Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: tracked as, Burundanga in Colombia, it is an odorless, tasteless, rob unwary victims, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Abyss Locker, Royal Ransomware

Description

Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Government
Education
Healthcare
Telecommunications
Defense
Critical infrastructure
Media
Non profit
Manufacturing
Retail
Information technology
Hospitality
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation
Think tank

Targeted Countries / Regions

RU
GB
IN
CN
UA
KP
AU
DE
IR
IL
PK
BY
PL
TW
CA

AI Analysis

· 2 weeks ago

Executive Summary

The ulose threat actor is a medium-sophistication criminal group primarily motivated by organizational gain, with goals of deploying ransomware for financial gain. The actor has been active since June 2026 and has already compromised 5 known victims. Their operations indicate a focus on exploiting vulnerabilities for ransom, posing a significant threat to unprepared organizations.

Goals & Targeting

The ulose threat actor targets organizations with the strategic objective of maximizing financial gain through the deployment of ransomware. The lack of specific information on targeted sectors or countries suggests a potentially opportunistic approach, where the actor may exploit vulnerabilities as they are discovered, rather than focusing on particular industries or geographies. Typical victims of ulose are likely those with inadequate cybersecurity measures in place, making them susceptible to ransomware attacks. The actor's medium level of sophistication indicates an ability to adapt and potentially expand its targeting profile as its capabilities evolve.

Enhanced Description

Continuing from the initial assessment, the ulose actor's reliance on ransomware as a means to achieve financial gain positions it as a significant threat to data integrity and business continuity. The financial motivation driving ulose's operations aligns with broader trends in cybercrime, where actors seek to monetize their capabilities through extortion. This approach often involves exploiting known vulnerabilities, leveraging social engineering tactics, or utilizing sophisticated malware to encrypt data until a ransom is paid. Given the evolving nature of ransomware threats and the adaptability of criminal groups, organizations must prioritize robust backup strategies, timely patch management, and employee education on phishing and other social engineering techniques to mitigate the risk of ulose and similar actors.

Key Capabilities

  • Ransomware deployment
  • Vulnerability exploitation
  • Social engineering
  • Data encryption
  • Extortion

MITRE ATT&CK Tactics

Defense Evasion
Execution
Privilege Escalation

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware
Exploit kits

Campaigns & Victims

The ulose actor's campaign patterns and operational tempo are not well-documented due to the limited historical data available. However, the fact that 5 known victims have been compromised since its first observation in June 2026 suggests a relatively aggressive operational pace. Notable past operations may include the exploitation of recently disclosed vulnerabilities, indicating a reactive and opportunistic strategy. Victim types are likely to include a range of organizations with varying levels of cybersecurity maturity, highlighting the need for all entities to be alert to the threat posed by ulose.

IOC Patterns

  • Spear-phishing with malicious attachments or links
  • Exploitation of known vulnerabilities in software or systems
  • Unusual network activity indicative of ransomware command and control (C2) communications

Recommended Actions

  • Implement robust backup and disaster recovery plans
  • Regularly update and patch software and systems
  • Conduct employee training on phishing and social engineering
  • Deploy anti-ransomware solutions and monitor for suspicious activity

Suggested Tags

Ransomware
Criminal
Financial gain
Medium sophistication

Confidence Assessment

The confidence level in the available data on the ulose threat actor is moderate due to the limited historical context and the absence of detailed information on its TTPs, targeted sectors, and countries. Information gaps exist regarding the actor's full capabilities, the extent of its operations, and its potential links to other threat actors or campaigns. Continuous monitoring and analysis of emerging intelligence are necessary to fill these gaps and provide a more comprehensive understanding of the ulose threat.

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  2. attack.mitre.org — Cited by web research for: Interception
  3. attack.mitre.org — Cited by web research for: PowerShell
  4. learn.microsoft.com — Cited by web research for: Tsunami

Intel Summary

6

Techniques

44

Tools

5

Campaigns

14

IOCs

0

Observed Data

4

Tactics

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Jun 9, 2026
Last Seen
Jun 9, 2026
Added
Jul 19, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.