Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going offline, with very little public documentation about their tactics, targets, or tooling. Known victims: 3
Objectives
Executive Summary
Bonaci Group is a medium-sophistication criminal threat actor specializing in ransomware attacks. Active for only a short period in late 2021, this group targeted at least three known victims before going offline. Their primary motivation appears to be financial gain through ransom demands, with no evidence of state-sponsored activity or advanced persistent tactics.
Goals & Targeting
Bonaci Group's primary goals align with typical ransomware operators: organizational disruption and direct financial gain through encrypting victims' data and demanding ransoms. Their targeting profile, however, remains underdetermined due to limited reporting, though their minimal victim count suggests they may have targeted smaller or less sophisticated organizations. There is no evidence of sector-specific targeting; Bonaci Group's activity appears indiscriminate, potentially reflecting a basic operational approach.
Enhanced Description
Bonaci Group emerged as a short-lived ransomware operation during the latter half of 2021. With limited public documentation, their exact tactics and tooling remain unclear. The group appears to have targeted three victims, though specific details about their targeting criteria—such as sector or geography—as well as their operational methods are absent from available intelligence. Bonaci Group's activity spanned a short timeframe, with their first known activity occurring on 2021-10-04 and last seen activity on 2021-12-06. Despite the brief duration of operations, their emergence highlights the ongoing evolution of ransomware-as-a-service (RaaS) offerings targeting small to medium-sized businesses for quick financial gains.
Key Capabilities
Software / Tooling
Campaigns & Victims
Bonaci Group's campaign remains poorly documented, with only three confirmed victims and a short operational window. Their lack of high-profile targets suggests they were likely a less experienced or resource-constrained group. The group's brief activity may indicate either early retirement, law enforcement intervention, or failure to achieve significant financial success. Notable for their minimal footprint compared to larger ransomware operations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in available data due to limited reporting on Bonaci Group's activities and capabilities. Additional intelligence gaps include details about their exact targeting criteria, operational tactics, and the tools they employed.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics