Also known as: tracked as, APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor, Playcrypt, Black Cat
Coinbase Cartel is an emerging threat actor that blends elements of supply‑chain exploitation with classic ransomware extortion tactics. Originating from a September 2025 incident wave, the group rapidly built a portfolio of more than sixty victims, primarily targeting healthcare organizations in the UAE, technology firms, and transportation providers. The group's operations are characterized by social engineering and credential harvesting, often leveraging initial access brokers to gain privileged local or domain accounts. Once inside, they manipulate administrative settings, tamper with log files to cover tracks, and exfiltrate valuable data over their command‑and‑control channel without applying any encryption—thereby avoiding the “captive platform” defense that many organizations now employ. Once sufficient data is exfiltrated, Coinbase Cartel publishes victim lists on a publicly accessible leak site while communicating ransom demands through an isolated chat module. The organization mandates Bitcoin payment and claims the value of each target based on the sensitivity of stolen information, making it a sophisticated “data‑theft ransomware” model. The threat actor also demonstrates an appetite for zero‑day vulnerabilities and collaborates within dark‑web underground marketplaces, indicating an evolving operational mindset that integrates exploitation with extortion. Overall, Coinbase Cartel presents a hybrid risk profile: they are more focused on data extraction than system shutdown but maintain classic ransomware negotiation workflows to monetize their exfiltration.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Coinbase Cartel is a data‑theft ransomware group that first emerged in September 2025, claiming over 60 victims across high‑margin sectors such as healthcare, technology, and transportation. Unlike traditional ransomware, the group focuses on exfiltrating data without encrypting files, publishing victim names on a leak site, and demanding Bitcoin payments via a dedicated chat interface.
Goals & Targeting
The primary objective of Coinbase Cartel is financial gain through the sale or exposure of stolen data. By targeting high‑margin sectors—particularly healthcare, technology, and transportation—they maximize the incentive for victims to pay rapidly. Their selection of geographically diverse targets (UAE, US, UK, BR, DE, etc.) suggests a strategy of global reach with a particular emphasis on entities that hold large volumes of protected or proprietary information. Their tactics indicate a preference for stealth; they exploit privilege escalation paths, obfuscate logs, and operate through a leak site to maintain operational security while retaining the option for ransom offers. The use of chat interfaces for negotiations allows them to stay hidden from automated monitoring systems while ensuring rapid communication with the threatened organization.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Coinbase Cartel surfaced in early September 2025 and rapidly ascended to a victim count exceeding sixty within weeks. The group adopts a high‑tempo approach, quickly moving from initial access—often facilitated by credential‑breach or broker services—to exfiltration and ransom communication. Victims primarily belong to high‑margin healthcare, technology, and transportation industries across the United Arab Emirates, United States, India, Brazil, Germany, Russia, Israel, Canada, Turkey, Italy, China, North Korea, South Korea, Taiwan, Mexico, Australia, and Japan. The actor’s operational pattern includes secure exfiltration over encrypted command‑and‑control channels, minimal use of encryption on victim data to avoid detection by anti‑ransomware controls, and a post‑exfiltration “leak site” that amplifies pressure on the target. They have been noted to seek zero‑day exploits and operate in closed underground circles, indicating an appetite for advanced persistent techniques. This pattern reflects a shift from traditional ransomware toward data‑theft ransom schemes: the primary currency is information exposure rather than system downtime, yet the organization still leverages classic demand communication channels such as chat interfaces and public leak repositories for amplification.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data available for Coinbase Cartel provides a reasonable baseline understanding of the actor’s capabilities, tactics, and target profile, but it is limited by sparse detailed technical indicators. The lack of disclosed zero‑day exploits, specific credential‑harvested tools, or definitive evidence of broker relationships suggests moderate confidence in the operational picture. Key gaps remain regarding: precise exploitation vectors used for initial access; full list of software components or persistence mechanisms employed; and a broader sample set of victim organizations. Continued analysis of leaked chat logs, payment records, and domain registrations will strengthen attribution certainty and improve defensive guidance.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
47
Tools
0
Campaigns
8
IOCs
0
Observed Data
3
Tactics