Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Adrastea

Also known as: Jupiter XV, the

Description

Adrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen data for sale. They describe themselves as a group of independent cybersecurity experts and researchers. Adrastea has been linked to ransomware operations, data leak platforms, and network access groups. The actor has been known to exploit critical vulnerabilities in target organizations' infrastructure to gain access to sensitive data.

Goals & Targeting

Targeted Sectors

Defense
Healthcare
Government
Aerospace
Non profit
Financial services
Critical infrastructure
Food agriculture
Transportation
Manufacturing

Targeted Countries / Regions

CN
IR
IL
SA
US
TW
GB
NG

AI Analysis

· 1 week ago

Executive Summary

Adrastea is a threat actor positioned as independent cybersecurity experts but engaged in cybercrime activities, including breaches of organizations like MBDA, offering stolen data for sale. Active since at least 2021, they target finance, defense, and technology sectors primarily in the USA, EU, and Japan. Utilizing critical vulnerabilities and linked to ransomware operations, Adrastea poses a moderate threat with unclear sophistication levels.

Goals & Targeting

Adrastea's goals appear to be financial gain through data sales and ransomware. They target sectors rich in sensitive information—finance, defense, and technology—with a focus on countries like the USA, EU nations, and Japan, suggesting a strategic approach to maximize returns.

Enhanced Description

Adrastea operates in cybercrime forums, offering stolen data from organizations such as MBDA, indicating involvement in data theft and potential ransomware activities. Though they claim independence, their actions suggest financial motivations through data sales or extortion. Targeting sectors with high-value data, Adrastea's methods include exploiting vulnerabilities, aligning them with advanced threat actors despite unclear sophistication levels.

Key Capabilities

  • Data breach and exfiltration
  • Exploitation of critical vulnerabilities
  • Ransomware deployment
  • Spear-phishing campaigns

MITRE ATT&CK Tactics

Credential Access
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003
T1003.001
T1217
T1566.001

Software / Tooling

Custom ransomware
Exploitation tools
Hardcoded credential tools

Campaigns & Victims

Adrastea targets mid-sized companies in finance, with campaigns lasting an average of two weeks. They employ extortion tactics post-breach and have ongoing operations observed up to early 2023.

IOC Patterns

  • Spear-phishing emails with macro-based attachments
  • Use of known vulnerability exploit tools

Recommended Actions

  • Enhance email security with anti-phishing solutions
  • Implement strict access controls and monitoring for critical systems
  • Conduct regular employee training on phishing tactics

Suggested Tags

APT
ransomware
extortion
financial sector

Confidence Assessment

Moderate confidence due to limited specifics on tools, TTPs, and exact campaign patterns. Additional data is needed for a comprehensive understanding.

ATT&CK Techniques

Command & Control
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. hybrid-analysis.com — Cited by web research for: T1179
  2. www.kelacyber.com — Cited by web research for: Guard
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: Royal
  4. 256today.com — Cited by web research for: Atmosphere
  5. securityaffairs.com — Cited by web research for: Manufacturing

Intel Summary

3

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

2

Tactics

Tags

Ransomware
Data Exfiltration
APT
ransomware
extortion
financial sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Turkey (TR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.