Unattributed financially-motivated ransomware-as-a-service (RaaS) operation. No confirmed link to a known named group or nation-state. Some vendor reporting (The Raven File) infers possible Middle Eastern connections based on early victim selection (Qatar, Morocco, UAE), but this is a weak, circumstantial signal and not established attribution. Operational infrastructure observed using Tor onion leak sites, residential proxies (largely India), and VPS providers in Bulgaria and Poland. No confirmed leaked-builder lineage (no reported LockBit, Babuk, or Chaos base).
First seen
2025-10-09
Last active
2026-03
Motivation
Financial (double extortion: data theft plus encryption, with countdown-timer data-release pressure and, in some cases, publication of ransom negotiation chat logs)
Attribution confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Healthcare, manufacturing, agriculture/food
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Healthcare, manufacturing, agriculture/food sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Flare: Windows event logs cleared with wevtutil cl; Raven File: self-terminating temporary service created via SCM over RPC to minimise forensic artifacts
Flare/CYFIRMA: living-off-the-land via PowerShell and cmd, incl. Set-MpPreference abuse; NetExec used for remote command execution (sc query | findstr fort) per Raven File
Flare: data staged, compressed and exfiltrated over encrypted channels with Rclone and WinSCP; Raven File: custom StealTENGU/StealTG exfil tools (Windows+Linux), ~450GB hosted across onion storage
Useful?
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
Flare: initial access via valid-account abuse against exposed RDP/VPN endpoints lacking MFA; compromised admin accounts reused for privilege escalation and lateral movement
Flare: Run-key values SystemSecurityMonitor, WraithNet, WindowsSecurityUpdate pointing to temp executables; schtasks.exe also used
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Tengu's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
App GovernanceT1078significantApp GovernanceT1110significantApp GovernanceT1110.001significantApp GovernanceT1562significantAdvanced Threat HuntingT1048significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1110significantAdvanced Threat HuntingT1110.001significantAdvanced Threat HuntingT1562significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1110partialDefender for Cloud AppsT1110.001partialDefender for Cloud AppsT1486partialMicrosoft Defender for Identity
respond · 7 techniques
Automated Investigation and ResponseT1048significantAutomated Investigation and ResponseT1078significantIncident ResponseT1059minimalIncident ResponseT1078minimalIncident ResponseT1110minimalIncident ResponseT1110.001minimalIncident ResponseT1562minimalZero Hour Auto PurgeT1059significantZero Hour Auto PurgeT1059.001significantConditional AccessT1078minimalID ProtectionT1110minimal
Countermeasures · D3FEND
Defensive techniques that counter Tengu's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.