Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Femwar02

Also known as: tracked as, Rorschach, Aug 5, ArechClient2, UAT-10027, fast16, according to the report, sophistication, operational behavior, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, BOLDBADGER, TG-0110, Sednit, Hammertoss, Patchwork

Description

Femwar02 emerged as a previously unknown adversary in February 2026, quickly attracting attention with a large‑scale ransomware assault on the Sapienza University of Rome. The gang’s hallmark is BabLock (also referenced as Rorschach), an evolution of lockBit 2.0 that incorporates hybrid encryption using curve25519 and hc-128 for speed while enabling partial file encryption to preserve system responsiveness. BabLock also employs direct syscalls to sidestep endpoint detection, DLL sideloading through DarkLoader, and domain‑wide lateral movement via Group Policy on Windows Domain Controllers. The malware’s code shares significant lineage with LockBit 2.0 but fuses modules from Babuk and DarkSide, making its payloads difficult to classify by traditional families alone. In a clear sign of ideological bias, the ransomware avoids encrypting files on systems configured for Russian or other post‑Soviet languages—a pattern that aligns it with pro‑Russian objectives. The attack on Sapienza involved an initial spear‑phishing vector and exploitation of known vulnerabilities in Zimbra services. Femwar02’s operational footprint extends beyond academia, touching government, defense, financial services, media, healthcare, aviation, and critical infrastructure across a broad geographic spectrum that includes the US, CN, GB, IN, JP, RU, IR, FR, DE, and many others. The gang’s approach is one of rapid impact: fast encryption to cripple operations before a ransom can be demanded. Analysts note a high degree of sophistication combined with a pragmatic “smash‑and‑grab” mentality, evidenced by the group’s large‑scale data exfiltration via command‑and‑control channels and evidence of persistence in long‑term espionage profiles tied to other known APTs such as APT28 and APT29. goals_targeting":"Femwar02 seeks to maximize financial gain through swift ransomware deployment while maintaining a political narrative that excludes Russian‑language systems. Their targeting strategy prioritizes high‑profile institutions within critical sectors where disruption is costly and ransom demands are high, yet shows a deliberate avoidance of infrastructures aligned with pro‑Russian usage, indicating both opportunistic profit motives and ideological alignment.

Goals & Targeting

Targeted Sectors

Government
Education
Defense
Financial services
Non profit
Media
Telecommunications
Energy
Aerospace
Healthcare
Maritime
Manufacturing
Information technology
Critical infrastructure
Think tank
Hospitality
Pharmaceutical
Chemical
Mining
Utilities
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
TW
FR
CA
IT
AE
IL
TR
AU
KZ
PK
ES
VN
UA
PL
SG
NL
BR
IQ
BY
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 hour ago

Executive Summary

Femwar02 is a pro‑Russian ransomware gang that surfaced in early 2026, launching a high‑impact attack on Italy’s Sapienza University by deploying the BabLock/Rorschach malware. The group focuses on fast hybrid encryption with selective language avoidance, targeting a wide array of sectors worldwide while avoiding systems set to Russian or other post‑Soviet languages. Their tactics combine rapid mass encryption, spear‑phishing, and domain‑wide propagation via Windows Group Policy.

Enhanced Description

Key Capabilities

  • Fast hybrid encryption with curve25519/hc-128
  • Selective language‑based encryption avoidance (excludes Russian/post‑Soviet languages)
  • Advanced customization of ransomware payloads
  • Rapid mass file encryption
  • Spear‑phishing campaigns
  • Domain policy propagation via Windows AD
  • DLL sideloading using DarkLoader
  • Exploitation of known vulnerabilities (e.g., Zimbra, Zscaler APTs)
  • Data exfiltration over command-and-control channels
  • Persistence mechanisms for long‑term compromise

MITRE ATT&CK Tactics

Impact
Initial Access
Collection
Command and Control
Exfiltration
Persistence

ATT&CK Techniques

T1486
T1566
T1189
T1041

Software / Tooling

BabLock
Rorschach
DarkLoader
MiniDuke
CosmicDuke
OnionDuke
CozyDuke
CloudDuke
SeaDuke
HammerDuke
PinchDuke
GeminiDuke

Campaigns & Victims

Femwar02’s known campaign record is limited to the Sapienza University incident, yet its pattern mirrors other pro‑Russian actors such as APT28 and APT29: swift initial access via spear‑phishing with a broad dropper bundle, rapid lateral movement using Windows Group Policy, and an emphasis on fast, selective encryption. Post‑attack, the gang appears to exfiltrate data through command‑and‑control channels before encrypting assets. Although only one large attack has been documented, analysts suspect ongoing smaller operations given the actor’s toolset breadth and language‑aware execution strategy.

IOC Patterns

  • Domain: demo-cloud.space
  • Domain: cisa.gov
  • Domain: TEMP.Hermit
  • Domain: TEMP.Veles
  • Domain: Cyber.Anarchy.Squad
  • Domain: TEMP.Avengers
  • Domain: TEMP.Hippo
  • Domain: TEMP.Zhenbao
  • Domain: TEMP.Beanie
  • Domain: TEMP.Noble
  • Domain: 360.net
  • Domain: Temp.Pittytiger
  • Domain: possible.If
  • Domain: took.Kaspersky
  • Domain: TMP.Lapis
  • Email: lorenzo@techcrunch.com

Recommended Actions

  • Deploy patches for CVE‑2026‑20316 and other relevant Windows updates
  • Implement monitoring of rapid, mass file encryption events to detect BabLock activity
  • Block known malicious domains such as demo-cloud.space, cisa.gov, and TEMP.* suffixes in internal DNS resolvers
  • Restrict or audit Group Policy-based domain propagation mechanisms
  • Require multi‑factor authentication for privileged accounts
  • Enable endpoint detection and response (EDR) with deep TLS inspection to catch C2 traffic

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. techcrunch.com — Cited by web research for: Rorschach
  2. www.techbuzz.ai — Cited by web research for: sophistication
  3. thecyberexpress.com — Cited by web research for: operational behavior
  4. misp-galaxy.org — Cited by web research for: cpyy
  5. securityaffairs.com — Cited by web research for: CVE-2026-58048

Intel Summary

4

Techniques

52

Tools

0

Campaigns

16

IOCs

0

Observed Data

3

Tactics

Tags

Ransomware
Phishing
APT
ransomware
espionage
education-sector
pro-Russian

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.