Also known as: tracked as, APT43, Samurai Panda, PLA Navy, APT4, Wisp Team
TommyLeaks emerged as an operational front for the SchoolBoys ransomware cohort and shares many tactics, techniques, and procedures (TTPs) with other prominent extortion groups such as Conti and Akira. The gang uses a custom encryptor built from the LockBit 3.0 builder to lock victim assets while simultaneously exfiltrating data to public cloud services—Mega.io in particular—via tools like Rclone or FileZilla. The organization’s negotiation strategy relies on an anonymous TOR‑based chat portal originally utilized by Karakurt and various Conti offshoots, a deliberate rebranding effort designed to obfuscate true intent while increasing perceived credibility. Once inside, TommyLeaks performs credential dumping (NTDS.dit), privilege escalation using Mimikatz or PowerShell, installs Cobalt Strike for persistence, and deploys remote access tools such as AnyDesk. A hallmark of the group’s extortion methodology is the exploitation of high‑value data exfiltrated from victims—particularly sensitive child health records—to heighten pressure during ransom negotiations. The combination of ransomware delivery with targeted data leaks has earned TommyLeaks a reputation for higher-than-average financial gains and an elevated operational tempo across sectors. Despite law‑enforcement pressure, the dispersed nature of the gang’s infrastructure allows it to remain active. Its recent pattern of leveraging public cloud exfiltration channels, coupled with sophisticated negotiation tactics, suggests that they will continue to evolve their threat model while maintaining a focus on monetization through ransomware and data extortion.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TommyLeaks, operating as the front for SchoolBoys ransomware, executes a dual‑phase strategy of device encryption paired with strategic data exfiltration to pressure victims into paying $400–$700k ransom demands. The group has targeted over 54 organizations across finance, healthcare, telecommunications, and critical infrastructure between June 2021 and August 2023, incurring more than $56 million in losses. While a recent U.S. conviction disrupted one negotiator, the gang’s distributed infrastructure—leveraging VPN hijacking, remote access tools, and TOR‑based negotiation portals—allows continued attacks with medium sophistication.
Goals & Targeting
TommyLeaks’ strategic objectives revolve around maximizing monetary gain by blending conventional ransomware deployment with secondary data‑exfiltration extortion. The group focuses on high‑value sectors—finance, healthcare, energy, defense, telecommunications, mining, and critical infrastructure—where sensitive information can command severe leverage. By targeting jurisdictions that include the U.S., UK, China, Taiwan, Russia, Iran, and Canada (GB), they exploit global regulatory variances to impede coordinated law‑enforcement action while maintaining a broad geographic bleed. The selective use of compromised VPN credentials for initial access signals an opportunistic yet calculated approach: once inside, attackers pivot deep into networks using credential dumping and lateral movement frameworks (Cobalt Strike, AnyDesk). Leveraging public exfil channels such as Mega.io not only facilitates rapid data extraction but also masks the traffic from conventional network monitoring, allowing them to maintain persistence even after detection. Overall, TommyLeaks seeks to generate high‑value ransom payouts and secondary revenue streams by monetizing stolen data in a manner that exploits both technological flaws (VPN hijacking) and human factors (data sensitivity).
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TommyLeaks and its SchoolBoys front have executed a sustained campaign from at least June 2021 through August 2023, affecting more than 54 victims with a combined loss over $56 million. The operational tempo is moderate to high, characterized by rapid credential‑dumping and lateral movement that often culminates in encrypting endpoints while simultaneously exfiltrating data for dual extortion. Victims span highly regulated sectors such as healthcare, finance, energy, defense, and telecommunications, with geographic coverage that includes the U.S., U.K., R.I., China, Iran, Canada, Taiwan, and Russia. Notable incidents include a high‑profile attack on a U.S. government entity’s 911 dispatch system—disrupting critical services—and large-scale deployments in mining operations where data exfiltration was used to amplify ransom demands. The group’s tendency to use public cloud storages for exfil and Tor‑based negotiation portals suggests a desire for operational anonymity coupled with a high return on investment. Recent law‑enforcement actions, such as the U.S. conviction of a key TommyLeaks negotiator, have not halted operations—underscoring a resilient, decentralized structure that can continue attacking under new or modified aliases while preserving its core capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data is drawn from two reputable security analysis sources that provide consistent accounts of TommyLeaks’ activities, affiliations, and TTPs. While the description includes precise operational details—such as the use of a LockBit 3.0 builder encryptor, TOR negotiation portal, and exfiltration to Mega.io—the exact dates of first and last appearances remain unspecified, reducing temporal clarity. Attribution to a single criminal organization is supported but not conclusively proven; the dual‑front nature (TommyLeaks/SchoolBoys) introduces some uncertainty regarding internal structure. Overall confidence in the core capabilities, tactics, and campaign patterns is moderate‑high, with the main gaps lying in precise operational timelines, comprehensive geographic reach beyond indicated countries, and direct evidence linking all reported tools to every operation. Additional intelligence collection—such as network traffic captures confirming exfiltration URLs or verified ransom note samples—would further strengthen certainty.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
59
Tools
0
Campaigns
7
IOCs
0
Observed Data
7
Tactics