Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Coinbase Cartel

Also known as: tracked as, APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor, Playcrypt, Black Cat

Description

Coinbase Cartel is an emerging threat actor that blends elements of supply‑chain exploitation with classic ransomware extortion tactics. Originating from a September 2025 incident wave, the group rapidly built a portfolio of more than sixty victims, primarily targeting healthcare organizations in the UAE, technology firms, and transportation providers. The group's operations are characterized by social engineering and credential harvesting, often leveraging initial access brokers to gain privileged local or domain accounts. Once inside, they manipulate administrative settings, tamper with log files to cover tracks, and exfiltrate valuable data over their command‑and‑control channel without applying any encryption—thereby avoiding the “captive platform” defense that many organizations now employ. Once sufficient data is exfiltrated, Coinbase Cartel publishes victim lists on a publicly accessible leak site while communicating ransom demands through an isolated chat module. The organization mandates Bitcoin payment and claims the value of each target based on the sensitivity of stolen information, making it a sophisticated “data‑theft ransomware” model. The threat actor also demonstrates an appetite for zero‑day vulnerabilities and collaborates within dark‑web underground marketplaces, indicating an evolving operational mindset that integrates exploitation with extortion. Overall, Coinbase Cartel presents a hybrid risk profile: they are more focused on data extraction than system shutdown but maintain classic ransomware negotiation workflows to monetize their exfiltration.

Goals & Targeting

Targeted Sectors

Healthcare
Financial services
Non profit
Manufacturing
Transportation
Government
Media
Construction
Think tank
Education
Critical infrastructure

Targeted Countries / Regions

US
AE
IN
BR
DE
RU
IL
CA
TR
IT
CN
KP
KR
TW
MX
AU
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Coinbase Cartel is a data‑theft ransomware group that first emerged in September 2025, claiming over 60 victims across high‑margin sectors such as healthcare, technology, and transportation. Unlike traditional ransomware, the group focuses on exfiltrating data without encrypting files, publishing victim names on a leak site, and demanding Bitcoin payments via a dedicated chat interface.

Goals & Targeting

The primary objective of Coinbase Cartel is financial gain through the sale or exposure of stolen data. By targeting high‑margin sectors—particularly healthcare, technology, and transportation—they maximize the incentive for victims to pay rapidly. Their selection of geographically diverse targets (UAE, US, UK, BR, DE, etc.) suggests a strategy of global reach with a particular emphasis on entities that hold large volumes of protected or proprietary information. Their tactics indicate a preference for stealth; they exploit privilege escalation paths, obfuscate logs, and operate through a leak site to maintain operational security while retaining the option for ransom offers. The use of chat interfaces for negotiations allows them to stay hidden from automated monitoring systems while ensuring rapid communication with the threatened organization.

Enhanced Description

Key Capabilities

  • Data exfiltration
  • Credential harvesting via social engineering
  • Use of administrator accounts for privileged actions
  • Log tampering and integrity manipulation
  • Publication of victim names on a data‑leak website
  • Ransom demands communicated through dedicated chat interface
  • Bitcoin payment acceptance
  • Data theft without encryption, only exfiltration
  • Targeted ransom based on stolen data value
  • Stealthy operations with minimal OPSEC failures
  • Broad cross-sector impact (healthcare, technology, transportation)

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Exfiltration

ATT&CK Techniques

T1078
T1562.006
T1041

Software / Tooling

Emissary
RansomHub
Akira
Black Basta
Shai‑Hulud
Qilin
Mythic
Phishing

Campaigns & Victims

Coinbase Cartel surfaced in early September 2025 and rapidly ascended to a victim count exceeding sixty within weeks. The group adopts a high‑tempo approach, quickly moving from initial access—often facilitated by credential‑breach or broker services—to exfiltration and ransom communication. Victims primarily belong to high‑margin healthcare, technology, and transportation industries across the United Arab Emirates, United States, India, Brazil, Germany, Russia, Israel, Canada, Turkey, Italy, China, North Korea, South Korea, Taiwan, Mexico, Australia, and Japan. The actor’s operational pattern includes secure exfiltration over encrypted command‑and‑control channels, minimal use of encryption on victim data to avoid detection by anti‑ransomware controls, and a post‑exfiltration “leak site” that amplifies pressure on the target. They have been noted to seek zero‑day exploits and operate in closed underground circles, indicating an appetite for advanced persistent techniques. This pattern reflects a shift from traditional ransomware toward data‑theft ransom schemes: the primary currency is information exposure rather than system downtime, yet the organization still leverages classic demand communication channels such as chat interfaces and public leak repositories for amplification.

IOC Patterns

  • Bitcoin address patterns
  • Malicious domains used by data-leak website
  • Chat-channel identifiers employed by attackers
  • CVE-2024-55591 zero‑day vulnerability

Recommended Actions

  • Implement strong privileged access management, ensuring all local and domain admin accounts are protected with least privilege and MFA. Deploy continuous credential monitoring to detect stolen or reused passwords. Use log integrity verification tools to guard against tampering of security logs. Segment your network to limit lateral movement and isolate critical databases. Block known malicious Bitcoin addresses and domains tied to the data‑leak site. Set up real‑time outbound traffic monitoring for anomalous large or encrypted exfiltration flows. Maintain comprehensive, off‑site backups (e.g., secure cloud storage) and verify backup integrity regularly. Develop an incident response playbook that includes steps for negotiating with extortionists, verifying payment legitimacy and documenting any interactions to avoid double‑payment scenarios.

Suggested Tags

Data Exfiltration
Bitcoin Payment
Non-Encryption Ransomware
Zero-Day Exploits
Initial Access Brokers
Dark Web Collaboration
Healthcare Targeting UAE
High-Value Industry Targeting
OPSEC

Confidence Assessment

The data available for Coinbase Cartel provides a reasonable baseline understanding of the actor’s capabilities, tactics, and target profile, but it is limited by sparse detailed technical indicators. The lack of disclosed zero‑day exploits, specific credential‑harvested tools, or definitive evidence of broker relationships suggests moderate confidence in the operational picture. Key gaps remain regarding: precise exploitation vectors used for initial access; full list of software components or persistence mechanisms employed; and a broader sample set of victim organizations. Continued analysis of leaked chat logs, payment records, and domain registrations will strengthen attribution certainty and improve defensive guidance.

ATT&CK Techniques

Exfiltration
1 technique
Stealth
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. fortiguard.fortinet.com — Cited by web research for: APT-C-17
  2. businessinsights.bitdefender.com — Cited by web research for: Black Cat
  3. learn.microsoft.com — Cited by web research for: Tsunami
  4. businessinsights.bitdefender.com — Cited by web research for: PLAY
  5. gbhackers.com — Cited by web research for: npm packages
  6. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  7. research.checkpoint.com — Cited by web research for: CVE-2024-55591

Intel Summary

3

Techniques

47

Tools

0

Campaigns

8

IOCs

0

Observed Data

3

Tactics

Tags

Ransomware
Healthcare Targeting
Phishing
Data Exfiltration
Data Extortion
Healthcare Sector
Technology Sector
Transportation Sector
Bitcoin Ransom Payments
Bitcoin Payment
Non-Encryption Ransomware
Zero-Day Exploits
Initial Access Brokers
Dark Web Collaboration
Healthcare Targeting UAE
High-Value Industry Targeting
OPSEC

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.