0mega, also known in its attack kits as “Omega Lock,” surfaced publicly in May 2022 and has since evolved into a coordinated ransomware outfit that blends technical prowess with classic blackmail. The actors routinely acquire victim credentials via phishing, credential‑dumping (Mimikatz, LaZagne), and exploitation of public‑facing services (T1190). Once inside, they deploy the Omega Lock payload to lock file systems while exfiltrating data through tools such as RClone and then threaten public release unless a ransom is paid. Beyond traditional on‑prem attacks, 0mega targets cloud identity platforms—most notably Microsoft 365 administrator accounts—and modifies Azure or AWS resource provisioning to expand lateral reach without relying solely on compromised local credentials. This adaptability points to a mature threat actor that blends ransomware delivery with sophisticated persistence vectors such as WMI executions, scheduled tasks, and registry tweaks. The group benefits from bulletproof hosting ecosystems (Medialand LLC, ML.Cloud) to distribute malware, host malicious domains for phishing campaigns, and mask command‑and‑control traffic. Defensive measures reveal a pattern of disabling Windows Defender via defoff.bat, clearing event logs, wiping shadow copies, and employing rootkits or obfuscation techniques for stealth. While concrete attribution remains uncertain—some reports link the actors to CIA/JSOC personnel or Russian‐linked infrastructure—independent investigations confirm their financial motivation and high‑value target focus. Overall, 0mega’s operational tempo demonstrates a disciplined blend of phishing, credential dumping, cloud exploitation, and double‑extortion ransomware tactics that make it an evolving threat to multi‑sector entities worldwide.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
0mega is a medium‑sophistication criminal ransomware group that first emerged in mid‑2022. They employ double‑extortion tactics, combining on‑prem encryption with data exfiltration and publication threats to increase ransom leverage. Their reach spans high‑value sectors such as finance, defense, and critical infrastructure across the US, UK, and Australia.
Goals & Targeting
0mega seeks to maximize monetary gain by monetizing data theft and file encryption. Their strategic objective is to pressure victims through the dual threat of data exposure and system compromise, thereby forcing payment before the released material jeopardizes reputational or regulatory standing. The actor selectively targets organizations with high-value data, public visibility, or critical operational roles—especially within finance, defense, media, food‑agriculture, manufacturing, and energy sectors in the US, UK, and Australia—to exploit higher ransom expectations and potential for wider impact. By extending attacks into cloud platforms, 0mega increases its attack surface, allowing access to tenant identities, privileged accounts, and inter‑tenant data. This focus on identity infrastructure also raises their prospects of establishing persistence through compromised admin users, thereby enabling lateral movement without detection. The group’s emphasis on double‑extortion rather than single‑extortion illustrates a shift toward more sophisticated extortion models that leverage public exposure to magnify ransom pressure and incentivize faster payment, further aligning with their purely financial objectives. Key capabilities: The actors utilize phishing, credential dumping (Mimikatz, LaZagne), exploitation of public services, MFA manipulation, WMI usage, scheduled tasks for persistence, registry modifications to bypass UAC, rootkits for stealth, obfuscation via packing & dynamic API resolution, RClone for exfiltration, disabling Windows Defender, clearing logs and shadow copies, cloud compute instance creation/deletion, bulletproof hosting, DDoS (via botnets), MiTM attacks, LLMNR poisoning, and use of PsExec for lateral movement. They also leverage group policy changes to embed malicious code across domains.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
0mega’s operations surface annually since July 2022, with confirmed incidents in Q3 2022 against a high‑profile victim. The group targets large organizations that can afford sizable ransom payments and where data exposure would cause significant reputational damage. 0mega exhibits a consistent double‑extortion methodology: encrypt files, exfiltrate data, threaten public release, then demand payment—typically within 14–30 days of infection. Operational tempo is moderate to high: multiple campaigns appear per quarter and show geographic spread primarily across the US, UK, and Australia. The actors adapt swiftly by shifting from pure on‑prem attacks to cloud‑centric tactics such as Microsoft 365 admin credential compromise and dynamic cloud instance creation/deletion. Notable previous operations include a 2022 ransomware incident detailed in an academic report where victims endured both encryption and data leakage, and a 2024 advisory citing bulletproof hosting usage for malware delivery. National security agencies have placed the group on their watch list for its potential impact on critical infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The body of evidence for 0mega’s ransomware campaigns and double‑extortion tactics is moderate to high, supported by multiple independent incident reports from 2022–2024. Attribution claims linking the group to CIA/JSOC personnel or a Russian state actor stem from single-source reports and lack corroborating forensic data; consequently confidence in those attribution aspects is low. The technical footprint—including use of Mimikatz, RClone, defoff.bat, and bulletproof hosting—is well documented. Information gaps remain regarding the group’s internal organizational structure, exact funding mechanisms, precise chain of command, and detailed linkage to national‑state actors. Additionally, the extent of automated versus human coordination in campaign rollouts is unclear. Sources: - https://greydynamics.com/omega-teams-cia-jsoc-hunter-killer-teams/ - https://www.kelacyber.com/wp-content/uploads/2022/10/KELA-RESEARCH_Ransomware-Victims-and-Network-Access-Sales-in-Q3-2022.pdf - https://cisa.gov/news-events/cybersecurity-advisories/aa24-290a - https://theprnet.com/news/41645 - https://he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion
No campaigns linked yet.
No observed data linked yet.
76
Techniques
60
Tools
0
Campaigns
42
IOCs
0
Observed Data
13
Tactics