Also known as: APT43, AzzaSecurity, Double Alliance, Paraodeus Ransomware, From Russia with Love, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Samurai Panda, PLA Navy, APT4, Wisp Team
"AzzaSec emerged from Italy and has positioned itself as a pro‑Palestine hacktivist collective. The actors are known for targeting Israeli or Israel‑aligned entities, while also engaging in ransomware campaigns against global sectors such as government, finance, energy, and telecommunications. In addition to ideological motives, the group operates with a clear financial objective and has been observed collaborating closely with other cybercriminal collections, most notably CyberVolk. The operator distributes ransomware based on a shared AzzaSec codebase that encrypts victims’ files using AES‑256 and wraps its session keys with RSA‑2048. A 5‑hour decryption timer is enforced via a "+time.dat" file in the user’s %AppData%\Roaming directory, while ransom notices are delivered as BMP images dropped into %TEMP%. To impede analysis, AzzaSec terminates MMC.exe and Task Manager before launching its payload. Beyond ransomware, the group supplies a Webshell that allows attackers to upload and download files, perform directory traversal, and harvest environment data. A Python-based stealer targets browser, Discord, gaming, and crypto wallet credentials; harvested information is exfiltrated over Discord channels. The adversary also escalates its influence by threatening other hacktivist communities via Telegram, warning of channel bans if extortion demands are not met."
Targeted Sectors
Targeted Countries / Regions
Executive Summary
"AzzaSec, a hacktivist-driven ransomware-as-a-service operator with pro-Palestine leanings, merges financial motives with geopolitical attacks, primarily targeting Israel‑linked entities while deploying multi-layered ransomware and credential theft tactics. The group shares a common codebase with affiliates such as CyberVolk, leveraging AES-256/RSA-2048 encryption and a 5-hour ransom timer to maximize impact. Their recent extortion against other hacktivist communities via Telegram demonstrates intra-community tool and resource exploitation."
Goals & Targeting
"AzzaSec’s strategic objectives blend political activism with monetization through ransomware and credential theft. The group actively targets entities linked to Israel as well as a broad array of sectors—including government, defense, finance, energy, telecommunications, media, manufacturing, and healthcare—across dozens of countries. By releasing multi-stage campaigns that combine file encryption, process termination, webshell exploitation, and remote exfiltration channels (Discord, Telegram), the actor seeks to achieve both high-profile geopolitical disruption and substantial financial gain through ransomware payments."
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
"AzzaSec frequently repurposes a shared codebase across multiple ransomware variants, evidenced by its close collaboration with the CyberVolk collective. Campaigns consistently feature a 5‑hour decryption window, BMP ransom notes in %TEMP%, and AES‑256/RSA‑2048 encryption. The group has shown a proclivity for geopolitical operations—such as the Japan-focused '#OpJP' attack—and for leveraging social channels (Discord, Telegram) to both exfiltrate credentials and engage in extortion of rival hacktivist groups. Operating with a flexible alliance model, AzzaSec blends RaaS capabilities with webshells and credential‑stealing scripts, maintaining an adaptable operational tempo across many sectors globally."
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
"The confidence in the technical capabilities and tactics of AzzaSec is moderate to high, backed by consistent indicators such as AES‑256/RSA‑2048 encryption, BMP ransom notes, process termination techniques, and documented usage of Discord/Telegram channels. However, attribution to a specific national or ideological group remains uncertain due to overlapping aliases with multiple cyber‑criminal entities (e.g., APT28, Fancy Bear). Information gaps persist regarding the unit’s exact founding timeline, precise membership structure, long‑term operational tempo, and full scope of geopolitical motivations."
No campaigns linked yet.
No observed data linked yet.
1
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics