Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

0mega, also known in its attack kits as “Omega Lock,” surfaced publicly in May 2022 and has since evolved into a coordinated ransomware outfit that blends technical prowess with classic blackmail. The actors routinely acquire victim credentials via phishing, credential‑dumping (Mimikatz, LaZagne), and exploitation of public‑facing services (T1190). Once inside, they deploy the Omega Lock payload to lock file systems while exfiltrating data through tools such as RClone and then threaten public release unless a ransom is paid. Beyond traditional on‑prem attacks, 0mega targets cloud identity platforms—most notably Microsoft 365 administrator accounts—and modifies Azure or AWS resource provisioning to expand lateral reach without relying solely on compromised local credentials. This adaptability points to a mature threat actor that blends ransomware delivery with sophisticated persistence vectors such as WMI executions, scheduled tasks, and registry tweaks. The group benefits from bulletproof hosting ecosystems (Medialand LLC, ML.Cloud) to distribute malware, host malicious domains for phishing campaigns, and mask command‑and‑control traffic. Defensive measures reveal a pattern of disabling Windows Defender via defoff.bat, clearing event logs, wiping shadow copies, and employing rootkits or obfuscation techniques for stealth. While concrete attribution remains uncertain—some reports link the actors to CIA/JSOC personnel or Russian‐linked infrastructure—independent investigations confirm their financial motivation and high‑value target focus. Overall, 0mega’s operational tempo demonstrates a disciplined blend of phishing, credential dumping, cloud exploitation, and double‑extortion ransomware tactics that make it an evolving threat to multi‑sector entities worldwide.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Media
Food agriculture
Manufacturing
Critical infrastructure
Defense
Government
Oil gas

Targeted Countries / Regions

US
GB
AU

AI Analysis

Grounded in web research
· analyzed in 6 chunks · 3 days ago

Executive Summary

0mega is a medium‑sophistication criminal ransomware group that first emerged in mid‑2022. They employ double‑extortion tactics, combining on‑prem encryption with data exfiltration and publication threats to increase ransom leverage. Their reach spans high‑value sectors such as finance, defense, and critical infrastructure across the US, UK, and Australia.

Goals & Targeting

0mega seeks to maximize monetary gain by monetizing data theft and file encryption. Their strategic objective is to pressure victims through the dual threat of data exposure and system compromise, thereby forcing payment before the released material jeopardizes reputational or regulatory standing. The actor selectively targets organizations with high-value data, public visibility, or critical operational roles—especially within finance, defense, media, food‑agriculture, manufacturing, and energy sectors in the US, UK, and Australia—to exploit higher ransom expectations and potential for wider impact. By extending attacks into cloud platforms, 0mega increases its attack surface, allowing access to tenant identities, privileged accounts, and inter‑tenant data. This focus on identity infrastructure also raises their prospects of establishing persistence through compromised admin users, thereby enabling lateral movement without detection. The group’s emphasis on double‑extortion rather than single‑extortion illustrates a shift toward more sophisticated extortion models that leverage public exposure to magnify ransom pressure and incentivize faster payment, further aligning with their purely financial objectives. Key capabilities: The actors utilize phishing, credential dumping (Mimikatz, LaZagne), exploitation of public services, MFA manipulation, WMI usage, scheduled tasks for persistence, registry modifications to bypass UAC, rootkits for stealth, obfuscation via packing & dynamic API resolution, RClone for exfiltration, disabling Windows Defender, clearing logs and shadow copies, cloud compute instance creation/deletion, bulletproof hosting, DDoS (via botnets), MiTM attacks, LLMNR poisoning, and use of PsExec for lateral movement. They also leverage group policy changes to embed malicious code across domains.

Enhanced Description

Key Capabilities

  • Phishing campaigns with credential harvesting
  • Credential dumping via Mimikatz, LaZagne, WebBrowserPassView
  • Exploitation of public-facing applications (T1190)
  • MFA manipulation and account hijacking
  • WMI execution for persistence
  • Scheduled task creation/modification for autonomous execution
  • Registry modifications to bypass UAC and inject cmd.exe
  • Rootkit installation for stealth
  • Binary obfuscation through packing & dynamic API resolution
  • Disabling Windows Defender with defoff.bat
  • Clearing event logs, shadow copies, registry keys
  • Data exfiltration using RClone and third‑party cloud services
  • Double‑extortion (encryption + data theft threat)
  • Bulletproof hosting infrastructure for malware distribution
  • DDoS via botnets
  • Man‑in‑the‑Middle attacks on communications
  • LLMNR/NBT-NS poisoning for local adversary movement
  • Use of PsExec for lateral movement over SMB/ RDP
  • Group Policy modifications to spread malicious code
  • Automated cloud compute instance creation/deletion

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Acquisition
Discovery
Collection
Command and Control
Exfiltration
Resource Development
Impact

ATT&CK Techniques

T1190
T1098.005
T1566
T1003
T1520
T1070.001
T1562.004
T1021.004
T1112
T1485
T1047
T1037
T1053
T1014
T1027
T1007
T1021
T1005
T1486
T1566.001
T1110.003
T1078
T1552
T1529
T1105
T1547
T1542
T1562
T1686
T1080
T1074
T1098.003
T1036.004
T1046
T1490
T1053.005
T1068
T1690
T1111
T1109
T1123
T1210
T1134
T1578.002
T1518
T1534
T1550
T1560
T1561

Software / Tooling

Omega Lock
Alphalocker
Alphv
Bianlian
MIMIKATZ
LaZagne
WebBrowserPassView
VNCPassView
PasswordFox
ProcDump
defoff.bat
SmokeLoader
PsExec
RClone
Media Land
ML.Cloud
Medialand LLC
ML Cloud
Data Center Kirishi
Medialand Technology (MLT)

Campaigns & Victims

0mega’s operations surface annually since July 2022, with confirmed incidents in Q3 2022 against a high‑profile victim. The group targets large organizations that can afford sizable ransom payments and where data exposure would cause significant reputational damage. 0mega exhibits a consistent double‑extortion methodology: encrypt files, exfiltrate data, threaten public release, then demand payment—typically within 14–30 days of infection. Operational tempo is moderate to high: multiple campaigns appear per quarter and show geographic spread primarily across the US, UK, and Australia. The actors adapt swiftly by shifting from pure on‑prem attacks to cloud‑centric tactics such as Microsoft 365 admin credential compromise and dynamic cloud instance creation/deletion. Notable previous operations include a 2022 ransomware incident detailed in an academic report where victims endured both encryption and data leakage, and a 2024 advisory citing bulletproof hosting usage for malware delivery. National security agencies have placed the group on their watch list for its potential impact on critical infrastructure.

IOC Patterns

  • malicious batch defoff.bat disabling Windows Defender
  • registry modifications bypassing UAC and injecting cmd.exe
  • exfiltration via RClone cloud service
  • bulletproof hosting domains
  • phishing domain infrastructure
  • malicious email attachments with names resembling legitimate software
  • brute‑force login attempts on authentication services

Recommended Actions

  • Block or mitigate bulletproof hosting providers used for malware distribution
  • Apply OFAC sanctions and asset freezes against identified hosting operators (Medialand LLC, ML.Cloud)
  • Implement proactive blocked domains lists updated from threat feeds for known phishing infrastructure
  • Deploy endpoint detection that specifically alerts for defoff.bat execution and Windows Defender disablement scripts
  • Enable monitoring of new or modified Scheduled Tasks and WMI execution requests to catch persistence attempts
  • Enforce code signing validation for all executable/PowerShell scripts within the corporate environment
  • Monitor registry changes that affect UAC, Group Policy objects, and security settings
  • Detect credential dumping techniques (LSASS memory reads, SAM access) with behavioral sensors
  • Restrict untrusted RDP/SMB connections and enforce MFA everywhere
  • Deploy a cloud resource change tracker that alerts on new instance creation or deletion across Azure/AWS/GCP
  • Integrate phishing detection solutions based on malicious email indicators such as known sending domains and attachment patterns
  • Conduct regular security awareness training focusing on spear‑phishing and double‑extortion scenarios

Suggested Tags

ransomware
double-extortion
phishing
credential-dumping
MFA-manipulation
cloud-identity-compromise
bulletproof-hosting
DDoS
Man-in-the-Middle
WMI-execution
scheduled-task-persistence
rootkit-stealth
defender-disabling
log-clearing
shadow-copy-deletion
reg-bypass-UAC
RClone-exfiltration
PsExec lateral movement
group-policy-modification
LLMNR-poisoning
startup-folder-attack
cloud-resource-manipulation
critical-infrastructure-targeted
data-encryption
financial-gain

Confidence Assessment

The body of evidence for 0mega’s ransomware campaigns and double‑extortion tactics is moderate to high, supported by multiple independent incident reports from 2022–2024. Attribution claims linking the group to CIA/JSOC personnel or a Russian state actor stem from single-source reports and lack corroborating forensic data; consequently confidence in those attribution aspects is low. The technical footprint—including use of Mimikatz, RClone, defoff.bat, and bulletproof hosting—is well documented. Information gaps remain regarding the group’s internal organizational structure, exact funding mechanisms, precise chain of command, and detailed linkage to national‑state actors. Additionally, the extent of automated versus human coordination in campaign rollouts is unclear. Sources: - https://greydynamics.com/omega-teams-cia-jsoc-hunter-killer-teams/ - https://www.kelacyber.com/wp-content/uploads/2022/10/KELA-RESEARCH_Ransomware-Victims-and-Network-Access-Sales-in-Q3-2022.pdf - https://cisa.gov/news-events/cybersecurity-advisories/aa24-290a - https://theprnet.com/news/41645 - https://he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion

ATT&CK Techniques

Command & Control
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.ransomware.live — Cited by web research for: T1547.001
  2. www.trendmicro.com — Cited by web research for: phishing
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: Soul
  4. www.justice.gov — Cited by web research for: PHOTO

Intel Summary

76

Techniques

60

Tools

0

Campaigns

42

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Data Exfiltration
Double-extortion
Cloud-based extortion
Financial gain
ransomware
double-extortion
financial-gain
cloud-extortion
criminal
microsoft365
cloud extortion
0mega
Bad Batch
Credential Access
Account Manipulation
Brute Force
MFA Modification
CISA Threat
phishing
credential‑dumping
defense‑evasion
exfiltration
DDOS
MITM
lateral‑movement
cybercrime
criminal organization
bulletproof hosting
cryptocurrency extortion
sanctioned entity
masquerading
obfuscation
process injection
net-sniffing
dll hijack
registry run key persistence
credential theft
network discovery
LLMNR poisoning
UAC bypass
system binary proxy execution
clear event logs
file deletion
hidden artifacts
credential-dumping
MFA-manipulation
cloud-identity-compromise
bulletproof-hosting
DDoS
Man-in-the-Middle
WMI-execution
scheduled-task-persistence
rootkit-stealth
defender-disabling
log-clearing
shadow-copy-deletion
reg-bypass-UAC
RClone-exfiltration
PsExec lateral movement
group-policy-modification
LLMNR-poisoning
startup-folder-attack
cloud-resource-manipulation
critical-infrastructure-targeted
data-encryption

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jul 14, 2022
Last Seen
Jan 25, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.