Also known as: tracked as, Abyss Locker
ExfilSquad emerged in mid‑2024 as a double‑extortion ransomware group that prioritizes data theft over immediate system impact. The actor employs compromised credentials or vulnerable Remote Desktop services (RDP) for initial access, then rapidly expands lateral movement within the victim network, performing extensive internal reconnaissance to identify high‑value corporate and personal files. Once sufficient data is identified, ExfilSquad exfiltrates it using application‑layer protocols such as HTTP/T1071 and legitimate cloud services. The stolen datasets are posted on public leak sites or dark‑web domains, naming the victim organization in an attempt to amplify reputational damage. Only after confirming that the target will not release the data willingly does the group proceed to encrypt systems with its custom ransomware, demanding a ransom for both the encryption key and to prevent data publication. The group's attacks focus on mid‑to‑large enterprises—government agencies, educational institutions, technology vendors, financial firms and transportation companies. Notable incidents include alleged breaches of Microsoft (8 million records), Viavi Solutions (≈430 k PII records), Analog Devices, the City of Atlanta, and several other organizations in the United States, United Kingdom and Nigeria. Defensive guidance stresses constant monitoring of outbound traffic for exfiltration signatures, strict credential hygiene including MFA enforcement, robust perimeter hardening of RDP services, reliable off‑site backups and the use of threat intelligence feeds that track double‑extortion ransomware activities.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ExfilSquad is a mid‑sophistication ransomware operator that has employed a double‑extortion tradecraft since mid‑2024. They prioritize data theft through credential theft or Remote Desktop exploitation before encrypting victims, publishing stolen data on leak sites to coerce payment. Their activities have been reported against high‑profile organizations across the United States, United Kingdom and Nigeria in sectors including education, government, finance, aviation, manufacturing and technology.
Goals & Targeting
ExfilSquad’s strategic objective is financial gain through a combined impact model: coercing victims to pay ransom while leveraging extortion via data disclosure. The organization targets medium‑to‑large entities that can produce sensitive records (staff, students, customers or government data) and thus generate high leverage for extortion. By publicly announcing data theft and publishing the exfiltrated material, ExfilSquad enhances reputational pressure, aiming to break victims’ resolve even if they possess strong internal security controls.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ExfilSquad operates on a rapid, opportunistic tempo, typically launching attacks within days of initial compromise. The group concentrates on large enterprises with valuable data repositories and high reputational leverage, and often exploits widely used protocols (RDP, HTTP) to widen their reach. Their campaigns are modular: they first exfiltrate in the background, then encrypt systems only when it increases extortion likelihood. Known operations have involved mass exfiltration claims followed by ransom demands, with a pattern of public leak site publication after victim refusals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence offers a solid, moderate‑to-high confidence assessment of ExfilSquad’s double-extortion modus operandi and known operations against major organizations. However, several claims—including the alleged Microsoft breach—remain unverified and may contain fabricated statements. Key gaps persist regarding the group’s full toolchain, persistence mechanisms, detailed exploitation payloads, and precise geographic staging of attacks.
No observed data linked yet.
9
Techniques
28
Tools
15
Campaigns
4
IOCs
0
Observed Data
7
Tactics