Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors AzzaSec

Also known as: APT43, AzzaSecurity, Double Alliance, Paraodeus Ransomware, From Russia with Love, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Samurai Panda, PLA Navy, APT4, Wisp Team

Description

"AzzaSec emerged from Italy and has positioned itself as a pro‑Palestine hacktivist collective. The actors are known for targeting Israeli or Israel‑aligned entities, while also engaging in ransomware campaigns against global sectors such as government, finance, energy, and telecommunications. In addition to ideological motives, the group operates with a clear financial objective and has been observed collaborating closely with other cybercriminal collections, most notably CyberVolk. The operator distributes ransomware based on a shared AzzaSec codebase that encrypts victims’ files using AES‑256 and wraps its session keys with RSA‑2048. A 5‑hour decryption timer is enforced via a "+time.dat" file in the user’s %AppData%\Roaming directory, while ransom notices are delivered as BMP images dropped into %TEMP%. To impede analysis, AzzaSec terminates MMC.exe and Task Manager before launching its payload. Beyond ransomware, the group supplies a Webshell that allows attackers to upload and download files, perform directory traversal, and harvest environment data. A Python-based stealer targets browser, Discord, gaming, and crypto wallet credentials; harvested information is exfiltrated over Discord channels. The adversary also escalates its influence by threatening other hacktivist communities via Telegram, warning of channel bans if extortion demands are not met."

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Media
Energy
Aerospace
Manufacturing
Transportation
Maritime
Education
Information technology
Healthcare
Think tank
Pharmaceutical
Critical infrastructure
Chemical
Mining
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
IN
GB
JP
DE
KR
IR
RU
SA
IL
TW
UA
FR
CA
AE
TR
AU
KZ
PK
VN
PL
ES
IT
SG
NL
BR
IQ
BY
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

"AzzaSec, a hacktivist-driven ransomware-as-a-service operator with pro-Palestine leanings, merges financial motives with geopolitical attacks, primarily targeting Israel‑linked entities while deploying multi-layered ransomware and credential theft tactics. The group shares a common codebase with affiliates such as CyberVolk, leveraging AES-256/RSA-2048 encryption and a 5-hour ransom timer to maximize impact. Their recent extortion against other hacktivist communities via Telegram demonstrates intra-community tool and resource exploitation."

Goals & Targeting

"AzzaSec’s strategic objectives blend political activism with monetization through ransomware and credential theft. The group actively targets entities linked to Israel as well as a broad array of sectors—including government, defense, finance, energy, telecommunications, media, manufacturing, and healthcare—across dozens of countries. By releasing multi-stage campaigns that combine file encryption, process termination, webshell exploitation, and remote exfiltration channels (Discord, Telegram), the actor seeks to achieve both high-profile geopolitical disruption and substantial financial gain through ransomware payments."

Enhanced Description

Key Capabilities

  • Deploys ransomware built on a shared AzzaSec codebase using AES‑256 file encryption with RSA‑2048 key wrapping and a 5‑hour decryption timer triggered by time.dat in %AppData%\Roaming
  • Drops BMP ransom notes into the %TEMP% directory for victim compliance
  • Terminates MMC.exe and Task Manager to impede investigation (process kill)
  • Deploys a Webshell that enables file upload/download, directory traversal, and environmental data collection
  • Runs a Python stealer harvesting browser, Discord, gaming, and crypto wallet credentials and exfiltrating them over Discord
  • Extorts other hacktivist communities via Telegram threats to block their channels

MITRE ATT&CK Tactics

Execution
Persistence
Defense Evasion
Impact
Exfiltration

ATT&CK Techniques

T1486

Software / Tooling

AzzaSec Ransomware
CyberVolk ransomware
Invisible/Doubleface ransomware
HexaLocker
Parano (Paraodeus Ransomware)
Webshell
Stealer script
Diamond RW
Lockbit
Chaos

Campaigns & Victims

"AzzaSec frequently repurposes a shared codebase across multiple ransomware variants, evidenced by its close collaboration with the CyberVolk collective. Campaigns consistently feature a 5‑hour decryption window, BMP ransom notes in %TEMP%, and AES‑256/RSA‑2048 encryption. The group has shown a proclivity for geopolitical operations—such as the Japan-focused '#OpJP' attack—and for leveraging social channels (Discord, Telegram) to both exfiltrate credentials and engage in extortion of rival hacktivist groups. Operating with a flexible alliance model, AzzaSec blends RaaS capabilities with webshells and credential‑stealing scripts, maintaining an adaptable operational tempo across many sectors globally."

IOC Patterns

  • %temp%/*.bmp
  • %appdata%\\Roaming\\time.dat
  • AES-256 file encryption indicator
  • RSA-2048 key wrapping usage
  • Process kill of MMC.exe and Taskmgr.exe
  • Webshell upload/download activity
  • Discord-based credential exfiltration channel
  • Telegram channel extortion identifiers

Recommended Actions

  • Deploy detection rules for BMP image dropper activity in temp directories.
  • Monitor process creation/termination of MMC.exe and Taskmgr.exe to detect kill attempts.
  • Implement ransomware protection that recognizes AES-256 encrypted files combined with RSA-2048 key wrapping.
  • Block or monitor outbound traffic to Discord servers to deter credential exfiltration.
  • Patch public-facing services promptly to mitigate webshell exploitation risk.
  • Do not comply with extortion demands issued through Telegram channels.
  • Extend monitoring for known ransomware families such as AzzaSec Ransom, Diamond RW, LockBit, and Chaos.

Suggested Tags

ransomware
AzzaSec
CyberVolk
Doubleface
RaaS
infostealer
webshell
Python stealer
Discord exfiltration
pro-Russia hacktivist
geopolitical targeting
telegram extortion
hacktivist

Confidence Assessment

"The confidence in the technical capabilities and tactics of AzzaSec is moderate to high, backed by consistent indicators such as AES‑256/RSA‑2048 encryption, BMP ransom notes, process termination techniques, and documented usage of Discord/Telegram channels. However, attribution to a specific national or ideological group remains uncertain due to overlapping aliases with multiple cyber‑criminal entities (e.g., APT28, Fancy Bear). Information gaps persist regarding the unit’s exact founding timeline, precise membership structure, long‑term operational tempo, and full scope of geopolitical motivations."

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 19 Domain 1

References

  1. www.sentinelone.com — Cited by web research for: AzzaSecurity
  2. thecyberexpress.com — Cited by web research for: From Russia with Love
  3. misp-galaxy.org — Cited by web research for: cpyy
  4. threatmon.io — Cited by web research for: Dark

Intel Summary

1

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

Ransomware
Hacktivism
APT
hacktivism
ransomware
pro-Palestine
Italy-based
Middle East targeting
AzzaSec
CyberVolk
Doubleface
RaaS
infostealer
webshell
Python stealer
Discord exfiltration
pro-Russia hacktivist
geopolitical targeting
telegram extortion
hacktivist

Details

MITRE ID
APT4
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.