Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors sevyware

Also known as: tracked as, advertising-supported software, APT43, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Royal Ransomware

Description

Direct Extortion Double Extortion

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Defense
Government
Media
Telecommunications
Healthcare
Education
Critical infrastructure
Non profit
Information technology
Manufacturing
Retail
Hospitality
Mining
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation
Think tank

Targeted Countries / Regions

RU
IN
CN
UA
KP
GB
CA
DE
IR
IL
IT
US
PK
BY
PL
TW
AU

AI Analysis

· 1 week ago

Executive Summary

Sevyware is a medium-sophistication criminal threat actor primarily motivated by organizational-gain and focused on ransomware activities for financial gain. Known for employing direct extortion and double extortion tactics, Sevyware targets organizations through encrypted data and threatens to leak sensitive information unless a ransom is paid.

Goals & Targeting

Sevyware's strategic objectives revolve around maximizing financial gains through the deployment of ransomware. While specific targeting criteria are not well-documented, the threat actor likely selects victims based on sector vulnerabilities and organizational size. The primary targets are typically businesses that rely heavily on digital operations, have weaker cybersecurity postures, or may lack adequate backup systems to recover data without paying ransoms.

Enhanced Description

Sevyware operates with a primary focus on ransomware attacks aimed at achieving financial gains. The threat actor's modus operandi involves direct extortion, where victims are coerced into paying ransoms after their data is encrypted, and double extortion, which includes the threat to leak stolen data if the ransom is not paid. Despite the absence of specific targeted sectors or countries in available intelligence, Sevyware likely follows common patterns observed in ransomware groups that often target industries with weaker defenses. The actor’s operational tactics and goals align with several known ransomware campaigns that focus on disrupting operations and extracting financial rewards.

Key Capabilities

  • Deployment of ransomware for financial gain
  • Double extortion tactics (encrypting data and threatening to leak it)
  • Encryption of victim data to disrupt business operations

MITRE ATT&CK Tactics

Ransomware Deployment
Data Encryption
Email Phishing

ATT&CK Techniques

T1568.002
T1437.001
T1059.003

Software / Tooling

Ransomware (e.g., Sodinokibi, REvil)
Phishing Tools (e.g., Cobalt Strike)

Campaigns & Victims

Sevyware is observed to follow a consistent pattern of targeting businesses for ransomware attacks. Campaigns often involve the rapid deployment of ransomware after successful initial access. While specific campaigns are not detailed in public intelligence, Sevyware’s tactics suggest small to medium-sized businesses as primary targets, aiming to achieve quick financial gains with minimal operational exposure.

IOC Patterns

  • Email phishing attempts mimicking legitimate communications
  • Encrypted files with specific extensions
  • Network traffic spikes during encryption processes

Recommended Actions

  • Implement regular backups and ensure they are offline or securely stored
  • Train employees to recognize phishing emails and suspicious links
  • Monitor network activities for unusual patterns and encrypted file changes
  • Maintain an incident response plan to address potential ransomware incidents

Suggested Tags

Ransomware
Financial-Crime
Cyber-Extortion

Confidence Assessment

The confidence level in the data is low as Sevyware’s exact tactics, tools, and previously known campaigns are unclear. The lack of specific IOCs or linked campaigns makes precise analysis challenging.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. www.recordedfuture.com — Cited by web research for: T1497
  4. learn.microsoft.com — Cited by web research for: Tsunami
  5. attack.mitre.org — Cited by web research for: Process Hollowing

Intel Summary

40

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Financial-Crime
Cyber-Extortion

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
Iran (IR)
Confidence
80%
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.