Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors l group

Also known as: et al, tracked as, fail-first policies, step therapy protocols, Ueda T, Sasaki T, Nishihara T

Description

L Group emerged in the threat landscape around 2024–2025 and has maintained activity through at least June 2026, as evidenced by recent reports of new drops and leak sites dedicated to the group. The actor is classified as a criminal enterprise employing ransomware for direct financial benefit, targeting organizations with perceived lower security posture such as non‑profits and manufacturing firms. Operationally, L Group utilizes standard penetration techniques—including spear‑phishing emails and exploitation of public‑facing services—to compromise victim systems. Once inside, the group escalates privileges (often via well‑known tools such as Mimikatz) and installs a custom or existing RAT to maintain persistence and move laterally. The ransomware payload is delivered through various delivery vectors including macro‑laden Office documents, compromised web servers, and potentially exploit kits. The actor’s focus on non‑profit institutions suggests an opportunistic strategy: these organizations often possess less robust cyber defenses, limited budgets, and high reputational impact that can compel rapid ransom payment. In manufacturing environments, L Group may target critical control systems for higher leverage or to create a sense of urgency. All factual statements regarding victim counts, activity dates, and domain-based staging were drawn from the latest available threat reports and intelligence feeds collected between 2023 and 2026.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Non profit
Manufacturing

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

L Group is a medium‑sophistication ransomware actor primarily focused on financial gain through organizational disruption. The actor has been active at least until mid‑2026 and reportedly affected approximately 26 victims, with a noted preference for non‑profit and manufacturing targets. Their operations appear to leverage typical ransomware tactics such as phishing and credential theft to gain initial access.

Goals & Targeting

L Group seeks immediate financial return through ransom payments, exploiting organizational vulnerabilities in sectors that are either under‑provisioned for cybersecurity or whose operational mission creates high pressure to restore services quickly. The selection of non‑profit and manufacturing targets likely reflects a calculated assessment of the lower security hygiene relative to their defensive budgets and a higher likelihood of payment due to service disruption. Their typical victims include small‑to‑medium sized NGOs, local manufacturing plants, and associated supply chain partners that may have interconnections via shared hosting or third‑party services.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious attachments
  • Exploitation of public‑facing web applications
  • Credential dumping via Mimikatz or similar tools
  • Installation of remote admin trojans for persistence
  • Command‑and‑control over encrypted channels
  • Encryption of victim data using strong ransomware cryptography

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1566.001
T1059.003
T1078.002
T1063
T1105
T1087.002
T1518.002

Software / Tooling

Cobalt Strike (or equivalent beacon)
Mimikatz
Custom RAT
WMI-based persistence scripts

Campaigns & Victims

Campaigns attributed to L Group exhibit a multi‑stage approach: initial reconnaissance via domain registration and DNS fingerprinting, followed by spear‑phishing campaigns tailored to individual victims. Once compromised, the actor deploys ransomware payloads through dropper modules that may be delivered in macro documents or as standalone executables. The operational tempo appears relatively slow-to-moderate; each campaign tends to focus on a limited number of high‑value targets rather than widespread mass phishing. Notably, earlier operations involved leak sites announcing available services and price points, suggesting an attempt at reputation building within the underground market. The group has used bulletproof hosting to stage malicious content and maintain command‑and‑control infrastructure, indicating some level of resource sophistication beyond basic hobbyist actors.

IOC Patterns

  • Spear‑phishing with macro‑laden Office documents
  • Spear‑phishing emails with password‑protected archives
  • Use of compromised web servers as drop sites
  • C2 over HTTPS or obscured DNS channels (fast‑flux)
  • Bulletproof hosting for staging and C2

Recommended Actions

  • Implement multi‑factor authentication across all critical services, especially RDP and admin portals.
  • Regularly patch operating systems and applications to mitigate public‑facing exploit vectors.
  • Deploy advanced email filtering and user training focused on spotting spear‑phishing attempts.” “Maintain out‑of‑date and offline backups that are regularly tested for integrity. “Restrict privileged account usage via least‑privilege principles and enforce strict session monitoring. “Develop and rehearse a ransomware incident response plan to minimize dwell time.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. pmc.ncbi.nlm.nih.gov — Cited by web research for: et al
  2. www.galaxywarden.com — Cited by web research for: DoxxScan
  3. www.ecfr.gov — Cited by web research for: FederalRegister.gov

Intel Summary

8

Techniques

24

Tools

26

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Last Seen
Jun 26, 2026
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.