Attribution
Unattributed financially-motivated ransomware-as-a-service (RaaS) operation. No confirmed link to a known named group or nation-state. Some vendor reporting (The Raven File) infers possible Middle Eastern connections based on early victim selection (Qatar, Morocco, UAE), but this is a weak, circumstantial signal and not established attribution. Operational infrastructure observed using Tor onion leak sites, residential proxies (largely India), and VPS providers in Bulgaria and Poland. No confirmed leaked-builder lineage (no reported LockBit, Babuk, or Chaos base).
Motivation
Financial (double extortion: data theft plus encryption, with countdown-timer data-release pressure and, in some cases, publication of ransom negotiation chat logs)