Also known as: et al, tracked as, fail-first policies, step therapy protocols, Ueda T, Sasaki T, Nishihara T
L Group emerged in the threat landscape around 2024–2025 and has maintained activity through at least June 2026, as evidenced by recent reports of new drops and leak sites dedicated to the group. The actor is classified as a criminal enterprise employing ransomware for direct financial benefit, targeting organizations with perceived lower security posture such as non‑profits and manufacturing firms. Operationally, L Group utilizes standard penetration techniques—including spear‑phishing emails and exploitation of public‑facing services—to compromise victim systems. Once inside, the group escalates privileges (often via well‑known tools such as Mimikatz) and installs a custom or existing RAT to maintain persistence and move laterally. The ransomware payload is delivered through various delivery vectors including macro‑laden Office documents, compromised web servers, and potentially exploit kits. The actor’s focus on non‑profit institutions suggests an opportunistic strategy: these organizations often possess less robust cyber defenses, limited budgets, and high reputational impact that can compel rapid ransom payment. In manufacturing environments, L Group may target critical control systems for higher leverage or to create a sense of urgency. All factual statements regarding victim counts, activity dates, and domain-based staging were drawn from the latest available threat reports and intelligence feeds collected between 2023 and 2026.
Objectives
Targeted Sectors
Executive Summary
L Group is a medium‑sophistication ransomware actor primarily focused on financial gain through organizational disruption. The actor has been active at least until mid‑2026 and reportedly affected approximately 26 victims, with a noted preference for non‑profit and manufacturing targets. Their operations appear to leverage typical ransomware tactics such as phishing and credential theft to gain initial access.
Goals & Targeting
L Group seeks immediate financial return through ransom payments, exploiting organizational vulnerabilities in sectors that are either under‑provisioned for cybersecurity or whose operational mission creates high pressure to restore services quickly. The selection of non‑profit and manufacturing targets likely reflects a calculated assessment of the lower security hygiene relative to their defensive budgets and a higher likelihood of payment due to service disruption. Their typical victims include small‑to‑medium sized NGOs, local manufacturing plants, and associated supply chain partners that may have interconnections via shared hosting or third‑party services.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns attributed to L Group exhibit a multi‑stage approach: initial reconnaissance via domain registration and DNS fingerprinting, followed by spear‑phishing campaigns tailored to individual victims. Once compromised, the actor deploys ransomware payloads through dropper modules that may be delivered in macro documents or as standalone executables. The operational tempo appears relatively slow-to-moderate; each campaign tends to focus on a limited number of high‑value targets rather than widespread mass phishing. Notably, earlier operations involved leak sites announcing available services and price points, suggesting an attempt at reputation building within the underground market. The group has used bulletproof hosting to stage malicious content and maintain command‑and‑control infrastructure, indicating some level of resource sophistication beyond basic hobbyist actors.
IOC Patterns
Recommended Actions
No observed data linked yet.
8
Techniques
24
Tools
26
Campaigns
40
IOCs
0
Observed Data
6
Tactics