Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors exfilsquad

Also known as: tracked as, Abyss Locker

Description

ExfilSquad emerged in mid‑2024 as a double‑extortion ransomware group that prioritizes data theft over immediate system impact. The actor employs compromised credentials or vulnerable Remote Desktop services (RDP) for initial access, then rapidly expands lateral movement within the victim network, performing extensive internal reconnaissance to identify high‑value corporate and personal files. Once sufficient data is identified, ExfilSquad exfiltrates it using application‑layer protocols such as HTTP/T1071 and legitimate cloud services. The stolen datasets are posted on public leak sites or dark‑web domains, naming the victim organization in an attempt to amplify reputational damage. Only after confirming that the target will not release the data willingly does the group proceed to encrypt systems with its custom ransomware, demanding a ransom for both the encryption key and to prevent data publication. The group's attacks focus on mid‑to‑large enterprises—government agencies, educational institutions, technology vendors, financial firms and transportation companies. Notable incidents include alleged breaches of Microsoft (8 million records), Viavi Solutions (≈430 k PII records), Analog Devices, the City of Atlanta, and several other organizations in the United States, United Kingdom and Nigeria. Defensive guidance stresses constant monitoring of outbound traffic for exfiltration signatures, strict credential hygiene including MFA enforcement, robust perimeter hardening of RDP services, reliable off‑site backups and the use of threat intelligence feeds that track double‑extortion ransomware activities.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Education
Government
Aviation
Financial services
Manufacturing
Gaming
Information technology
Media
Telecommunications
Transportation
Retail

Targeted Countries / Regions

GB
US
NG
FR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

ExfilSquad is a mid‑sophistication ransomware operator that has employed a double‑extortion tradecraft since mid‑2024. They prioritize data theft through credential theft or Remote Desktop exploitation before encrypting victims, publishing stolen data on leak sites to coerce payment. Their activities have been reported against high‑profile organizations across the United States, United Kingdom and Nigeria in sectors including education, government, finance, aviation, manufacturing and technology.

Goals & Targeting

ExfilSquad’s strategic objective is financial gain through a combined impact model: coercing victims to pay ransom while leveraging extortion via data disclosure. The organization targets medium‑to‑large entities that can produce sensitive records (staff, students, customers or government data) and thus generate high leverage for extortion. By publicly announcing data theft and publishing the exfiltrated material, ExfilSquad enhances reputational pressure, aiming to break victims’ resolve even if they possess strong internal security controls.

Enhanced Description

Key Capabilities

  • Initial access via compromised credentials or phishing
  • Exploitation of vulnerable Remote Desktop Services (RDP)
  • Rapid lateral movement within victim networks
  • Extensive internal reconnaissance post‑compromise
  • Data exfiltration of high‑value corporate, customer, employee and governmental records
  • Double‑extortion tradecraft: exfiltrate before encrypting
  • Public leak site publishing to coerce payments
  • Naming victims on claim platforms

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1071
T1537
T1567
T1486
T1566.001
T1021.004
T1041
T1078

Software / Tooling

PlugX
Royal
Clop
Qilin
Cobalt Strike
Dark
Qbot
Abyss Locker
Interlock
Pink
Chaos
Global
Resident
rock
STOP
DoxxScan
msaRAT

Campaigns & Victims

ExfilSquad operates on a rapid, opportunistic tempo, typically launching attacks within days of initial compromise. The group concentrates on large enterprises with valuable data repositories and high reputational leverage, and often exploits widely used protocols (RDP, HTTP) to widen their reach. Their campaigns are modular: they first exfiltrate in the background, then encrypt systems only when it increases extortion likelihood. Known operations have involved mass exfiltration claims followed by ransom demands, with a pattern of public leak site publication after victim refusals.

IOC Patterns

  • domains
  • email addresses
  • file hashes
  • exfiltration before encryption
  • leak site publication of stolen data
  • onion dark web postings of victim claims
  • unverified or fabricated breach statements

Recommended Actions

  • Implement MFA and strict access controls to prevent credential theft
  • Patch RDP services and reduce exposure by disabling unused remote protocols
  • Deploy network perimeter monitoring and anomaly detection for HTTP/S exfiltration traffic
  • Maintain offline backups and ransomware detection systems
  • Block known malicious domains, IPs and URLs identified in threat intelligence feeds
  • Hardening Microsoft-related accounts and services against credential compromise
  • Monitor official communications and trusted sources to verify extortion claims before taking action

Suggested Tags

cybercriminal
financially motivated
double-extortion
data-exfiltration
ransomware
remote-desktop exploitation
leak site publication
fabricated victim claim
high-profile target
unverified breach allegations
reputation damage leverage
targeting large enterprises

Confidence Assessment

The available intelligence offers a solid, moderate‑to-high confidence assessment of ExfilSquad’s double-extortion modus operandi and known operations against major organizations. However, several claims—including the alleged Microsoft breach—remain unverified and may contain fabricated statements. Key gaps persist regarding the group’s full toolchain, persistence mechanisms, detailed exploitation payloads, and precise geographic staging of attacks.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

Intel Summary

9

Techniques

28

Tools

15

Campaigns

4

IOCs

0

Observed Data

7

Tactics

Tags

Ransomware
Exfiltration
Criminal Activity
Financial Gain
Education Sector
Data Extortion
double_extortion
Credential Access
Dark Web Leak
Mass Exfiltration
Public Sector
Government Target
Corporate Target
High Activity
PII Theft
Financial Motive
Remote Desktop Service
Phishing
Internal Reconnaissance
cybercriminal
financially motivated
double-extortion
data-exfiltration
ransomware
remote-desktop exploitation
leak site publication
fabricated victim claim
high-profile target
unverified breach allegations
reputation damage leverage
targeting large enterprises

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
United States (US)
Confidence
80%
First Seen
Jul 26, 2026
Last Seen
Jul 26, 2026
Added
Jul 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.