Logo del actor de amenaza Team Underground

Team Underground

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: Underground, TeamUnderground
Ver en IntelTracker → APTTrail →
Team Underground is a ransomware group that emerged in early July 2023, initiating continuous, high-profile attacks across various industries globally. The group re-emerged with an overhauled dedicated leak site in May 2024, confirming its ongoing operations. Their primary motivation is financial gain, achieved through data encryption and a dual-extortion model where they threaten to publish stolen sensitive information if a ransom is not paid. A unique characteristic setting them apart is their peculiar practice of not altering file names or extensions after encryption, making detection challenging for victims. Additionally, the group has been noted for offering assistance in identifying and resolving system vulnerabilities to their victims.

Aliases del actor

UndergroundTeamUnderground

Actores similares

undergroundactor · 1Ransomware Group: undergroundactor · 1auditteamactor · 16audit-teamactor · 3apt-1877teamactor · 1apt-hackingteamactor · 1AuditTeamactor · 1aztroteamransomware · 1fsteamransomware · 1malekteamransomware · 1
Tecnicas MITRE
T1021.002, T1059.003, T1018, T1105
CVEs relacionadas
CVE-2023-36884

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
78
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBrazilCanadaChinaGermanyEgyptSpainFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesHospitalsManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationOil & GasEducational ServicesWholesale Trade