Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors wallstreet

Also known as: tracked as, Lou Gehrig's disease, Wall Street, was an American businessman

Description

Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Healthcare
Government
Defense
Critical infrastructure
Education
Manufacturing
Energy
Retail
Hospitality
Legal services
Transportation
Telecommunications
Utilities
Construction
Food agriculture
Media

Targeted Countries / Regions

US
CN
MX
GB
DE
IN
IR
CA
AU
ES
IT
FR
BR
SG

AI Analysis

· 1 week ago

Executive Summary

The threat actor known as 'wallstreet' is a medium-sophistication criminal group primarily motivated by financial gain through ransomware activities. Operating since June 2026, they have targeted sectors including automotive and healthcare, with notable campaigns such as the attack on Gold Standard Automotive. Their modus operandi involves strategic targeting of industries likely to yield high monetary returns, leveraging ransomware and data exfiltration for organizational profit.

Goals & Targeting

Wallstreet targets sectors such as automotive and healthcare due to their vulnerability and high potential for financial gain through ransomware. They likely focus on industries where data breaches can lead to substantial ransoms or data sales, such as those with sensitive customer information. Their campaigns suggest a preference for North American entities, possibly due to easier access vectors like RDP vulnerabilities or phishing.

Enhanced Description

Wallstreet is a cybercriminal group specializing in ransomware operations, primarily targeting sectors with financial value and sensitive data. Linked campaigns include attacks on automotive dealerships, healthcare organizations, and local government entities, indicating a strategic focus on industries where data breaches can yield significant financial returns. The group's activities demonstrate a methodical approach to compromising networks, encrypting data, and demanding ransoms for decryption keys. Wallstreet operates with medium sophistication, relying on established tools and techniques but not yet evidence of advanced persistence or complex campaign infrastructure.

Key Capabilities

  • Ransomware deployment
  • RDP brute force/exploitation
  • Scheduled task persistence
  • File encryption

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Impact

ATT&CK Techniques

T1567.001
T1059
T1238
T1566.001

Software / Tooling

Ransomware (e.g., LockBit, REvil)
RDP brute force tools
Scheduled task utilities
Custom encryption tools

Campaigns & Victims

Wallstreet has conducted several campaigns targeting various industries. Notable victims include Gold Standard Automotive, Baraga County Memorial Hospital, Edgewood Police Department, and Omax Autos. Their attacks involve initial access via RDP or phishing, followed by data encryption with ransomware demands. Campaigns exhibit a modus operandi of compromising systems, encrypting files, and leaving instructions for payment in clear text.

IOC Patterns

  • Scheduled task creation/modification
  • File encryption patterns consistent with ransomware strains
  • Presence of known ransomware binaries
  • RDP brute force attempts

Recommended Actions

  • Implement multi-factor authentication for RDP access
  • Conduct regular backups and store offline
  • Monitor for scheduled task anomalies
  • Apply patches to systems promptly
  • Educate employees on phishing attacks

Suggested Tags

ransomware
cybercrime
financial-gain

Confidence Assessment

Confidence is moderate based on linked campaigns and TTP analysis, but gaps exist in detailed attack patterns and specific toolsets used.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. www.welivesecurity.com — Cited by web research for: T1587.001
  2. www.cybereason.com — Cited by web research for: Payload
  3. redpiranha.net — Cited by web research for: Device code phishing
  4. www.fortinet.com — Cited by web research for: Qilin
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

40

Techniques

44

Tools

7

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

ransomware
cybercrime
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
United States (US)
Confidence
80%
First Seen
Jun 16, 2026
Last Seen
Aug 10, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.