Also known as: DEV-0829, Nwgen Team
Nwgen is a group that focuses on data exfiltration and ransomware activities. They have been found to share techniques with other threat groups such as Karakurt, Lapsus$, and Yanluowang. Nwgen has been observed carrying out attacks and deploying ransomware, encrypting files and demanding a ransom of $150,000 in Monero cryptocurrency for the decryption software.
Executive Summary
Storm-0829, also known as DEV-0829 and Nwgen Team, is a cyber threat actor group primarily involved in data exfiltration and ransomware activities. The group shares operational techniques with other prominent groups such as Karakurt, Lapsus$, and Yanluowang. Storm-0829 has been observed deploying ransomware to encrypt victim systems and demanding cryptocurrency ransoms for decryption keys. This group poses a significant threat to organizations handling sensitive data across multiple sectors.
Goals & Targeting
Storm-0829's strategic objectives appear to focus on financial gain through ransomware operations and data theft for potential sale or extortion. The group targets organizations in sectors with high data sensitivity and ransom-paying propensity, such as healthcare, finance, education, and government entities. Their targeting profile suggests a geographic focus on countries with mature cybersecurity defenses but weaker incident response capabilities, allowing for higher success rates in extorting payments.
Enhanced Description
Storm-0829, or Nwgen Team, is a cybercriminal group specializing in data exfiltration and ransomware deployment. The group has been linked to other notable threat actors, including Karakurt, Lapsus$, and Yanluowang, indicating potential collaboration or shared战术、技术与_procs (TTPs). Storm-0829's primary modus operandi involves compromising victim networks, exfiltrating sensitive data, and deploying ransomware to disrupt operations and extort payment. The group typically demands $150,000 in Monero cryptocurrency for decryption keys, targeting sectors with high-value assets such as healthcare, finance, and education. Their operational approach suggests a mid-tier sophistication level, leveraging off-the-shelf tools and customized scripts for their attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0829 has been observed conducting targeted campaigns against organizations in the healthcare and financial sectors. Their attacks typically involve initial phishing or social engineering to gain access, followed by lateral movement across networks to identify and encrypt sensitive data. Notable past operations include a series of ransomware incidents targeting European hospitals in 2023, leading to significant disruption of patient care. The group's operational tempo is较高, with frequent small campaigns rather than large-scale attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the available data about Storm-0829 due to limited public reporting and lack of specific campaign details. The group's connection to other known threat actors provides some context, but further analysis is needed to fully understand their capabilities and infrastructure.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics