Also known as: tracked as, Burundanga in Colombia, it is an odorless, tasteless, rob unwary victims, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Abyss Locker, Royal Ransomware
Known victims: 5
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The ulose threat actor is a medium-sophistication criminal group primarily motivated by organizational gain, with goals of deploying ransomware for financial gain. The actor has been active since June 2026 and has already compromised 5 known victims. Their operations indicate a focus on exploiting vulnerabilities for ransom, posing a significant threat to unprepared organizations.
Goals & Targeting
The ulose threat actor targets organizations with the strategic objective of maximizing financial gain through the deployment of ransomware. The lack of specific information on targeted sectors or countries suggests a potentially opportunistic approach, where the actor may exploit vulnerabilities as they are discovered, rather than focusing on particular industries or geographies. Typical victims of ulose are likely those with inadequate cybersecurity measures in place, making them susceptible to ransomware attacks. The actor's medium level of sophistication indicates an ability to adapt and potentially expand its targeting profile as its capabilities evolve.
Enhanced Description
Continuing from the initial assessment, the ulose actor's reliance on ransomware as a means to achieve financial gain positions it as a significant threat to data integrity and business continuity. The financial motivation driving ulose's operations aligns with broader trends in cybercrime, where actors seek to monetize their capabilities through extortion. This approach often involves exploiting known vulnerabilities, leveraging social engineering tactics, or utilizing sophisticated malware to encrypt data until a ransom is paid. Given the evolving nature of ransomware threats and the adaptability of criminal groups, organizations must prioritize robust backup strategies, timely patch management, and employee education on phishing and other social engineering techniques to mitigate the risk of ulose and similar actors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The ulose actor's campaign patterns and operational tempo are not well-documented due to the limited historical data available. However, the fact that 5 known victims have been compromised since its first observation in June 2026 suggests a relatively aggressive operational pace. Notable past operations may include the exploitation of recently disclosed vulnerabilities, indicating a reactive and opportunistic strategy. Victim types are likely to include a range of organizations with varying levels of cybersecurity maturity, highlighting the need for all entities to be alert to the threat posed by ulose.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on the ulose threat actor is moderate due to the limited historical context and the absence of detailed information on its TTPs, targeted sectors, and countries. Information gaps exist regarding the actor's full capabilities, the extent of its operations, and its potential links to other threat actors or campaigns. Continuous monitoring and analysis of emerging intelligence are necessary to fill these gaps and provide a more comprehensive understanding of the ulose threat.
No observed data linked yet.
6
Techniques
44
Tools
5
Campaigns
14
IOCs
0
Observed Data
4
Tactics