Also known as: tracked as, caterpillar tread, tank tread, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, confusing language, brand, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Tech Sectors, Royal Ransomware, Agrius
Mortar emerged as a hybrid threat actor blending ransomware delivery with espionage capabilities. Their most prominent toolset includes the Mortar Loader V3—an Office add‑in based payload that delivers shellcode into victim systems while avoiding detection through stealthy execution paths. Once compromised, victims are instrumented with the BRICKSTORM backdoor, which features a SOCKS proxy for covert command and control, as well as optional credential harvesting modules. Ransomware deployment follows a double‑extortion model: data is first exfiltrated via native OS APIs or via cloud connectors, then encrypted using an RSA‑based key or a Rust‑derived cryptographic routine. Custom ransomware variants (e.g., MORTAR or BlackSuit) modify file extensions and terminate anti‑malware services to accelerate payoff. Beyond ransomware, Mortar demonstrates supply‑chain reach—injecting malicious updates into legitimate software—and employs mobile malware such as Pineflower for surveillance in Android environments. Phishing campaigns are sophisticated, often leveraging IABs, typo‑squatted domains or phishing kits (GCollection) to deliver attachments and links. Operationally, the group relies on “living off the land” primitives (PowerShell scripts, Windows binaries like rundll32), remote desktop persistence, and Cobalt Strike for post‑exploitation movement. They target a broad spectrum of organizations with no apparent sector focus, although critical infrastructure and high‑profile commercial entities are frequent targets due to their ability to pay. Overall, Mortar’s dual threat profile—extortion plus ongoing espionage via backdoors—creates significant risks for medium‑sized enterprises that lack robust detection for Office add‑ins, RDP exfiltration, or cloud‑to‑cloud lateral movement.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Mortar is a financially‑motivated ransomware group that combines stealthy initial access via Office add‑ins and phishing with an espionage‑grade backdoor (BRICKSTORM) and a custom ransomware engine. The actors exploit cloud storage, supply‑chain vulnerabilities, and credential theft to exfiltrate data before encrypting victims, leveraging double‑extortion tactics to maximize revenue.
Goals & Targeting
Mortar’s strategic objective is to extract maximum financial value through ransomware while extracting data for dual extortion and potentially for longer‑term espionage. The group pursues a wide target spectrum with no clear sector bias, focusing instead on organizations offering high revenue potential or rich data assets. Through stealthy initial access techniques (phishing via Office add‑ins), rapid lateral movement, and persistent backdoors, Mortar maintains prolonged presence enabling both immediate ransom demands and delayed intel exploitation. By leveraging cloud services (OneDrive, Azure AD, Okta) they seek to exfiltrate data with minimal network visibility. Their use of custom ransomware coupled with supply‑chain attacks signals an intent to evolve defensively against patching cycles and detection systems while capitalizing on privileged access. In sum, Mortar combines short‑term ransom pressure with long‑term data extraction missions to satisfy financial motives while sustaining espionage capabilities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Mortar campaigns typically follow a rapid, double‑extortion pattern: spearphishing initiates compromise; the loader places BRICKSTORM for persistence and data theft; ransomware is then deployed on a wide range of systems—from Windows workstations to Linux servers and ESXi hosts—often in under an hour. The actor shares infrastructure with other cybercriminal RaaS groups (e.g., Akira, LockBit) through mutual backdoor libraries, suggesting operational collaboration or shared codebases. Victim profiles skew toward organizations with remote workforces leveraging cloud services, offering abundant credential vaults and backup systems that are easy to encrypt. Attackers often exploit zero‑day vulnerabilities (ProxyShell/Exchange, Log4Shell) or credential stuffing when initial access fails. The group employs a mix of waterhole sites, typo‑scattered domains, and malicious URLs bundled in phishing emails. Defensive posture reveals that incidents peak during major public events or fiscal closures, aligning with higher willingness to pay. Notable operations include the deployment of Rhysida ransomware across multiple sectors and a coordinated exfiltration followed by a Wiper payload aimed at Israeli infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence is derived from multiple, partially overlapping sources that collectively outline Mortar’s malware toolkit, operational tactics, and attack lifecycle. While the core capabilities—Office add‑in delivery, Brickstorm backdoor, double‑extortion ransomware—are consistently reported, gaps remain regarding precise target sectors, attribution depth, and the full scope of infrastructure used. Overall confidence is moderate; ongoing monitoring and intelligence collection are essential to refine activity patterns.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
51
Tools
0
Campaigns
38
IOCs
0
Observed Data
6
Tactics