Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Nullbulge

Also known as: LockBit Black

Description

NullBulge is a cybercriminal threat group targeting AI and gaming focused entities. They weaponize code in publicly available repositories to distribute malware, including LockBit ransomware. The group claims to be motivated by a pro-art, anti-AI cause, but their activities indicate a financial focus. NullBulge uses obfuscated code in public repositories and malicious mods to target their victims.

Goals & Targeting

Targeted Sectors

Gaming
Financial services
Media
Defense
Government
Critical infrastructure

Targeted Countries / Regions

US
GB

AI Analysis

· 2 weeks ago

Executive Summary

NullBulge is a cybercriminal threat group targeting AI and gaming sectors, utilizing publicly available code repositories to distribute malware, including LockBit ransomware. Despite claiming anti-AI motivations, their activities suggest a financial focus.

Goals & Targeting

NullBulge targets AI and gaming sectors likely due to the high value of intellectual property and potential for financial gain. Their victims typically include businesses in these industries, potentially globally, reflecting a broad targeting strategy aimed at maximizing opportunities for ransom payments.

Enhanced Description

NullBulge emerges as a cybercriminal entity focusing on the AI and gaming industries, exploiting publicly accessible software repositories to deploy malicious payloads such as LockBit ransomware. Their operations highlight a unique blend of targeting sectors at the forefront of technology innovation while employing sophisticated tactics to disseminate malware. The group's claimed motivations, which include pro-art and anti-AI sentiments, remain ambiguous, with their actual activities indicating a primary focus on financial gain through ransomware activity.

Key Capabilities

  • Weaponization of code from publicly available repositories
  • Distribution of LockBit ransomware
  • Use of malicious gaming mods to deliver malware
  • Obfuscation techniques to hide malicious activities

Software / Tooling

LockBit Ransomware

Campaigns & Victims

NullBulge has conducted multiple campaigns targeting AI companies and gaming firms, often leveraging their access to public repositories. Their operational tempo appears focused on quick deployment of ransomware for financial gain. Notable past operations include incidents against unspecified targets in the gaming sector using malicious mods. The group's long-term goals remain unclear but seem to center around maximizing immediate financial returns.

IOC Patterns

  • Weaponized code from public software repositories
  • Distribution via malicious gaming mods or updates
  • Obfuscated malware payloads targeting AI and gaming industries

Recommended Actions

  • Monitor third-party software repositories for signs of malicious activity
  • Enhance supply chain security to detect potential compromisings of public repositories
  • Educate employees on the risks of downloading non-official gaming mods or updates
  • Implement rigorous network monitoring for signs of obfuscated malware activity

Suggested Tags

Cybercriminal
Ransomware
Gaming Sector
AI Sector
Malware Distribution

Confidence Assessment

The confidence level in the data surrounding NullBulge is moderate. Their activities and modus operandi are partially understood, but key details such as specific TTPs, long-term strategic goals, and geographic targeting remain underdocumented due to limited reporting from law enforcement or victim disclosures.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 6 Domain 7 Filename 7

References

  1. www.sentinelone.com — Cited by web research for: LockBit Black
  2. www.sentinelone.com — Cited by web research for: T1490
  3. attack.mitre.org — Cited by web research for: T1213.001
  4. www.cyber.gc.ca — Cited by web research for: Phishing emails
  5. www.infosecurity-magazine.com — Cited by web research for: UK

Intel Summary

8

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

2

Tactics

Tags

Ransomware
Cybercriminal
Gaming Sector
AI Sector
Malware Distribution

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.