Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors tommyleaks

Also known as: tracked as, APT43, Samurai Panda, PLA Navy, APT4, Wisp Team

Description

TommyLeaks emerged as an operational front for the SchoolBoys ransomware cohort and shares many tactics, techniques, and procedures (TTPs) with other prominent extortion groups such as Conti and Akira. The gang uses a custom encryptor built from the LockBit 3.0 builder to lock victim assets while simultaneously exfiltrating data to public cloud services—Mega.io in particular—via tools like Rclone or FileZilla. The organization’s negotiation strategy relies on an anonymous TOR‑based chat portal originally utilized by Karakurt and various Conti offshoots, a deliberate rebranding effort designed to obfuscate true intent while increasing perceived credibility. Once inside, TommyLeaks performs credential dumping (NTDS.dit), privilege escalation using Mimikatz or PowerShell, installs Cobalt Strike for persistence, and deploys remote access tools such as AnyDesk. A hallmark of the group’s extortion methodology is the exploitation of high‑value data exfiltrated from victims—particularly sensitive child health records—to heighten pressure during ransom negotiations. The combination of ransomware delivery with targeted data leaks has earned TommyLeaks a reputation for higher-than-average financial gains and an elevated operational tempo across sectors. Despite law‑enforcement pressure, the dispersed nature of the gang’s infrastructure allows it to remain active. Its recent pattern of leveraging public cloud exfiltration channels, coupled with sophisticated negotiation tactics, suggests that they will continue to evolve their threat model while maintaining a focus on monetization through ransomware and data extortion.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Healthcare
Government
Telecommunications
Energy
Mining
Critical infrastructure
Defense

Targeted Countries / Regions

US
TW
RU
GB
IR
CN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

TommyLeaks, operating as the front for SchoolBoys ransomware, executes a dual‑phase strategy of device encryption paired with strategic data exfiltration to pressure victims into paying $400–$700k ransom demands. The group has targeted over 54 organizations across finance, healthcare, telecommunications, and critical infrastructure between June 2021 and August 2023, incurring more than $56 million in losses. While a recent U.S. conviction disrupted one negotiator, the gang’s distributed infrastructure—leveraging VPN hijacking, remote access tools, and TOR‑based negotiation portals—allows continued attacks with medium sophistication.

Goals & Targeting

TommyLeaks’ strategic objectives revolve around maximizing monetary gain by blending conventional ransomware deployment with secondary data‑exfiltration extortion. The group focuses on high‑value sectors—finance, healthcare, energy, defense, telecommunications, mining, and critical infrastructure—where sensitive information can command severe leverage. By targeting jurisdictions that include the U.S., UK, China, Taiwan, Russia, Iran, and Canada (GB), they exploit global regulatory variances to impede coordinated law‑enforcement action while maintaining a broad geographic bleed. The selective use of compromised VPN credentials for initial access signals an opportunistic yet calculated approach: once inside, attackers pivot deep into networks using credential dumping and lateral movement frameworks (Cobalt Strike, AnyDesk). Leveraging public exfil channels such as Mega.io not only facilitates rapid data extraction but also masks the traffic from conventional network monitoring, allowing them to maintain persistence even after detection. Overall, TommyLeaks seeks to generate high‑value ransom payouts and secondary revenue streams by monetizing stolen data in a manner that exploits both technological flaws (VPN hijacking) and human factors (data sensitivity).

Enhanced Description

Key Capabilities

  • Data exfiltration as leverage
  • Device encryption using LockBit 3.0 builder encryptor
  • Negotiation via TOR‑based chat system
  • Leak and sell compromised sensitive records to pressure victims
  • Cryptocurrency laundering of ransom proceeds
  • Initial access through compromised VPN credentials
  • Persistence via Cobalt Strike
  • VPN IP pool switching
  • Installation of AnyDesk remote control tool
  • Privilege escalation using Mimikatz/PowerShell to harvest NTDS.dit from AD
  • Leverage stolen child health information for extortion

MITRE ATT&CK Tactics

Impact
Exfiltration
Initial Access
Persistence
Privilege Escalation
Credential Dumping

ATT&CK Techniques

T1486
T1048.001
T1071.004
T1078
T1003
T1059.001
T1086

Software / Tooling

LockBit 3.0 builder encryptor
Conti ransomware framework
Karakurt chat system
Cobalt Strike
AnyDesk
Mimikatz
PowerShell
SchoolBoys Ransomware
Akira

Campaigns & Victims

TommyLeaks and its SchoolBoys front have executed a sustained campaign from at least June 2021 through August 2023, affecting more than 54 victims with a combined loss over $56 million. The operational tempo is moderate to high, characterized by rapid credential‑dumping and lateral movement that often culminates in encrypting endpoints while simultaneously exfiltrating data for dual extortion. Victims span highly regulated sectors such as healthcare, finance, energy, defense, and telecommunications, with geographic coverage that includes the U.S., U.K., R.I., China, Iran, Canada, Taiwan, and Russia. Notable incidents include a high‑profile attack on a U.S. government entity’s 911 dispatch system—disrupting critical services—and large-scale deployments in mining operations where data exfiltration was used to amplify ransom demands. The group’s tendency to use public cloud storages for exfil and Tor‑based negotiation portals suggests a desire for operational anonymity coupled with a high return on investment. Recent law‑enforcement actions, such as the U.S. conviction of a key TommyLeaks negotiator, have not halted operations—underscoring a resilient, decentralized structure that can continue attacking under new or modified aliases while preserving its core capabilities.

IOC Patterns

  • TOR-based C2 channels
  • Cryptocurrency wallet addresses used for ransom payments
  • Encrypted ransomware payloads using Lockbit architecture
  • Publicly posted ransom notes containing multiple group aliases
  • Compromised VPN credentials
  • Cobalt Strike beacon activity
  • Installation of remote control tool AnyDesk
  • Extraction of NTDS.dit from Active Directory
  • Mimikatz credential dumping

Recommended Actions

  • Deploy detection for TOR‑based negotiation chats and suspicious data exfiltration to public cloud services
  • Block known LockBit 3.0 encryptor binaries via endpoint protection or file integrity monitoring
  • Log and alert on ransom note patterns across segmented network zones
  • Maintain robust, off‑site backups and test rapid recovery procedures
  • Enforce MFA on VPN and privileged accounts; monitor for anomalous credential usage
  • Segment networks to isolate AD controllers and enforce least‑privilege access controls
  • Detect and block remote control tools such as AnyDesk and Cobalt Strike beacons with UTM/EDR solutions
  • Implement real‑time monitoring of NTDS.dit extractions from domain controllers

Suggested Tags

ransomware
extortion
data leakage
TOR C2
LockBit 3.0
Conti offshoot
SchoolBoys
TommyLeaks
Karakurt
VPN hijacking
credential dumping
remote access tools
NTDS.exfiltration
child data exploitation
public cloud exfil

Confidence Assessment

The available data is drawn from two reputable security analysis sources that provide consistent accounts of TommyLeaks’ activities, affiliations, and TTPs. While the description includes precise operational details—such as the use of a LockBit 3.0 builder encryptor, TOR negotiation portal, and exfiltration to Mega.io—the exact dates of first and last appearances remain unspecified, reducing temporal clarity. Attribution to a single criminal organization is supported but not conclusively proven; the dual‑front nature (TommyLeaks/SchoolBoys) introduces some uncertainty regarding internal structure. Overall confidence in the core capabilities, tactics, and campaign patterns is moderate‑high, with the main gaps lying in precise operational timelines, comprehensive geographic reach beyond indicated countries, and direct evidence linking all reported tools to every operation. Additional intelligence collection—such as network traffic captures confirming exfiltration URLs or verified ransom note samples—would further strengthen certainty.

ATT&CK Techniques

Command & Control
1 technique
Credential Access
1 technique
Execution
1 technique
Stealth
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. https://arcticwolf.com/resources/blog/follow-on-extortion-campaign-targeting-victims-of-akira-and-royal-ransomware/ — Cited by AI analysis.
  2. https://www.bleepingcomputer.com/news/security/tommyleaks-and-schoolboys-two-sides-of-the-same-ransomware-gang/ — Cited by AI analysis.
  3. https://www.scworld.com/brief/tommyleaks-schoolboys-ransomware-gangs-found-to-be-the-same — Cited by AI analysis.
  4. https://www.cyberdaily.au/security/10008-ransomware-victims-lured-by-false-offers-to-counter-hack-attackers — Cited by AI analysis.
  5. https://www.bankinfosecurity.com/breach-roundup-microsoft-edge-turns-passwords-into-targets-a-31629 — Cited by AI analysis.
  6. https://www.ransomlook.io/browse — Cited by AI analysis.
  7. https://www.dailycourt.com/news/global-ransomware-group-negotiator-involved-in-56-million-cyberattacks-sentenced-to-8-5-years-in/article_b78210d1-c9d8-4da7-9539-ba9cc0b796dd.html — Cited by AI analysis.
  8. https://www.hhs.gov/sites/default/files/trinity-ransomware-threat-actor-profile.pdf — Cited by AI analysis.
  9. https://analyst1.com/karakurt-case-study-three-key-insights-to-consider-when-investigating-russian-ransomware/ — Cited by AI analysis.
  10. https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Threat%20Landscape%202023.pdf — Cited by AI analysis.
  11. https://www.ransomware.live/groups — Cited by AI analysis.
  12. https://www.gendigital.com/blog/insights/reports/avast-q32022-threat-report — Cited by AI analysis.
  13. https://regmedia.co.uk/2024/08/23/zolotarjovs_complaint.pdf — Cited by AI analysis.
  14. https://github.com/cert-orangecyberdefense/ransomware_map — Cited by AI analysis.
  15. https://www.securityweek.com/karakurt-ransomware-negotiator-sentenced-to-prison/ — Cited by AI analysis.
  16. https://socradar.io/free-tools/ransomware-intelligence/groups/worldleaks — Cited by AI analysis.
  17. https://www.clarkhill.com/news-events/news/right-to-know-june-2026-vol-42/ — Cited by AI analysis.
  18. https://securityboulevard.com/2026/06/the-new-face-of-cybercrime-when-the-criminal-isnt-the-hacker/ — Cited by AI analysis.
  19. https://cyberscoop.com/latvian-russia-ransomware-conti-sentenced/ — Cited by AI analysis.
  20. https://www.mallory.ai/stories/019e5fca-505e-70f5-8e5a-3d59db0ac402 — Cited by AI analysis.
  21. https://securityaffairs.com/191722/cyber-crime/u-s-court-sentences-karakurt-ransomware-negotiator-to-8-5-years.html — Cited by AI analysis.
  22. https://www.ransomware.live/group/Tommyleaks — Cited by AI analysis.
  23. https://www.itpro.com/security/ransomware/ransomware-negotiator-sentenced-for-role-in-major-cyber-crime-group — Cited by AI analysis.

Intel Summary

7

Techniques

59

Tools

0

Campaigns

7

IOCs

0

Observed Data

7

Tactics

Tags

APT
Ransomware
Financial Crime
Disruption
extortion
double-extortion
ransomware
post-incident-extortion
tommyleaks
schoolboys
lockbit 3.0 builder
conti
karakurt
akira
health data breach
child records
law-enforcement-connections
tor-based c2
impersonation
corporate targeting
credential dumping
privilege escalation
cloud exfiltration
vpn credential exploitation
organized cybercrime
data leakage
TOR C2
LockBit 3.0
Conti offshoot
SchoolBoys
TommyLeaks
Karakurt
VPN hijacking
remote access tools
NTDS.exfiltration
child data exploitation
public cloud exfil

Details

MITRE ID
APT4
Type
Criminal
Sophistication
Medium
Resource Level
Government
Primary Motivation
Organizational gain
Country of Origin
United States (US)
Confidence
80%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.