**Toolset/Malware:** QNAPCrypt ransomware **Notes:** Operates from Union State & Ukraine
Targeted Countries / Regions
Executive Summary
FullofDeep is a nation-state level threat actor primarily engaged in espionage activities. The group has targeted specific sectors and countries, including the United Kingdom (GB) and Ukraine (UA), leveraging advanced tools such as QNAPCrypt ransomware. Their operations suggest a sophisticated capability to compromise systems with the goal of extracting sensitive information.
Goals & Targeting
FullofDeep's primary objective appears to be intelligence gathering, likely for state-sponsored espionage purposes. They target sectors and countries that align with their geopolitical interests, focusing on GB and UA as potential high-value targets for sensitive data. Their choice of ransomware indicates the ability to disrupt operations while also extracting information during the attack process.
Enhanced Description
FullofDeep represents a nation-state actor whose primary activity appears to be espionage-driven, targeting specific geopolitical regions and sectors. The group's use of QNAPCrypt ransomware indicates a dual-capability for both disrupting operations through encryption and potentially gathering intelligence during the attack lifecycle. Operating from locations in Eastern Europe—likely Russia or another nearby state—they exhibit a regional focus on GB and UA, suggesting a strategic interest in these nations' political, economic, or military infrastructure. The actor's toolset suggests operational maturity, though additional details about their TTPs are limited to the known use of QNAPCrypt.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FullofDeep's campaigns are likely regionally focused, targeting GB and UA. Their use of QNAPCrypt suggests a preference for encrypting systems to extort ransoms while potentially exfiltrating data during the attack process. The group operates with a modus operandi consistent with nation-state actors, emphasizing stealth and long-term access.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on limited available data, primarily the identification of FullofDeep as a nation-state actor with a focus on GB and UA. Additional details regarding their TTPs and specific campaigns are needed to fully understand their modus operandi.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics