Also known as: tracked as, Jul 6, 2026, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter
Suspicious group Known victims: 3
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The threat actor d1r is a newly identified cybercriminal group operating with medium sophistication, primarily targeting organizations for ransomware attacks and financial gain. Despite limited activity observed as of July 13, 2026, this group poses a moderate risk due to their strategic objectives in the cybercrime landscape.
Goals & Targeting
The d1r threat actor appears to target industries that would yield significant financial returns through ransomware operations. While specific sectors have not been definitively identified, their choice of campaigns like 'D1R: Bosch' and others suggests an interest in high-profile or critical infrastructure targets. The group's strategy revolves around maximizing financial gain through data exfiltration and extortion.
Enhanced Description
The d1r threat actor has emerged as a potential player in the cybercriminal ecosystem, specializing in ransomware activities aimed at achieving financial gain. While operational details are sparse and only one instance of activity has been recorded, initial indicators suggest a focus on infiltrating organizations to extract data for extortion or sale. The group's ability to adapt and employ effective tactics indicates a moderate level of sophistication, positioning them as a growing concern in the cybersecurity domain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The d1r threat actor has initiated campaigns such as 'D1R: Bosch', 'D1R: ARM', and 'D1R: Synopsys', targeting various sectors, though specific details remain undisclosed. While early in their activity, these campaigns suggest a methodical approach to selecting high-value targets for maximum extortion potential.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in d1r's details is low to medium due to limited observed activity and lack of comprehensive reporting. The primary risk factors are based on their identified TTPs, which align with common cybercriminal methodologies.
No observed data linked yet.
14
Techniques
44
Tools
3
Campaigns
40
IOCs
0
Observed Data
8
Tactics