Financially motivated ransomware-as-a-service (RaaS) operation of unconfirmed nationality. Operators are believed to be Russian-speaking cybercriminals; the group's rules reportedly prohibited affiliates from targeting CIS countries, Cuba, North Korea, and China, a convention common among Russia-nexus RaaS crews. No confirmed state sponsorship. Attribution to a specific individual or country is unproven.
First seen
2024-02
Last active
2025-04
Motivation
Financial gain via double-extortion (data encryption plus exfiltration and threatened leak on a Tor data-leak site).
Attribution confidence
medium
MENA targeting
UAE, Saudi Arabia, Egypt, Lebanon
Sectors
Manufacturing, energy/utilities, government/defense, professional services, technology
Corpus activity · 6mo1 mention
AMJJAS
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE, Saudi Arabia, Egypt (Manufacturing, energy/utilities, government/defense sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
ESET (Mar 2025): EDRKillShifter BYOVD EDR killer deployed by RansomHub affiliates (e.g. QuadSwitcher); Group-IB: PCHunter used to terminate EDR before ransomware drop; CISA: WMI used to disable antivirus
CISA: escalation to SYSTEM incl. CVE-2020-0787; Group-IB: CVE-2021-42278 sAMAccountName spoofing and CVE-2020-1472 ZeroLogon to seize domain controllers; ESET: EDRKillShifter abuses vulnerable drivers (rentdrv2.sys, TFSysMon) via BYOVD
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside RansomHub's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 13 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1562significantAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1219significantConditional AccessT1110significantID ProtectionT1098significantID ProtectionT1110partialIdentity Secure ScoreT1110partialMultifactor AuthenticationT1098minimalMultifactor AuthenticationT1110significantMultifactor AuthenticationT1566partialPrivileged Identity ManagementT1098significantPrivileged Identity ManagementT1136partialPasswordless AuthenticationT1110significantPassword PolicyT1110partialPassword ProtectionT1110partialRole Based Access ControlT1059minimalRole Based Access ControlT1098partialRole Based Access ControlT1136minimalRole Based Access ControlT1562minimalAntimalwareT1036significantAntimalwareT1059significantAntimalwareT1059.001significantAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantAudit SolutionsT1562partialInformation ProtectionT1048significantInformation ProtectionT1070significantInformation ProtectionT1070.001significant
detect · 21 techniques
Adaptive Application Control IntegrationT1036partialAdvanced Anti-Phishing T1566partialApp GovernanceT1110significantApp GovernanceT1562significantApp GovernanceT1566significantAdvanced Threat HuntingT1048significantAdvanced Threat HuntingT1110significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1566significantDefender for Cloud AppsT1098minimalDefender for Cloud AppsT1110partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1219partialDefender for Cloud Apps
respond · 9 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1048significantAutomated Investigation and ResponseT1566significantIncident ResponseT1059minimalIncident ResponseT1098minimalIncident ResponseT1110minimalIncident ResponseT1136minimalIncident ResponseT1562minimalIncident ResponseT1566minimalQuarantine PoliciesT1036significantQuarantine PoliciesT1566significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1566partialZero Hour Auto Purge
Countermeasures · D3FEND
Defensive techniques that counter RansomHub's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.