Also known as: other aliases, several other aliases, Turla, network, software application, APT28, Jumpy Pisces, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, root access, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, DEV-0391, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Incransom, Qakbot, Pawn Storm, Fancy Bear, Sednit, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505
BreachLaboratory operates by targeting financial institutions, government bodies, healthcare providers and various other sectors that hold valuable personal or banking information. Initial access typically occurs through spear‑phishing campaigns that deliver malicious attachments or links, after which the actor deploys custom loaders – most notably the Latrodectus downloader and Lotus loader families – to gain persistence on compromised hosts. Once inside, the organisation’s internal database systems are surveyed for high-value data sets. The group extracts large volumes of information, including customer names, account details, SWIFT codes and other transaction identifiers, then stages this information in an organized format such as CSV or SQL dumps. These structured datasets are subsequently posted on private forums where they can be purchased by third parties. Financial gain is the primary motivation: BreachLaboratory monetises through direct sales of datasets and potentially through facilitating downstream fraud operations that exploit the stolen data. The actor demonstrates an ability to sell data for substantial amounts, having claimed to have sold approx. 950,000 records from Grupo Catalana Occidente and over 18,000 records from Bank Mandiri. While many aliases are listed in public threat‑intel sources – some of which pertain to distinct APTs such as Turla or Fancy Bear – the available evidence points specifically to BreachLaboratory’s focus on data extraction and marketplace sales rather than advanced espionage or ransomware campaigns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BreachLaboratory is a financially driven cyber‑criminal enterprise that specialises in harvesting and selling sensitive financial data from organisations worldwide. The group infiltrates internal databases—often via phishing or database‑exploits—and then packages customer records, account numbers and SWIFT codes into CSV or SQL dumps for sale on underground forums. Its operations demonstrate a clear monetisation focus rather than a traditional espionage agenda.
Goals & Targeting
The group’s strategic objective is pure monetisation driven by the high value of raw financial datasets. By targeting global banking institutions, government ministries, and other sectors that maintain customer or transaction records, BreachLaboratory maximises its marketability on underground marketplaces. Typical victims are regional banks in Latin America, Southeast Asia, as well as large multinational banks with complex internal data stores – organisations that often lack robust database hardening and multi‑factor authentication for privileged accounts.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BreachLaboratory operates on a large‑scale, low‑frequency campaign model: key operations involve the compromise of sizeable financial data stores, extraction of datasets for sale, and minimal engagement with affected organisations beyond the initial breach. The actor’s activity is consistent with other financially motivated cyber‑crime syndicates that prioritize marketable information over sabotage or espionage objectives. Its notable incidents include the 2014‑style exfiltration from Spanish retailers Grupo Catalana Occidente and a 2021 incident involving Bank Mandiri in Indonesia.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is derived from limited public sources and a brief actor description that lists many aliases not directly linked to BreachLaboratory’s documented activities. While the reported dataset exfiltration incidents provide concrete evidence of financial motives, mapping specific MITRE techniques and tools remains partially speculative due to sparse technical details. The attribution of associated tools (e.g., Emotet) is based on common industry patterns rather than direct documentation for this actor.
No campaigns linked yet.
No observed data linked yet.
5
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics