Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or sell stolen information rather than encrypting files, targeting technology, healthcare, manufacturing, telecom, and government sectors across multiple countries. Known victims: 16
Objectives
Executive Summary
Apos is a medium-sophistication criminal threat actor specializing in data-broker extortion. They surfaced in April 2024 and have targeted multiple sectors including technology, healthcare, manufacturing, telecom, and government across various countries. Apos focuses on data exfiltration, threatening to publish or sell stolen information for financial gain rather than encrypting files.
Goals & Targeting
Apos's strategic objectives center on financial gain through data extortion. They target sectors where stolen data holds significant value for resale or leverage in negotiations. Their choice of victims aligns with industries that could face severe reputational damage or regulatory consequences from data exposure, allowing Apos to apply maximum pressure during negotiations. The group's geographic diversity in targeting suggests a global approach rather than region-specific interests.
Enhanced Description
Apos operates as a cybercriminal group engaged in data extortion. They emerged in April 2024 and have conducted attacks against diverse industries, leveraging their capabilities to steal sensitive information and leveraging threats of publication or sale to coerce victims into compliance. Unlike ransomware-focused groups that encrypt files, Apos's primary modus operandi involves unauthorized access followed by data exfiltration. Their targeting strategy suggests a focus on sectors with high-value data, such as healthcare (with PHI) and government institutions, which are more susceptible to pressure from public exposure. The group's operational timeline indicates steady activity over the past year, with 16 known victims, suggesting they have both capability and intent to sustain their campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Apos demonstrates a consistent operational tempo over the past year, with campaigns targeting a mix of industries. Their victims include technology firms and healthcare providers, suggesting a strategic focus on sectors where data is highly sensitive or valuable. Notable patterns include an emphasis on data theft rather than system encryption, indicating their primary goal is financial gain through extortion. The group's campaigns often involve multi-faceted attack vectors, combining phishing with lateral movement to access critical systems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence exists regarding Apos's general characteristics and modus operandi. While the group has been observed targeting specific sectors with consistent TTPs, detailed information on their tools, exact campaign details, or infrastructure remains limited. This necessitates relying on broader patterns and educated guesses in certain areas.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics