Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FullofDeep

Description

**Toolset/Malware:** QNAPCrypt ransomware **Notes:** Operates from Union State & Ukraine

Goals & Targeting

Targeted Countries / Regions

GB
UA

AI Analysis

· 1 week ago

Executive Summary

FullofDeep is a nation-state level threat actor primarily engaged in espionage activities. The group has targeted specific sectors and countries, including the United Kingdom (GB) and Ukraine (UA), leveraging advanced tools such as QNAPCrypt ransomware. Their operations suggest a sophisticated capability to compromise systems with the goal of extracting sensitive information.

Goals & Targeting

FullofDeep's primary objective appears to be intelligence gathering, likely for state-sponsored espionage purposes. They target sectors and countries that align with their geopolitical interests, focusing on GB and UA as potential high-value targets for sensitive data. Their choice of ransomware indicates the ability to disrupt operations while also extracting information during the attack process.

Enhanced Description

FullofDeep represents a nation-state actor whose primary activity appears to be espionage-driven, targeting specific geopolitical regions and sectors. The group's use of QNAPCrypt ransomware indicates a dual-capability for both disrupting operations through encryption and potentially gathering intelligence during the attack lifecycle. Operating from locations in Eastern Europe—likely Russia or another nearby state—they exhibit a regional focus on GB and UA, suggesting a strategic interest in these nations' political, economic, or military infrastructure. The actor's toolset suggests operational maturity, though additional details about their TTPs are limited to the known use of QNAPCrypt.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Use of QNAPCrypt ransomware
  • Geographically targeted attacks
  • Espionage-focused activities

MITRE ATT&CK Tactics

Reconnaissance
Lateral Access Expansion
Staged Access

ATT&CK Techniques

T1566.003
T1003
T1021
T1084

Software / Tooling

QNAPCrypt ransomware

Campaigns & Victims

FullofDeep's campaigns are likely regionally focused, targeting GB and UA. Their use of QNAPCrypt suggests a preference for encrypting systems to extort ransoms while potentially exfiltrating data during the attack process. The group operates with a modus operandi consistent with nation-state actors, emphasizing stealth and long-term access.

IOC Patterns

  • Spear-phishing targeting specific sectors
  • Use of QNAPCrypt ransomware for system encryption
  • Indicator activity linked to nation-state espionage tools

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to identify advanced threats.
  • Conduct regular vulnerability assessments and patch management to mitigate exploit attempts.
  • Monitor network traffic for signs of data exfiltration or encrypted communications.

Suggested Tags

nation-state
espionage
ransomware
GB
UA

Confidence Assessment

The analysis is based on limited available data, primarily the identification of FullofDeep as a nation-state actor with a focus on GB and UA. Additional details regarding their TTPs and specific campaigns are needed to fully understand their modus operandi.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
nation-state
espionage
ransomware
GB
UA

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.