The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary1
Who is behind the activity — operator vs. customer.
payload
Capability
Tradecraft, techniques, and tooling the adversary employs.
No techniques or tooling mapped yet.
Infrastructure
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Victim
Targeting — sectors and geographies in scope.
No victimology recorded yet.
Social-political (intent)Financial extortion
Operator ↔ CustomerOperator/affiliate model — the crew runs the intrusion; the RaaS brand and initial-access brokers are upstream parties.
Honesty note
Attribution ≠ confirmation. payload is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.