Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'. Known victims: 54 3 ransom note(s) on file
Objectives
Executive Summary
BrainCipher is a medium-sophistication criminal threat actor specializing in ransomware attacks. Emerging in July 2024, they have targeted various industries, leveraging known vulnerabilities like CVE-2023-28252 and using LockBit Black malware. Their campaigns involve spear-phishing attacks and encrypted communication channels, seeking significant financial gains through organizational disruption.
Goals & Targeting
BrainCipher's primary motivation is financial gain through ransomware operations targeting organizations with critical data and infrastructure. Their strategic objectives include disrupting business continuity and extorting large sums from victims. Typically, they target mid-sized to large organizations across various sectors such as healthcare, automotive, and finance, suggesting a focus on industries where downtime or data loss would have significant consequences.
Enhanced Description
BrainCipher, a relatively new ransomware group active since July 2024, has demonstrated moderate technical sophistication in their operations. Known for targeting both Windows and Linux systems, they have employed a leaked version of the LockBit Black ransomware to further their objectives. Their campaigns are characterized by precision attacks across various sectors, including healthcare, automotive, and financial services, with a focus on demanding significant ransoms ranging from $150,000 to $1 million in Monero cryptocurrency. BrainCipher's operational strategy involves shifting infrastructure over time, exemplified by their adoption of a new negotiation portal hosted on a vanity TOR domain starting with 'brain'. This strategic shift underscores their adaptability and focus on maintaining communication channels to facilitate extortion. Their activities highlight the evolving nature of ransomware groups, which increasingly rely on sophisticated tools and techniques to maximize their financial gain while avoiding detection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BrainCipher has demonstrated an operational pattern of precision attacks, leveraging known vulnerabilities and sophisticated TTPs. Their shift to a new negotiation portal, hosted on a vanity TOR domain starting with 'brain', indicates efforts to maintain operational persistence and avoid detection. Campaigns have targeted diverse industries, suggesting a strategic focus on maximizing disruption across sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in BrainCipher's intelligence is high due to known campaigns and indicators. However, gaps exist regarding their exact targeting countries and detailed TTPs beyond observed hashes and emails.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
25
Campaigns
15
IOCs
0
Observed Data
0
Tactics