessT1530minimalID ProtectionT1110partialIdentity Secure ScoreT1078minimalIdentity Secure ScoreT1110partialMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1110significantMultifactor AuthenticationT1530significantMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.001partialPrivileged Identity ManagementT1078minimalPasswordless AuthenticationT1110significantPassword PolicyT1078significantPassword PolicyT1110partialPassword ProtectionT1078partialPassword ProtectionT1110partialRole Based Access ControlT1078minimalRole Based Access ControlT1530partialAntimalwareT1566significantAntimalwareT1566.001significantAnti-PhishingT1566significantAnti-PhishingT1566.001significantAntiSpamT1566significantAntiSpamT1566.001significantAudit SolutionsT1078partialAudit SolutionsT1530partialInformation ProtectionT1567significant
detect · 11 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantApp GovernanceT1078significantApp GovernanceT1110significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1110significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1110partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1219partialDefender for Cloud Apps
respond · 6 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1110minimalIncident ResponseT1530minimalIncident ResponseT1566minimalQuarantine PoliciesT1530significantQuarantine PoliciesT1566significantQuarantine PoliciesT1566.001significant
Countermeasures · D3FEND
Defensive techniques that counter KillSec's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.