Team Underground
0 incidentes
0 paises
0 sectores
ransomware RU Ultimo: -
Aliases: Underground, TeamUnderground
Team Underground is a ransomware group that emerged in early July 2023, initiating continuous, high-profile attacks across various industries globally. The group re-emerged with an overhauled dedicated leak site in May 2024, confirming its ongoing operations. Their primary motivation is financial gain, achieved through data encryption and a dual-extortion model where they threaten to publish stolen sensitive information if a ransom is not paid. A unique characteristic setting them apart is their peculiar practice of not altering file names or extensions after encryption, making detection challenging for victims. Additionally, the group has been noted for offering assistance in identifying and resolving system vulnerabilities to their victims.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
Australia
Brazil
Canada
China
Germany
Egypt
Spain
France
United Kingdom
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesHospitalsManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationOil & GasEducational ServicesWholesale Trade