Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: tracked as, Jul 6, 2026, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter

Description

Suspicious group Known victims: 3

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Government
Healthcare
Defense
Telecommunications
Manufacturing
Transportation
Education
Construction
Retail
Aerospace
Aviation
Critical infrastructure
Information technology
Energy
Chemical
Legal services
Media
Non profit
Oil gas
Hospitality

Targeted Countries / Regions

US
IL
BR
IR
IN
AU
GB
AE
JP
RO
PK
CA
FR
RU

AI Analysis

· 1 week ago

Executive Summary

The threat actor d1r is a newly identified cybercriminal group operating with medium sophistication, primarily targeting organizations for ransomware attacks and financial gain. Despite limited activity observed as of July 13, 2026, this group poses a moderate risk due to their strategic objectives in the cybercrime landscape.

Goals & Targeting

The d1r threat actor appears to target industries that would yield significant financial returns through ransomware operations. While specific sectors have not been definitively identified, their choice of campaigns like 'D1R: Bosch' and others suggests an interest in high-profile or critical infrastructure targets. The group's strategy revolves around maximizing financial gain through data exfiltration and extortion.

Enhanced Description

The d1r threat actor has emerged as a potential player in the cybercriminal ecosystem, specializing in ransomware activities aimed at achieving financial gain. While operational details are sparse and only one instance of activity has been recorded, initial indicators suggest a focus on infiltrating organizations to extract data for extortion or sale. The group's ability to adapt and employ effective tactics indicates a moderate level of sophistication, positioning them as a growing concern in the cybersecurity domain.

Key Capabilities

  • Spear-phishing with malicious email attachments
  • Polymorphic ransomware deployment
  • Data exfiltration techniques

MITRE ATT&CK Tactics

Exfiltration: Data Transfer Methods
Initial Access tactics

ATT&CK Techniques

T1566.001
T1059.003

Software / Tooling

Custom ransomware framework
Phishing kits

Campaigns & Victims

The d1r threat actor has initiated campaigns such as 'D1R: Bosch', 'D1R: ARM', and 'D1R: Synopsys', targeting various sectors, though specific details remain undisclosed. While early in their activity, these campaigns suggest a methodical approach to selecting high-value targets for maximum extortion potential.

IOC Patterns

  • Spear-phishing email campaigns
  • Encrypted C2 communication channels
  • Malicious scripts delivery via M365

Recommended Actions

  • Implement advanced email filtering and threat detection solutions
  • Monitor network traffic for signs of data exfiltration

Suggested Tags

Ransomware
Financial-Motiv
APT3

Confidence Assessment

Confidence in d1r's details is low to medium due to limited observed activity and lack of comprehensive reporting. The primary risk factors are based on their identified TTPs, which align with common cybercriminal methodologies.

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. www.ransomware.live — Cited by web research for: Bjorka
  2. hybrid-analysis.com — Cited by web research for: T1036
  3. www.usgs.gov — Cited by web research for: Payload
  4. darkfeed.io — Cited by web research for: Babuk
  5. pmc.ncbi.nlm.nih.gov — Cited by web research for: Neuron
  6. securityarsenal.com — Cited by web research for: ScreenConnect
  7. pmc.ncbi.nlm.nih.gov — Cited by web research for: PLAY

Intel Summary

14

Techniques

44

Tools

3

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

Ransomware
Financial-Motiv
APT3

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Jul 13, 2026
Last Seen
Jul 13, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.