Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: bashe, Eraleig

Description

A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the group reportedly self-proclaimed as an APT, which stands for 'Advanced Persistent Threat' in the cybersecurity field.<br> <br> According to research, much of the available information about the aforementioned group came from another ransomware group known as LockBit.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 140

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 months ago

Executive Summary

APT73 is a medium-sophistication ransomware group that emerged in mid-April 2024, with a primary motivation of organizational gain through financial extortion. The group has reportedly self-proclaimed as an Advanced Persistent Threat, and much of the available information about them came from another ransomware group known as LockBit. With over 140 known victims, APT73 poses a significant threat to various sectors and countries.

Goals & Targeting

APT73's strategic objectives are centered around generating revenue through ransomware attacks, with a primary focus on organizational gain. The group's targeting profile is likely focused on sectors and countries that are perceived as having valuable data and the ability to pay significant ransom demands. Typical victims of APT73 may include organizations with sensitive information, such as financial institutions, healthcare providers, and government agencies. The group's motivations and targeting profile suggest that they are likely to continue attacking organizations that can provide them with substantial financial gains.

Enhanced Description

The emergence of APT73 highlights the ongoing evolution of the ransomware landscape, where new groups and actors continually appear and disappear. The group's self-proclaimed APT designation and potential connection to LockBit may indicate a shift towards more sophisticated and persistent ransomware operations. As such, it is crucial for organizations to remain vigilant and proactive in their cybersecurity measures to mitigate the risk of APT73 and other ransomware threats.

Key Capabilities

  • Ransomware development and deployment
  • Network exploitation and lateral movement
  • Data encryption and exfiltration
  • Social engineering and phishing
  • Use of advanced evasion techniques

MITRE ATT&CK Tactics

Defense Evasion
Credential Access
Discovery
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204
T1550.002

Software / Tooling

Custom ransomware
Phishing kits
Exploit kits
Remote access tools
Data exfiltration tools

Campaigns & Victims

APT73's campaign patterns are likely characterized by a high operational tempo, with the group continuously targeting new organizations and sectors. The group's notable past operations include the compromise of over 140 organizations, with the potential for future attacks to be more sophisticated and destructive. APT73's use of ransomware and data exfiltration tactics suggests that they are focused on generating revenue and causing disruption to their targets. The group's potential connection to LockBit may indicate a larger campaign or operation, with multiple groups working together to achieve common goals.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Use of custom ransomware variants
  • Data exfiltration via encrypted channels

Recommended Actions

  • Implement robust email security measures to prevent phishing attacks
  • Use advanced threat detection and response tools to identify and mitigate ransomware attacks
  • Conduct regular backups and ensure data integrity
  • Implement a comprehensive incident response plan
  • Provide cybersecurity awareness training to employees

Suggested Tags

Ransomware
APT
Financial crime
Cybercrime
Data exfiltration

Confidence Assessment

The confidence level in the available data about APT73 is moderate, as much of the information comes from a single source (LockBit) and there is limited context about the group's operations and motivations. There are several information gaps, including the group's targeting profile, potential connections to other ransomware groups, and the extent of their capabilities. Further research and analysis are necessary to fill these gaps and provide a more comprehensive understanding of APT73's threat landscape.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 16 IPv4 Address 1

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

84

Campaigns

17

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 1, 2023
Last Seen
Jul 24, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.